I Changed My Password Perfectly. I Locked Out the Hackers—and Myself.
비밀번호를 완벽하게 바꿨다. 해커도 막고 나도 막았다
Mr. Park began taking passwords seriously one morning after watching the news. A report about a major personal-data breach was followed by a cybersecurity expert explaining that people should never use the same password across multiple websites, should avoid birthdays and phone numbers, and should create long passwords combining uppercase and lowercase letters, numbers, and special characters. Mr. Park listened over his morning coffee and began to feel slightly uneasy. He had been using more or less the same password for years. There were small variations from site to site, but the basic structure was usually the same, and it almost always included numbers that were easy for him to remember. The expert ended with a firm warning: “When it comes to passwords, security is more important than convenience.” Mr. Park completely agreed. At least, he did that morning.
Mr. Park was in his mid-sixties, but he was reasonably comfortable with computers and smartphones. He used online banking, shopped online, and booked his own flights and hotels when he traveled. The real problem was that the digital world seemed to require more and more logins every year. Email, shopping sites, online portals, credit card companies, airlines, hotel booking sites, and streaming services—everywhere he went, someone wanted an ID and a password. In the old days, a few keys were enough to open his home, car, and office. Now he seemed to need dozens of invisible keys just to move through everyday life. Sometimes Mr. Park wondered whether he was using the internet or taking a daily exam to prove his own identity.
That morning, inspired by the news, Mr. Park decided to create a proper password. When he looked at the password he had been using for years, he realized that it contained almost everything the expert had warned against: familiar words, easy-to-remember numbers, and a predictable pattern. This time, he was determined to create something no one could guess. He added an uppercase letter, several lowercase letters, a few numbers, an exclamation mark, another special character, and then made the whole thing longer. A helpful indicator beside the password box rated its strength. At first it said “Weak.” After a few changes, it became “Medium.” Finally, after adding several more characters, the word he had been waiting for appeared: “Strong.”
Mr. Park stared proudly at the word for a moment. He could almost imagine a hacker somewhere trying to crack his password and eventually giving up in frustration. He felt a small sense of victory. Cybersecurity, he decided, was not really that difficult. You simply had to make an effort. He entered the new password twice, clicked the button, and saw the message: “Your password has been successfully changed.” Mr. Park leaned back in his chair, satisfied. Now he was safe.
The trouble began the next morning. When Mr. Park tried to check his email, he discovered that he had been logged out. Without thinking, he entered his old password and received a message saying it was incorrect. Then he remembered. “Ah, right.” He had changed it yesterday. He began typing the new password. He remembered whether it started with an uppercase or lowercase letter. He roughly remembered the numbers. The problem was the special characters. Had he used an exclamation mark? An @ sign? Or both? He tried several combinations, but none of them worked.
Mr. Park stopped and stared at the screen.
It had not even been twenty-four hours since he created the password.
The first attempt failed. So did the second. On the third, he changed the order of the numbers, but that was wrong too. By the fourth attempt, Mr. Park no longer felt as though he were trying to remember his own password. He felt as though he were trying to crack a code created by a stranger. He knew for a fact that he had created it himself the day before. Nobody had forced him to do it. Yet somehow, overnight, yesterday’s Mr. Park had built a security wall between himself and today’s Mr. Park.
After several more failed attempts, a warning appeared on the screen: “Too many login attempts. Please try again later.” Mr. Park stared at it in disbelief. From the security system’s point of view, this was perfectly reasonable. Someone had repeatedly entered the wrong password, so the account needed protection. There was only one detail the system did not know.
The suspicious person it was protecting the account from was the account owner.
Eventually, Mr. Park clicked “Forgot your password?” The site informed him that it would send a verification code to his phone. A six-digit number arrived a few seconds later, and he quickly entered it. Now he was asked to create another password. Mr. Park had not expected to replace yesterday’s carefully designed password after less than a day, so this time he decided to make something easier to remember. The system, however, had other ideas. “Please include an uppercase letter.” He added one. “Please include a number.” He added one. “Please include a special character.” He added that too. Then came another message: “You cannot use a recently used password.” Mr. Park stared at the screen and muttered, “The reason I’m here is because I can’t remember the recently used password.”
The second password was slightly simpler than the first, though the system still rated it “Strong.” This time, determined not to forget it, Mr. Park wrote it on a small piece of paper. As soon as he did, however, another concern occurred to him. He vaguely remembered the expert saying that passwords should never be written down and left near the computer. There was little point in creating an unbreakable password if he was going to stick it next to the monitor for everyone to see. So he folded the paper carefully and placed it deep inside his desk drawer. That felt much safer.
Three days later, Mr. Park tried to buy something from an online shopping site and was asked to log in again. He had expected to be logged in automatically, so he confidently entered the new password he had created a few days earlier. It was wrong. Thinking he might have mistyped it, he carefully entered it again. Wrong again. Mr. Park stared at the screen for a moment before suddenly realizing something important: he had changed his email password, but he had never changed the password for the shopping site. What he needed here was not the new password but the old one. Relieved, he entered his old password.
Wrong again.
Now things became complicated. Mr. Park could no longer remember which passwords he had changed and which ones he had left alone. His email had the new password, the shopping site supposedly had the old one, his online portal used a variation of the old one, and his credit card account had something else entirely. He had changed just one password in the name of better security, but inside his head, his passwords had begun switching places and playing hide-and-seek with him.
That evening, Mr. Park decided to solve the problem once and for all. He would create a different password for every website. Wasn’t that exactly what the experts recommended? He sat down at his laptop and began with his email, then moved on to the shopping site, online portal, credit card company, and travel booking sites. Each received its own combination of uppercase and lowercase letters, numbers, and special characters. If one password looked too similar to another, he deliberately changed it again. After about an hour, he felt a considerable sense of accomplishment. Even if one password were stolen, all his other accounts would remain safe. A hacker who broke into his email could not enter his shopping account, and someone who cracked his shopping account would still be locked out of his travel account. Mr. Park had followed one of the most important rules of online security perfectly.
At the same time, Mr. Park was no longer confident that he could get into any of the accounts either.
So he began writing the passwords down. His wife happened to walk past and saw him sitting at the laptop, carefully filling a sheet of paper with letters, numbers, exclamation marks, and @ signs. “What are you doing?” she asked. Mr. Park proudly explained, “I’m changing all my passwords so they’re different. Security is really important these days.” His wife looked at the page covered with strange combinations and asked, “Can you remember all of those?” Mr. Park answered confidently, “That’s why I’m writing them down.” She thought for a moment and asked one simple question: “What happens if you lose the paper?” Mr. Park’s hand stopped moving. Strangely enough, even the cybersecurity expert on television had not asked him that question.
Mr. Park now realized that the piece of paper containing his passwords needed security of its own. The desk drawer suddenly seemed too obvious, while carrying it in his wallet would create an entirely new problem if he ever lost the wallet. After some thought, he looked around his study and selected a thick book that he almost never opened. He folded the paper into a small square, slipped it deep between the pages, and placed the book toward the back of the shelf. Nobody, he thought, would ever choose that particular book from all the others and happen to open it to exactly the right page. Mr. Park stood back and looked at the bookshelf with satisfaction. His passwords were complicated, every site had a different one, and even the paper containing them was hidden somewhere nobody could find.
It was perfect security.
For about a month.
One day, Mr. Park was trying to reserve a hotel on a travel website when he was asked for his password. Naturally, he could not remember it, but he was not worried. He had his secret sheet containing every password. He walked confidently into his study and looked at the bookshelf.
Then he stopped.
Which book was it?
He was certain it had been a thick book. He also remembered thinking that the title would be easy to remember. Unfortunately, once he looked at the shelf, he discovered that he owned far more thick books than he had realized. He pulled one out and shook the pages. Nothing. The second book was not it. Neither was the third. Before long, more than ten books were piled on the floor. His wife walked past and asked, “Why are you suddenly studying so hard?” Still searching through the shelf, Mr. Park replied, “I’m looking for my passwords.” She laughed. “On the computer?” Mr. Park answered seriously, “No. In a book.” His wife decided not to ask any more questions. After enough years of marriage, you learn that there are moments when trying to understand is more exhausting than simply walking away.
Eventually, Mr. Park gave up looking for the paper and clicked “Forgot your password?” on the hotel booking site. A message informed him that a password-reset link had been sent to his email. Good. All he had to do was check his email and the problem would be solved. He opened his email account.
He had been logged out.
It wanted his email password.
Mr. Park stared at the screen for a long moment. To recover the hotel password, he needed to open his email. To open his email, he needed the email password. And the email password was written on the very piece of paper he had just spent the last half hour searching for.
Technically, the system was working perfectly. Everything was being protected exactly as intended.
The security was flawless. Nobody could get in.
After several rounds of phone verification and identity checks, Mr. Park finally reset his email password and then created another password for the hotel site. But he knew he could not continue living like this. He could not search his bookshelf and prove his identity every time he needed to log in somewhere. So he called his son and explained what had happened. His son laughed for quite a while before saying, “Dad, just use a password manager.” Mr. Park asked what that was, and his son explained that it could securely store all his complicated passwords in one place, leaving him with only one master password to remember. Mr. Park immediately brightened. “So I don’t have to remember ten different passwords?” “Right. You only need to remember one.” Mr. Park thought for a moment and asked the obvious question. “What happens if I forget that one?” There was a brief silence on the other end of the phone. Finally, his son replied, “Well… that’s the one you’re not supposed to forget.”
The logic seemed reasonable. Remembering one password was obviously easier than remembering ten. With his son’s help, Mr. Park installed a password manager and organized his accounts one by one. Finally, he had to create the master password that would unlock everything else. Once again, he combined uppercase and lowercase letters, numbers, and special characters and made it sufficiently long. The program praised the result as highly secure. Mr. Park looked at the screen with satisfaction. From now on, there would be no need to remember all those complicated passwords individually. He only had to remember this one. He silently repeated the master password several times before closing the program. This time, the problem really seemed to be solved.
The next morning, Mr. Park opened the password manager and entered the master password.
Incorrect.
He tried again, this time typing more slowly.
Incorrect again.
He changed the position of the uppercase letter, checked the order of the numbers, and tried several combinations, but the program remained firm. Mr. Park stared at the screen and let out a deep sigh. His wife, sitting nearby, asked, “What’s wrong now?” He answered weakly, “I can’t remember the password that manages my passwords.” His wife looked at him for a moment and then asked, as naturally as if the answer should have been obvious, “So where did you write that password down?” Mr. Park did not answer. A moment later, both of them slowly turned their heads toward the bookshelf in the study.
That afternoon, Mr. Park finally found the missing sheet of passwords. It was not inside any of the thick books he had searched so carefully. Instead, it had been tucked like a bookmark inside a travel guide he had been reading a few weeks earlier. When he discovered it, he reacted like a man who had recovered a lost treasure. The page was covered with complicated passwords for his email, shopping sites, credit card account, and travel websites. At the bottom, he had even added the master password he had created a few days earlier. Mr. Park held the sheet and stared at it for a while. As long as a hacker never found this piece of paper, his accounts were probably quite secure. There was only one small problem: so far, the person who had spent the most time trying to find the secret password sheet was not a hacker. It was Mr. Park himself.
That evening, his wife asked, “So, is the password problem finally solved?” Mr. Park nodded confidently. “Completely.” She asked, “Hackers can’t get in now?” “No chance,” he replied. His wife smiled and asked one final question. “What about you?” Mr. Park did not answer immediately. He thought about the past month: being locked out of his email, rejected by the shopping site, searching through books for his passwords, and then forgetting the password designed to manage all his other passwords. Finally, he gave the most truthful answer he could.
“It’s not exactly easy for me either.”
Only then did Mr. Park realize that he had actually followed the cybersecurity expert’s advice remarkably well. He no longer used the same password everywhere. His passwords were long and difficult to guess. He had carefully protected the paper on which they were written. In fact, he had followed almost every rule of good password security.
There had simply been one unexpected result.
He locked out the hackers—and himself.
비밀번호를 완벽하게 바꿨다. 해커도 막고 나도 막았다
박 씨가 비밀번호의 중요성을 진지하게 생각하게 된 것은 어느 날 아침 뉴스 때문이었다. 개인정보 유출 사고가 있었다는 보도가 나오면서 전문가가 화면에 등장해 같은 비밀번호를 여러 사이트에서 사용하면 위험하고, 생일이나 전화번호처럼 쉽게 추측할 수 있는 숫자는 피해야 하며, 영문 대문자와 소문자, 숫자, 특수문자를 섞어 가능한 한 길고 복잡하게 만들어야 한다고 설명했다. 박 씨는 커피를 마시며 뉴스를 듣다가 조금 불안해졌다. 생각해보니 자신은 몇 년째 거의 같은 비밀번호를 사용하고 있었다. 사이트마다 조금씩 다르기는 했지만 기본 구조는 비슷했고, 무엇보다 자신이 기억하기 쉬운 숫자가 항상 들어가 있었다. 전문가는 마지막으로 “비밀번호는 편리함보다 보안이 중요합니다”라고 강조했다. 박 씨는 그 말에 깊이 공감했다. 그날 아침까지는 그랬다.
박 씨는 60대 중반이었지만 인터넷이나 스마트폰을 못 다루는 편은 아니었다. 인터넷뱅킹도 사용했고 온라인 쇼핑도 했으며, 여행할 때는 호텔과 항공권도 직접 예약했다. 다만 디지털 세상이 점점 복잡해지면서 로그인해야 할 곳이 너무 많아진 것이 문제였다. 이메일, 쇼핑몰, 포털사이트, 카드회사, 항공사, 호텔 예약 사이트, 온라인 동영상 서비스까지 어디를 가든 아이디와 비밀번호를 요구했다. 예전에는 열쇠 몇 개만 잘 챙기면 집과 자동차와 사무실을 열 수 있었는데, 이제는 눈에 보이지 않는 수십 개의 문을 열기 위해 수십 개의 암호를 기억해야 했다. 박 씨는 가끔 “인터넷을 쓰는 건지, 매일 신원 확인 시험을 보는 건지 모르겠다”고 생각했다.
뉴스를 본 그날, 박 씨는 이번 기회에 제대로 된 비밀번호를 만들기로 했다. 먼저 자신이 오랫동안 사용하던 비밀번호를 떠올려보니 전문가가 하지 말라고 한 것이 거의 다 들어 있었다. 기억하기 쉬운 단어, 익숙한 숫자, 반복되는 구조까지 보안 전문가가 본다면 한숨부터 쉴 만한 비밀번호였다. 박 씨는 이번에는 누구도 쉽게 알아낼 수 없는 강력한 비밀번호를 만들겠다고 결심했다. 영문 대문자 하나, 소문자 여러 개, 숫자 몇 개, 느낌표와 특수문자를 넣고 길이도 충분히 늘렸다. 화면 옆에는 친절하게 비밀번호 강도를 알려주는 표시가 있었는데 처음에는 ‘약함’, 조금 수정하자 ‘보통’, 몇 글자를 더 넣자 마침내 ‘강함’으로 바뀌었다.
박 씨는 화면에 나타난 ‘Strong’이라는 글자를 한동안 만족스럽게 바라보았다. 해커가 어디선가 자신의 비밀번호를 풀어보려다가 포기하는 모습까지 머릿속에 그려졌다. 자신도 모르게 작은 승리감이 생겼다. 보안이라는 것이 별것 아니었다. 조금만 신경 쓰면 되는 일이었다. 새 비밀번호를 두 번 입력하고 변경 버튼을 눌렀더니 “비밀번호가 성공적으로 변경되었습니다”라는 메시지가 나타났다. 박 씨는 의자에 기대며 생각했다. 이제 안전하다.
문제는 다음 날 시작되었다.
아침에 이메일을 확인하려는데 로그인이 풀려 있었다. 박 씨는 아무 생각 없이 예전 비밀번호를 입력했다. 화면에 ‘비밀번호가 올바르지 않습니다’라는 메시지가 나타났다. 그제야 전날 비밀번호를 바꿨다는 사실이 떠올랐다. “아, 맞다.” 박 씨는 새 비밀번호를 입력하기 시작했다. 대문자로 시작했는지 소문자로 시작했는지는 기억났다. 숫자도 대충 기억났다. 문제는 특수문자였다. 느낌표를 넣었는지, 골뱅이를 넣었는지, 아니면 둘 다 넣었는지가 확실하지 않았다. 몇 가지 조합을 시도했지만 모두 실패했다.
박 씨는 잠시 멈춰 화면을 바라보았다.
비밀번호를 만든 지 24시간도 지나지 않았다.
첫 번째 시도는 실패했다. 두 번째도 실패했다. 세 번째에서는 숫자의 순서를 바꿔보았지만 역시 틀렸다. 네 번째쯤 되자 박 씨는 자신이 만든 비밀번호가 맞는지 확인하는 것이 아니라 남이 만든 암호를 추리하는 기분이 들기 시작했다. 분명 어제 자신이 만들었다. 누가 강제로 시킨 것도 아니었다. 그런데 하루가 지나자 어제의 자신과 오늘의 자신 사이에 보안 장벽이 생겨 있었다.
몇 번 더 틀리자 화면에 경고가 나타났다.
“로그인 시도가 너무 많습니다. 잠시 후 다시 시도해 주세요.”
박 씨는 어이가 없어 화면을 바라보았다. 보안 시스템 입장에서는 완벽하게 정상적인 대응이었다. 누군가 계속 틀린 비밀번호를 입력하고 있었으니 계정을 보호해야 했다. 다만 시스템이 미처 알지 못한 사실이 하나 있었다.
지금 막아야 할 수상한 사람이 계정 주인이었다.
박 씨는 결국 ‘비밀번호를 잊으셨나요?’를 눌렀다. 그러자 본인 확인을 위해 휴대전화로 인증번호를 보내겠다는 안내가 나왔다. 몇 초 뒤 여섯 자리 숫자가 도착했고 박 씨는 재빨리 입력했다. 이제 새 비밀번호를 만들라는 화면이 나타났다. 박 씨는 잠시 고민했다. 어제 그렇게 어렵게 만든 비밀번호를 하루 만에 다시 바꾸게 될 줄은 몰랐다. 이번에는 조금 더 기억하기 쉬운 것으로 만들기로 했다. 하지만 시스템은 쉽게 허락하지 않았다. ‘영문 대문자를 포함해 주세요.’ 대문자를 넣었다. ‘숫자를 포함해 주세요.’ 숫자를 넣었다. ‘특수문자를 포함해 주세요.’ 그것도 넣었다. ‘최근 사용한 비밀번호는 사용할 수 없습니다.’ 박 씨는 화면을 보며 중얼거렸다. “그 최근 비밀번호를 내가 기억 못 해서 이러고 있잖아.”
두 번째 비밀번호는 첫 번째보다 조금 단순하게 만들었다. 그래도 시스템은 ‘강함’이라고 평가했다. 박 씨는 이번에는 잊지 않기 위해 작은 메모지에 적어두었다. 그런데 적고 나니 갑자기 또 불안해졌다. 뉴스에서 비밀번호를 종이에 적어 컴퓨터 주변에 두면 안 된다고 했던 것 같았다. 해킹을 막으려고 비밀번호를 복잡하게 만들었는데 모니터 옆에 붙여놓으면 모든 노력이 무의미해지는 것 같았다. 결국 메모지를 접어 책상 서랍 안쪽에 넣었다. 그러고 나니 마음이 놓였다.
사흘 뒤 박 씨는 온라인 쇼핑몰에서 물건을 하나 사려다가 다시 로그인 화면과 마주쳤다. 자동 로그인이 되어 있을 줄 알았는데 비밀번호를 입력하라는 창이 나타나자 그는 별생각 없이 며칠 전 새로 만든 비밀번호를 입력했다. 틀렸다는 메시지가 나왔다. 혹시 잘못 눌렀나 싶어 천천히 다시 입력했지만 또 틀렸다. 박 씨는 화면을 한동안 바라보다가 갑자기 중요한 사실을 깨달았다. 새 비밀번호로 바꾼 것은 이메일이었고 쇼핑몰은 아직 예전 비밀번호를 사용하고 있었던 것이다. ‘그렇지’라고 중얼거리며 이번에는 자신 있게 예전 비밀번호를 입력했는데 그것마저 틀렸다고 나왔다. 그 순간부터 상황이 조금 복잡해졌다. 이메일에는 새 비밀번호, 쇼핑몰에는 옛 비밀번호, 포털에는 옛 비밀번호를 조금 변형한 비밀번호, 카드회사에는 또 다른 비밀번호가 있었다. 보안을 강화하겠다고 비밀번호 하나를 바꿨을 뿐인데, 며칠 사이 박 씨의 머릿속에서는 비밀번호들이 서로 자리를 바꾸며 숨바꼭질을 시작하고 있었다.
그날 저녁 박 씨는 이 문제를 근본적으로 해결하기로 했다. 이참에 모든 사이트의 비밀번호를 각각 다르게 만드는 것이었다. 전문가들도 같은 비밀번호를 여러 곳에서 사용하지 말라고 하지 않았던가. 그는 노트북 앞에 앉아 이메일부터 시작해 쇼핑몰, 포털사이트, 카드회사, 여행 예약 사이트의 비밀번호를 차례로 변경했다. 각각 다른 대문자와 소문자, 숫자와 특수문자를 조합했고, 어떤 사이트에서 이미 사용한 조합과 비슷해 보이면 일부러 다시 바꾸기까지 했다. 한 시간쯤 지나자 상당한 성취감이 들었다. 이제 어느 한 곳의 비밀번호가 유출되어도 다른 계정은 안전할 것이다. 이메일을 뚫어도 쇼핑몰에는 들어갈 수 없고, 쇼핑몰을 뚫어도 여행 사이트에는 들어갈 수 없다. 보안의 기본 원칙을 완벽하게 실천한 셈이었다. 문제는 모든 비밀번호가 서로 달라지면서 박 씨 자신도 어느 계정에도 들어갈 자신이 없어졌다는 것이었다.
그래서 박 씨는 비밀번호를 종이에 적기 시작했다. 아내가 지나가다가 남편이 노트북 앞에서 알파벳과 숫자, 느낌표와 골뱅이를 빼곡하게 적고 있는 것을 보고 무엇을 하느냐고 물었다. 박 씨는 꽤 자랑스러운 표정으로 “비밀번호를 전부 다르게 바꾸는 중이야. 요즘 보안이 얼마나 중요한데”라고 설명했다. 아내는 종이를 내려다보다가 “그걸 다 외울 수 있어?”라고 물었고, 박 씨는 당연하다는 듯 “그러니까 적어놓는 거지”라고 대답했다. 아내는 잠시 생각하더니 아주 간단한 질문 하나를 던졌다. “그럼 그 종이 잃어버리면?” 박 씨의 손이 그대로 멈췄다. 이상하게도 뉴스에 나온 보안 전문가도 그 질문까지는 하지 않았었다.
박 씨는 비밀번호를 적어놓은 종이 자체에도 보안이 필요하다는 사실을 깨달았다. 책상 서랍에 넣어두는 것은 너무 쉽게 찾을 수 있을 것 같았고, 그렇다고 지갑에 넣고 다니자니 지갑을 잃어버렸을 때가 문제였다. 한참 고민하던 그는 서재를 둘러보다가 평소 거의 펼쳐보지 않는 두꺼운 책 한 권을 골랐다. 종이를 작게 접어 책 중간 깊숙한 곳에 넣고 책장 안쪽에 꽂았다. 아무도 수많은 책 가운데 그 책을 골라 그 페이지까지 펼쳐볼 것 같지 않았다. 박 씨는 책장을 바라보며 만족했다. 비밀번호도 복잡하고, 사이트마다 모두 다르고, 그것을 적어놓은 종이까지 아무도 모르는 곳에 숨겼다.
완벽한 보안이었다.
한 달 뒤까지는.
어느 날 박 씨는 여행 사이트에서 호텔을 예약하려다가 비밀번호를 입력하라는 화면을 만났다. 당연히 기억나지 않았지만 당황하지 않았다. 자신에게는 모든 비밀번호를 기록해둔 비밀 종이가 있었기 때문이다. 그는 여유 있게 서재로 가서 책장을 바라보았다. 그리고 몇 초 뒤 표정이 굳었다. 종이를 어느 책에 넣었는지가 기억나지 않았다. 분명 두꺼운 책이었고 제목도 기억하기 쉬운 것이었다고 생각했는데, 막상 책장을 보니 두꺼운 책이 생각보다 많았다. 박 씨는 한 권을 꺼내 페이지를 흔들어보고 다시 꽂았다. 두 번째 책도 아니었고 세 번째도 아니었다. 잠시 후 책장 앞 바닥에는 열 권이 넘는 책이 쌓여 있었다. 그 모습을 본 아내가 “갑자기 무슨 공부를 그렇게 열심히 해?”라고 묻자 박 씨는 책장을 뒤지면서 “비밀번호 찾고 있어”라고 대답했다. 아내가 웃으며 “컴퓨터에서?”라고 묻자 박 씨는 진지하게 “아니, 책에서”라고 했다. 아내는 더 이상 묻지 않았다. 결혼생활이 오래되면 이해하려고 노력하는 것보다 그냥 지나가는 편이 나은 순간도 있다는 것을 알게 된다.
결국 종이를 찾지 못한 박 씨는 호텔 예약 사이트의 ‘비밀번호를 잊으셨나요?’를 눌렀다. 이메일로 재설정 링크를 보냈다는 안내가 나타났고, 이제 이메일만 확인하면 문제가 해결될 것 같았다. 그런데 이메일을 열자 이번에는 로그인이 풀려 있었다. 이메일 비밀번호를 입력해야 했다. 박 씨는 화면을 한동안 바라보았다. 호텔 사이트의 비밀번호를 찾으려면 이메일에 들어가야 하고, 이메일에 들어가려면 이메일 비밀번호가 필요했다. 그리고 그 이메일 비밀번호는 자신이 조금 전부터 찾고 있는 종이에 적혀 있었다. 시스템은 논리적으로 아무 문제가 없었다. 모든 것이 안전하게 보호되고 있었다.
보안은 완벽했다. 접근할 수 있는 사람이 아무도 없었다.
박 씨는 결국 휴대전화 인증과 몇 차례의 본인 확인을 거쳐 이메일 비밀번호부터 다시 설정한 뒤 호텔 사이트의 비밀번호까지 새로 만들었다. 하지만 이렇게 살 수는 없다는 생각이 들었다. 앞으로 로그인할 때마다 책장을 뒤지고 본인 인증을 할 수는 없는 노릇이었다. 결국 아들에게 전화를 걸어 지금까지 벌어진 일을 설명했다. 아들은 한참 웃더니 “아버지, 그냥 비밀번호 관리 프로그램 쓰세요”라고 했다. 박 씨가 그게 무엇이냐고 묻자, 여러 사이트의 복잡한 비밀번호를 한곳에 안전하게 저장해두고 자신은 하나의 마스터 비밀번호만 기억하면 된다고 설명했다. 박 씨의 얼굴이 밝아졌다. “그러니까 비밀번호를 열 개씩 외울 필요가 없다는 거지?”라고 묻자 아들은 그렇다고 했다. 박 씨는 잠시 생각하다가 아주 중요한 질문을 하나 더 했다. “그럼 그 하나를 잊어버리면?” 전화기 너머로 잠깐 침묵이 흐른 뒤 아들이 조심스럽게 대답했다. “그건…… 잊어버리시면 안 돼요.”
설명은 합리적이었다. 열 개를 기억하는 것보다 하나를 기억하는 것이 훨씬 쉬운 것은 분명했다. 박 씨는 아들의 도움을 받아 비밀번호 관리 프로그램을 설치하고 여러 계정을 하나씩 정리했다. 마지막에는 모든 비밀번호를 열 수 있는 마스터 비밀번호를 만들어야 했다. 이번에도 대문자와 소문자, 숫자와 특수문자를 조합하고 길이도 충분히 늘렸다. 프로그램은 아주 강력한 비밀번호라고 평가했다. 박 씨는 만족스러운 표정으로 화면을 바라보았다. 이제 복잡한 비밀번호들을 일일이 기억할 필요가 없었다. 이 하나만 기억하면 모든 문제가 해결되는 것이었다. 그는 마스터 비밀번호를 몇 번 소리 없이 되뇌어본 뒤 프로그램을 닫았다. 이번에는 정말 끝난 것 같았다.
다음 날 아침 박 씨는 비밀번호 관리 프로그램을 열었다. 마스터 비밀번호를 입력했는데 틀렸다는 메시지가 나타났다. 어제 만든 것이니 설마 틀릴 리가 없다고 생각하며 천천히 다시 입력했지만 또 틀렸다. 대문자 위치를 바꿔보고 숫자의 순서도 확인해봤지만 프로그램은 단호했다. 박 씨는 화면을 바라보다가 깊은 한숨을 쉬었다. 옆에 있던 아내가 “또 왜 그래?”라고 묻자 그는 힘없이 “비밀번호 관리하는 비밀번호가 생각이 안 나”라고 대답했다. 아내는 잠시 남편을 바라보다가 아주 자연스럽게 물었다. “그럼 그 비밀번호는 어디다 적어놨어?” 박 씨는 대답하지 않았다. 잠시 후 두 사람의 시선이 약속이라도 한 듯 동시에 서재의 책장으로 향했다.
그날 오후 박 씨는 마침내 비밀번호가 적힌 종이를 찾아냈다. 자신이 그렇게 열심히 뒤졌던 두꺼운 책에서는 나오지 않았다. 몇 주 전 여행지를 알아보다 읽던 여행책 사이에 책갈피처럼 끼워져 있었다. 종이를 발견한 순간 박 씨는 잃어버린 보물을 되찾은 사람처럼 기뻐했다. 거기에는 이메일과 쇼핑몰, 카드회사와 여행 사이트의 복잡한 비밀번호들이 빼곡하게 적혀 있었고, 맨 아래에는 며칠 전 새로 만든 마스터 비밀번호까지 추가되어 있었다. 박 씨는 종이를 들고 한동안 바라보았다. 해커가 이 종이를 발견하지 않는 한 자신의 계정은 상당히 안전할 것이다. 다만 한 가지 문제가 있었다. 지금까지 이 종이를 가장 열심히 찾은 사람은 해커가 아니라 박 씨 자신이었다.
그날 저녁 아내가 “그래서 이제 비밀번호 문제는 다 해결됐어?”라고 묻자 박 씨는 자신 있게 고개를 끄덕이며 “완벽하게”라고 대답했다. 아내가 “이제 해커도 못 들어와?”라고 묻자 그는 당연하다는 듯 “못 들어오지”라고 했다. 아내는 잠시 웃더니 마지막으로 하나를 물었다. “당신은?” 박 씨는 바로 대답하지 못했다. 지난 한 달 동안 이메일에서 쫓겨나고, 쇼핑몰에서 거절당하고, 책장에서 비밀번호를 찾고, 비밀번호를 관리하기 위한 비밀번호까지 잊어버린 자신의 모습을 차례로 떠올렸다. 그리고 마침내 아주 솔직하게 대답했다.
“나도 쉽지는 않아.”
박 씨는 그제야 자신이 보안 전문가의 조언을 충실하게 따랐다는 사실을 깨달았다. 같은 비밀번호를 여러 곳에서 사용하지 않았고, 누구도 쉽게 추측할 수 없도록 복잡하게 만들었으며, 비밀번호가 적힌 종이도 아무도 찾기 어려운 곳에 보관했다. 모든 원칙을 거의 완벽하게 지킨 셈이었다.
다만 한 가지 예상하지 못한 결과가 있었다.
해커도 막았고, 본인도 막았다.