{"id":64650,"date":"2014-04-15T01:16:28","date_gmt":"2014-04-14T23:16:28","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=64650"},"modified":"2025-07-02T00:45:21","modified_gmt":"2025-07-02T07:45:21","slug":"heartbleed-password-manager","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/heartbleed-password-manager\/","title":{"rendered":"Why it&#8217;s time to start using a password manager"},"content":{"rendered":"<p>The <a title=\"&quot;Heartbleed&quot; security bug leaves majority of the web vulnerable\" href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed<\/a> security bug has left up to <strong>two-thirds of the internet vulnerable<\/strong>. The bug allows attackers to steal user names and passwords. Even popular sites like Google and Yahoo! were affected, though they&#8217;ve since patched the vulnerability.<\/p>\n<p>While you can&#8217;t stop hackers from attacking websites, you can take steps to protect your information. The first line of defense is to create secure and unique passwords for every site and service you use. The problem is, how are you supposed to remember all of these passwords? The answer is with <strong>password managers<\/strong>.<\/p>\n<h3>What&#8217;s a password manager?<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-64659\" title=\"1password for Mac\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/1password-for-Mac-568x323.png\" alt=\"1password for Mac\" width=\"568\" height=\"323\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/1password-for-Mac-568x323.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/1password-for-Mac-256x145.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/1password-for-Mac-238x134.png 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/1password-for-Mac.png 1738w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>Password managers are programs that generate, store, and encrypt all your passwords. You&#8217;ll just need to remember one, strong <strong>master password<\/strong> to get into your password database.<\/p>\n<p>By creating unique and randomized passwords with letters, numbers, and symbols, you&#8217;ll prevent compromising all of your accounts if your password is stolen. If your Facebook account gets hacked, the hacker can easily access your other accounts that use the same password.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-64653\" title=\"LastPass secure password example\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-secure-password-example-568x154.jpg\" alt=\"LastPass secure password example\" width=\"568\" height=\"154\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-secure-password-example-568x154.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-secure-password-example-256x69.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-secure-password-example.jpg 871w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>Weak passwords with just letters and numbers are vulnerable to brute-force attacks. Short passwords make these types of attacks even easier.<\/p>\n<p>Apps like <a title=\"1Password\" href=\"https:\/\/agilebits.com\/onepassword\" target=\"_blank\" rel=\"noopener noreferrer\">1Password<\/a> and <a title=\"LastPass\" href=\"https:\/\/lastpass.com\/how-it-works\/\" target=\"_blank\" rel=\"noopener noreferrer\">LastPass<\/a> are great options and act as much more than just password managers; they can store sensitive documents, credit card information, and even your software licenses.<\/p>\n<h3>But what if someone steals my master password?<\/h3>\n<p>This is highly unlikely, and password managers make it difficult for attackers to crack your master password. We spoke with <a href=\"https:\/\/twitter.com\/JeffreyGoldberg\" target=\"_blank\" rel=\"noopener noreferrer\">Jeffrey Goldberg<\/a>, Defender Against the Dark Arts (that&#8217;s really his title) at 1Password, about how the app protects master passwords. &#8220;Your 1Password data is encrypted with keys derived from your Master Password. Nobody has any access to those keys or your Master Password. If someone captures your 1Password data, they cannot decrypt it without your Master Password.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-64661\" title=\"LastPass for Chrome\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-for-Chrome-568x426.png\" alt=\"LastPass for Chrome\" width=\"568\" height=\"426\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-for-Chrome-568x426.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-for-Chrome-256x192.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-for-Chrome.png 800w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>This is the same case with LastPass. Although LastPass syncs your password database with its servers, it doesn&#8217;t send or store any encryption keys. All encryption keys are derived from your master password and stored locally on your computer or device.<\/p>\n<p>&#8220;We use SSL only as a second level of protection. Our core protection is from storing keys locally,&#8221; says LastPass CEO Joe Siegrist.<\/p>\n<h3>Do I really need to change all my passwords?<\/h3>\n<p>First, check which sites you use that were affected by Heartbleed, and make sure they&#8217;ve been patched. <a title=\"Mashable Heartbleed list\" href=\"http:\/\/mashable.com\/2014\/04\/09\/heartbleed-bug-websites-affected\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mashable<\/a> has a great list of popular sites and their reactions to Heartbleed. Make sure a site has <strong>fixed the Heartbleed bug<\/strong> before you change your password, otherwise you risk having your new password exposed as well. Although there have been reports that Heartbleed may be exaggerated, there&#8217;s no harm in being just a bit paranoid.<\/p>\n<p>Cloudflare, a content delivery network, proposed a <a title=\"Cloudflare Heartbleed challenge \" href=\"http:\/\/blog.cloudflare.com\/answering-the-critical-question-can-you-get-private-ssl-keys-using-heartbleed\" target=\"_self\" rel=\"noopener noreferrer\">challenge<\/a> for people to steal private keys using a site with the Heartbleed bug. Within hours, several people were successful in exploiting the bug to steal private encryption keys, meaning the threat is very real.<\/p>\n<p>&#8220;[Heartbleed] is not an exaggeration,&#8221; says Siegrist. &#8220;Cloudflare has proven that it is exploitable. It&#8217;s quite possible that usernames and passwords were taken.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-64664\" title=\"LastPass Heartbleed checker\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-Heartbleed-checker-568x347.jpg\" alt=\"LastPass Heartbleed checker\" width=\"568\" height=\"347\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-Heartbleed-checker-568x347.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-Heartbleed-checker-256x156.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/LastPass-Heartbleed-checker.jpg 1164w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>Changing passwords with a password manager is easy; the apps will remember the new passwords and store them for you. LastPass makes it even easier by <a title=\"LastPass Now Checks If Your Sites Are Affected by Heartbleed\" href=\"http:\/\/blog.lastpass.com\/2014\/04\/lastpass-now-checks-if-your-sites-are.html\" target=\"_blank\" rel=\"noopener noreferrer\">alerting users<\/a> which sites and accounts were vulnerable to the Heartbleed bug. They have a <a title=\"LastPass public Heartbleed tool\" href=\"https:\/\/lastpass.com\/heartbleed\/\" target=\"_blank\" rel=\"noopener noreferrer\">public website<\/a> where you can type in URLs to check if they were affected. Mashable has compiled a great list of company responses to Heartbleed.<\/p>\n<p>While there are no automation tools, both 1Password and Lastpass are working on this feature.<\/p>\n<p>&#8220;You still have to find the password change form yourself and then let 1Password assist you with creating and saving a new strong login. Improving this process is something that we&#8217;re are always doing,&#8221; says Goldberg.<\/p>\n<p>Still, a little bit of work now can prevent a big headache in the future.<\/p>\n<h3>What else can I do to protect myself?<\/h3>\n<p>Password managers are the first step you should take to protect your accounts. Be vigilant about security news and <strong>pay attention<\/strong> to the websites you visit.<\/p>\n<p>Phishing attacks, websites made to trick users into thinking they&#8217;re another site, are a popular way to steal user data. Never click on <strong>suspicious links<\/strong> sent to you via email or over chat.<\/p>\n<p>Password managers can help in this regard as well by taking users directly to the correct site. Sometimes, the smallest typo in a web address can take you to a phishing site, and you may not notice.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-64662\" title=\"Chrome browser lock\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/Chrome-browser-lock-440x568.jpg\" alt=\"Chrome browser lock\" width=\"440\" height=\"568\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/Chrome-browser-lock-440x568.jpg 440w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/Chrome-browser-lock-198x256.jpg 198w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/Chrome-browser-lock.jpg 483w\" sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/p>\n<p>&#8220;People should try to take SSL\/TLS warnings in their browsers more seriously,&#8221; says Goldberg. The lock in the URL bar in modern browsers will show which sites are legitimate and are using encryption. Most browsers will warn you if you&#8217;re visiting a dangerous site, but awareness never hurts.<\/p>\n<p>You should also enable <a title=\"Guide to two-factor authentication\" href=\"http:\/\/features.en.softonic.com\/guide-to-using-two-step-verification\" target=\"_self\" rel=\"noopener noreferrer\">two-factor authentication<\/a> on sites and services that support it. Two-factor authentication basically requires two forms of identification: a password and a <strong>randomly generated code<\/strong>. Once you enter your password, you&#8217;ll be required to provide a random code, which can be sent to you via SMS or via an authenticator app like <a title=\"Google Authenticator app\" href=\"http:\/\/en.softonic.com\/s\/google-authenticator:iphone-android\" target=\"_self\" rel=\"noopener noreferrer\">Google Authenticator<\/a>. The codes will only work for a small window of time before they expire.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-64668\" title=\"Dropbox two factor authentication\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/04\/Dropbox-two-factor-authentication.jpg\" alt=\"Dropbox two factor authentication\" width=\"359\" height=\"228\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/Dropbox-two-factor-authentication.jpg 359w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/04\/Dropbox-two-factor-authentication-256x162.jpg 256w\" sizes=\"auto, (max-width: 359px) 100vw, 359px\" \/><\/p>\n<p>Facebook, Google, Twitter, Evernote, and many other companies provide this extra layer of security. It may be a bit more work to get into your account, but it&#8217;s worth it to keep your accounts secure.<\/p>\n<p>Finally, make sure to keep all of your computers, phones, and tablets updated. <strong>Security flaws are often patched in system and software updates<\/strong>.<\/p>\n<p>Apps like <a title=\"Avast! Free Antivirus 2014\" href=\"http:\/\/avast.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Avast!<\/a> alert users about outdated software. <a title=\"Softonic for Windows\" href=\"http:\/\/softonic-for-windows.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Softonic for Windows<\/a> also helps users keep their apps up to date.<\/p>\n<p>For more information about Heartbleed and how you can protect yourself, check out our coverage below.<\/p>\n<p><strong>Lastpass:<\/strong><\/p>\n<ul>\n<li><a title=\"Download LastPass for Windows\" href=\"http:\/\/lastpass.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download LastPass for Windows<\/a><\/li>\n<li><a title=\"Download LastPass for Mac\" href=\"http:\/\/lastpass.en.softonic.com\/mac\" target=\"_self\" rel=\"noopener noreferrer\">Download LastPass for Mac<\/a><\/li>\n<li><a title=\"Download LastPass for Windows 8\" href=\"http:\/\/lastpass-windows-8.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download LastPass for Windows 8<\/a><\/li>\n<li><a title=\"Download LastPass for Windows Phone\" href=\"http:\/\/lastpass.en.softonic.com\/windows-phone-7\" target=\"_self\" rel=\"noopener noreferrer\">Download LastPass for Windows Phone<\/a><\/li>\n<\/ul>\n<p><strong>1Password:<\/strong><\/p>\n<ul>\n<li><a title=\"Download 1Password for Windows\" href=\"http:\/\/1password.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download 1Password for Windows<\/a><\/li>\n<li><a title=\"Download 1Password for Mac\" href=\"http:\/\/1passwd.en.softonic.com\/mac\" target=\"_self\" rel=\"noopener noreferrer\">Download 1Password for Mac<\/a><\/li>\n<li><a title=\"Download 1Password for iOS\" href=\"http:\/\/1password.en.softonic.com\/iphone\" target=\"_self\" rel=\"noopener noreferrer\">Download 1Password for iOS<\/a><\/li>\n<li><a title=\"Download 1Password for Android\" href=\"http:\/\/1password-reader.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">Download 1Password for Android<\/a><\/li>\n<\/ul>\n<h4>MORE ON HEARTBLEED<\/p>\n<ul>\n<li><a href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">&#8220;Heartbleed&#8221; security bug leaves majority of the web vulnerable<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/report-nsa-has-been-exploiting-heartbleed-bug-for-years\" target=\"_self\" rel=\"noopener noreferrer\">Report: NSA has been exploiting Heartbleed bug for years<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/heartbeat-bug-exaggeration\" target=\"_self\" rel=\"noopener noreferrer\">Are the dangers of the Heartbleed vulnerability exaggerated?<\/a><\/li>\n<li><a href=\"http:\/\/features.en.softonic.com\/heartbleed-five-steps-to-protect-your-account\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed: five steps to protect your accounts<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/the-softonic-minute-heartbleed-twitter-facebook-and-windows-xp\" target=\"_self\" rel=\"noopener noreferrer\">The Softonic Minute: Heartbleed, Twitter, Facebook and Windows XP<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/soundcloud-heartbleed-bug-fix\" target=\"_self\" rel=\"noopener noreferrer\">Soundcloud signs out users in wake of Heartbleed bug<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/apple-not-affected-by-heartbleed-bug\" target=\"_self\" rel=\"noopener noreferrer\">Apple claims it was not affected by Heartbleed security bug<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>The Heartbleed security bug has left up to two-thirds of the internet vulnerable. The bug allows attackers to steal user names and passwords. Even popular sites like Google and Yahoo! were affected, though they&#8217;ve since patched the vulnerability. While you can&#8217;t stop hackers from attacking websites, you can take steps to protect your information. The &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/heartbleed-password-manager\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Why it&#8217;s time to start using a password manager&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":64659,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-64650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=64650"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64650\/revisions"}],"predecessor-version":[{"id":330940,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64650\/revisions\/330940"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/64659"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=64650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=64650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=64650"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=64650"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=64650"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=64650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}