Hi. Yes, it’s PSA time.
I hope that nobody in my friends list did this, but you never know.
Frienditto is not your friend. If you went there and gave them your LiveJournal username and password, kindly go here RIGHT NOW and change your LiveJournal password. Frienditto is a site that basically uses *your* username and password to compromise your friends’ protected entries and post them publicly. Yes, it’s basically breaking your trust with your friends. But hey, *you* gave them your password.
Here’s my advice on third-party sites: Don’t give them your password. If you decide you really really really want to use that service, go change your password first to something you never use (this assumes you’re like me and use the same password for multiple items), then give it to them, then change it back to your normal password.
More security advice: If you have over 70 passwords (like I do), categorize them by risk level:
Low security: Use the same password for a whole bunch of sites, like registration-only bulletin boards, memes, and the like. These sites are for publicly-viewable chatting, with no exchange of personal or sensitive information. I also use them for signing up on websites that require registration just to send an email to the site owner, for instance.
Mid-security: Sites like Yahoo!, where there’s some privacy involved, or where I may store sensitive information. I’ll use the same password for these sites, but it’ll be a harder to guess password. I would use this password on IM accounts, but if you’re on IM a lot, you might want to go with high security for those.
High security: Your primary email account, which someone might use to impersonate you. Any account which someone could or would successfully impersonate you with. Any account that gives access to your money (PayPal, eBay, online banking). Any account that has one-click shopping (amazon.com). Any account that can be used to get passwords for other accounts (usually your primary email account). Any account in which you have sensitive, personal, or embarassing information, or which such information about others has been entrusted to you (ex: LiveJournal). EACH HIGH SECURITY ACCOUNT MUST HAVE ITS OWN SECURE, HARD-TO-GUESS PASSWORD!! I use a password program on my PDA to track all my passwords, and recommend it to anyone looking for such a solution (it’s called Password Store and is made by Standalone Software).