Accueil / Tech News / My 140 reused passwords finally came back to bite me. Here’s how I fixed it

My 140 reused passwords finally came back to bite me. Here’s how I fixed it

Affiliate links on Android Authority may earn us a commission. Learn more.

It’s famous online security lore that you shouldn’t reuse the same password across multiple accounts. But once upon a time, I was a naïve student who liberally ignored this rule, placing far too much trust in the companies that held my data.

Fast forward to 2026, and those bad habits have come back to bite an older and wiser version of myself. While I have long since stopped reusing passwords, the Ghost of Passwords Past decided to visit me when I was notified that my data had been exposed in a breach. And it ended up affecting a lot more than I expected.

While I was aware that I’d used the password many times in the past, I hadn’t realized just how much. It was somewhat of a holy grail at the time: a secure password with random letters and characters — as well as one that I actually remembered.

At the time, password managers weren’t as ubiquitous as they are now. Chrome only introduced a built-in password manager around 2015, and it only started generating passwords in 2018. I had started using this password in 2009. These were the days of adding every game and quiz you could on Facebook (not realizing they were harvesting data), while e-commerce and online services were growing quickly. By the time Chrome’s password manager came around, I had already signed up for dozens of sites using the same password.

I eventually set up a few safeguards as well, including signing up for Have I Been Pwned updates and keeping an eye on Google Password Manager’s notifications for leaked passwords. I did eventually stop using the password because password managers allowed me to generate much more complex credentials without needing to remember them. I could also easily store and access passwords from my phone or my browser, meaning that these secure credentials applied to new app sign-ups as well.

Over the years, I also started changing some of my most important accounts, as well as the ones I was most concerned about when it came to leaks. My Facebook password has long-since changed, along with my primary Google account. At the same time, though, I didn’t realize how much of a trail of reused passwords I had left behind. These were mostly sites I no longer used, so they fell to the back of my mind.

I only realized just how much I had reused the same password when it was already compromised. I visited my Pass Monitor feature in Proton Pass and discovered I had used the same password over 140 times. A few of these were false positives, since they were the same account with slightly different URLs saved. A few had also already been updated. Luckily, these weren’t identical credentials — the password was spread out across different usernames and email addresses.

But the conclusion was clear: I had spent years in the early 2010s signing up for a large number of online accounts with the same password. Also, despite changing some of my most-used accounts, I had missed some in my cleanup. This included my secondary Gmail account and my Reddit account.

About a month ago, I received an email from a service I no longer use, stating that my data may have been compromised. It was frustrating because the app I signed up for had been rebranded and integrated into another app, so I had no idea what account information was stored in it besides my email address. The disclosure noted that encrypted passwords were included, but didn’t clarify what that meant. Ever the optimist, I hoped this meant the actual passwords were still protected by encryption.

However, last week, Google sent a critical security alert noting that my password had appeared online. It flagged 11 accounts that were affected, including the defunct app that had been breached. I finally found out which password I had used for the app, and my stomach sank when I realized it was the holy grail password of my student days.

Knowing that I had relied on this password for years, I also knew that the count of 11 compromised logins was too low. Google Password Manager didn’t let me search for accounts that shared the same password, so I moved to Proton Pass. And that’s when I saw the throat-lump-inducing total of 140 logins sharing the same password.

Oh no, the consequences of my actions. When I saw how many times I had reused the password, I wanted to kick myself. However, rather than lingering on a past I couldn’t change, I decided to fix what I could. This meant going scorched earth on the password.

As mentioned, the password was spread across multiple usernames and email addresses. However, I didn’t want to risk someone linking my leaked email address and password with other accounts and breaching those. As a result, I decided to change every single login that included the password.

First, I started off with Google’s Password Manager dashboard. The tool allowed me to follow links to the sites with breached passwords. Not every password reset link worked, but it did prove quicker than manually visiting every site myself. The problem was that Google had only flagged 11 accounts with the leaked password. I reset the passwords for the remaining sites, then moved to Proton Pass.

With Proton Pass, I could use the Pass Monitor dashboard to find which logins used the same password. This proved helpful because it flagged the same password across different accounts, not only my primary Google account.

I prioritized the most vulnerable services first — those that exactly matched my leaked credentials. I then moved on to any service that included the leaked email address but a different username. Finally, I reset the services with different email addresses and the same password.

The main hurdle was services that no longer existed or that no longer worked correctly. I couldn’t delete these accounts or even reset their passwords. However, at least every account that matched their credentials had been changed.

My Proton Pass browser extension made it easy to generate new passwords and update the credentials. This saved a lot of time while going through all the logins. I also used its mobile app when resetting passwords using apps on my phone.

Eventually, I managed to change all the remaining accounts. I kept the logins for defunct sites in Proton Pass, since if those ever get breached, I want to be able to easily check which credentials were used. The entire process took two afternoons.

My next-most-reused password was used 34 times, though some of the credentials were duplicates for the same account. However, I went ahead and changed these too. I also decided to change the passwords for both of my Google accounts to something both secure and memorable, out of an abundance of caution.

After my war on reused passwords, I feel a lot better about my online security. I still have to watch out for scams, since over the years, my phone number and email have been leaked in breaches. It’s frustrating that many of the places we trust with our data fail to secure it. However, I at least know that my own passwords won’t be the weak point in my online security anymore.

Thank you for being part of our community. Read our Comment Policy before posting.

Origine de l’article : lire l’article original
Traduction