Exactly! This is about as secure as having your first dog's name as a password reset hint. I either already know or can simply ask about the birthday, address and mother's maiden name of practically anyone I know.
I've always hated the mother's maiden name security question because my mother kept her maiden name so it's not exactly a hard thing to figure out in my case.
I think that one will go away sooner than later though, because taking a husband's name is becoming less common in a lot of societies.
The lazy way (which is still arguably better than answering truthfully) is to use the same answer for all the security questions. The better way is to treat each answer as another password and encrypt and store the answers somewhere safe.
Realistically how many people outside (or even inside) HN are going to do that? No matter how you spin it, security questions are a very bad "security pattern" in my opinion and we should get rid of them.
The same way as you keep track of any secure password: either with a password manager like 1Password, etc, or else through some Byzantine scheme that you manage yourself.
I use 1Password for this as well, but I recently had a security questions form (can't remember where) that tried to reject random strings because they didn't look like words.
Luckily, 1Password has a 'correct horse battery staple'-generator these days as well.
If it's only 2 bits, you're assuming the attacker already knows that the formula is "Using someone else's information" and that there are only 4 possible people whose information you would use.
Even knowing that you're using a formula is a bit of information. The type of formula is potentially thousands of bits of information. An attacker doesn't know whether it's a cipher, or a code, or something more complex, and only then can they begin figuring out the parameters to that formula.
Pretty sure lots of people use relatives' info. Very, very few use ciphers in their head.
Friend used to have a car with a keycode door lock. He just used 5555 or whatever. I suggested he use the address where the car was parked, or some hash of that. Wouldn't have to remember it! And it would vary some at least.
Well, sure, 8 bits of entropy isn't going to help you much if your password is "password". Those bits only provide the opportunity for randomness. At the end of the day you still have to apply that entropy effectively by picking something that can't be guessed easily. The point is that there are opportunities for people savvy enough to recognize them.
My aim isn't to guard against the answers being guessed, it is to deny the operator of the service asking those questions from gathering accurate data about me that may later be exposed.
Someone then trying to fraudulently use my identity info, or for any kind of socially engineered attack, would lose out.
E.g. calling some financial service provider and trying to get a password reset based on D.O.B, mother's maiden name, or whatever.
Think of those fields as secondary password fields and act accordingly.
Diceware can also be useful for when they need to be spoken on the phone. With the right amount of words (7 or more) it has reasonably good entropy too.
Thank you for answering the security question Mr. Stavros. I'll accept "Bee" as your dog's name. To which offshore bank did you say you wanted to transfer the money ?