Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exactly! This is about as secure as having your first dog's name as a password reset hint. I either already know or can simply ask about the birthday, address and mother's maiden name of practically anyone I know.


I've always hated the mother's maiden name security question because my mother kept her maiden name so it's not exactly a hard thing to figure out in my case.

I think that one will go away sooner than later though, because taking a husband's name is becoming less common in a lot of societies.


Pro tip: You shouldn't be answering those questions truthfully.


But you have to remember the answers correctly. How do you keep track ?


The lazy way (which is still arguably better than answering truthfully) is to use the same answer for all the security questions. The better way is to treat each answer as another password and encrypt and store the answers somewhere safe.


Realistically how many people outside (or even inside) HN are going to do that? No matter how you spin it, security questions are a very bad "security pattern" in my opinion and we should get rid of them.


I do that, the security questions and answers just get added to the site's entry in 1Password.


I use KeyPass and save all the security questions and answers too. I should use fake answers next time though...



The same way as you keep track of any secure password: either with a password manager like 1Password, etc, or else through some Byzantine scheme that you manage yourself.


I use 1Password for this as well, but I recently had a security questions form (can't remember where) that tried to reject random strings because they didn't look like words.

Luckily, 1Password has a 'correct horse battery staple'-generator these days as well.


I 'time shift' each number in date of birth so neither the day, month, or year are correct. My secret key is the formula I use.

For other questions I use answers that 'belong' to a friend or relative. My secret key is the formula for figuring out who that is.


I wonder how many 'bits' those secret keys have? Maybe one or two? E.g. how long to brute force those answers.


If it's only 2 bits, you're assuming the attacker already knows that the formula is "Using someone else's information" and that there are only 4 possible people whose information you would use.

Even knowing that you're using a formula is a bit of information. The type of formula is potentially thousands of bits of information. An attacker doesn't know whether it's a cipher, or a code, or something more complex, and only then can they begin figuring out the parameters to that formula.


Pretty sure lots of people use relatives' info. Very, very few use ciphers in their head.

Friend used to have a car with a keycode door lock. He just used 5555 or whatever. I suggested he use the address where the car was parked, or some hash of that. Wouldn't have to remember it! And it would vary some at least.


Well, sure, 8 bits of entropy isn't going to help you much if your password is "password". Those bits only provide the opportunity for randomness. At the end of the day you still have to apply that entropy effectively by picking something that can't be guessed easily. The point is that there are opportunities for people savvy enough to recognize them.


My aim isn't to guard against the answers being guessed, it is to deny the operator of the service asking those questions from gathering accurate data about me that may later be exposed.

Someone then trying to fraudulently use my identity info, or for any kind of socially engineered attack, would lose out.

E.g. calling some financial service provider and trying to get a password reset based on D.O.B, mother's maiden name, or whatever.


I usually store it as another password field in keepass http://keepass.info/


you only have to remember that for password resets, if you already store your password in 1password you're golden.


Thank goodness KeePassX remembers my mother's maiden name! I always have a hard time remembering NortOrnEgMeefibrocEu myself.


Think of those fields as secondary password fields and act accordingly.

Diceware can also be useful for when they need to be spoken on the phone. With the right amount of words (7 or more) it has reasonably good entropy too.


I just tell them my dog's name was Beez6Ich8eeso5uil6Pha4omailai2fu and store it in my Dropbox-stored KeePass database.


Well we just used to call him old Bee..


Thank you for answering the security question Mr. Stavros. I'll accept "Bee" as your dog's name. To which offshore bank did you say you wanted to transfer the money ?


Easiest things on the planet to mine, too - the below lark appears to still work, from its ongoing prevalence.

"Your superhero name is your first pet's name, your mother's maiden name, and the street you grew up on - mine is Muffy Hitler Queen, what's yours?"


Recently United Airlines changed their online security policy and added security questions. The answers to which must be chosen from dropdowns.


I always mash the keyboard for those




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: