Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

61–70 of 207 posts

Re: Don't give away historic details about yourself

#61

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there.

That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singular favorite things? How the hell should I know what my favorite movie was 3 years ago when I rushed through some account creation process on some random website?

Re: Don't give away historic details about yourself

#62
post #17

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…

Even if humans were excellent at remembering passwords - I look into my pwd manager and I have over 500 passwords. OK, I am not a common case - I have passwords from various systems, logins, keys, etc. there. But even a common person can have accounts on a hundred sites. And now add rotation requirements. Nobody outside of trained mnemotechnic performers can remember those - and keep them up to date for years. It's not just humanly possible in current environment. Either you use one password virtually everywhere, or you don't remember any of them.

Re: Don't give away historic details about yourself

#63

Earlier quoted context omitted.

> Humans are TERRIBLE at remembering passwords This is the main problem and we created this problem. Over the last 30 years we worked so hard to make passwords weird and not even that hard for computers to try find. If your password is a sentence that you know by heart, say your favorite quote, the motto of your country, of your school, or some cool fact etc... your password would be (1) safer and (2) easier for you…

Are you kidding? Those are terrible passwords, and there’s already some script kiddie out there with a password list containing the top 10 billion book, music, tv show, and movie quotes. A good password has entropy, which is not a property of the alphanumeric string but of the process used to create it. Could your password generation method plausibly have produced 2^60 alternative passwords with equal probability? Pr…

Are you kidding?

Which is longer, the alphabet or the dictionary?

There's a hell of a lot more words in any language than there are characters that make them up.

N case insensitive words is far better than N character password from the normal set of characters (alphanumeric + special characters).

Even if you restrict the combinations of words to grammatically correct sentences there's still more combinations than there are of for the same number of characters

That still holds even if you make assumptions about sentence structure, common word combinations, etc, etc. There's a lot of words out there.

Re: Don't give away historic details about yourself

#64

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

Exactly. But having to come up with fake answers to stupid questions and track them, is just proof of how bad some people are at their job.

Apple still does this kind of crap. Actual questions:

In what city did your parents meet? What is the first name of your best friend in high school?

Recently an airport public WiFi in a major city in Europe wanted my birthdate and the agreement language said that I acknowledge everything I'm stating is true and correct. It's so blatantly asinine. I didn't even bother to look if it cited some EU law that lying is a crime, I just said fuck it, and went without Internet for a few hours.

Re: Don't give away historic details about yourself

#65
post #61

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there. That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singula…

They stop making new movies when you answer that question, thus ensuring your answer will remain valid.

Re: Don't give away historic details about yourself

#66
post #4

Underlying this, don't ever answer these stupid 'account security' questions truthfully. Better to make something up and store it in your password manager along with other account info. I'd normally be tempted to put in the same types of random passwords I normally use, eg: > What was the name of the street you grew up on? L9Pro840Of9KNIGfKD4tf8tOwTG9Dcqj Unfortunately, I've heard you can talk to customer support and…

"Underlying this, don't ever answer these stupid 'account security' questions truthfully. Better to make something up and store it in your password manager along with other account info.

I'd normally be tempted to put in the same types of random passwords I normally use, eg:

> What was the name of the street you grew up on? L9Pro840Of9KNIGfKD4tf8tOwTG9Dcqj"

that's what I do too:

Mother's maiden name: jklqedwsfjkl;ewdfq;jklqwe First car: iohwrqefhiokqwefiohp0u-0ui

and so on

Re: Don't give away historic details about yourself

#68

Earlier quoted context omitted.

I do the same. Once, a bank asked me over the phone what my high school mascot was (or whatever) to verify that I was really me. I hadn't expected them to use the question in this way, so I wasn't prepared to look up my answer. Knowing whatever randomly generated string I'd used was likely unpronounceable I answered, "I could teach you to pronounce it, but first you'd need to cut out your tongue." which they accepted…

> which they accepted That's not great.

I confirm here. Another bank accepted for me.

Re: Don't give away historic details about yourself

#69

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I nearly lost my google account that way. I gave a nonsense answer totally unrelated to the question as I knew I would never forget my password. Was in a different country, got locked out, had to give my security question answer.... oh dear. After about 3 months occasionally sitting down and just trying out random things I meant have entered I managed to get it back.

I've lost an account on another service this way. They did a forced password reset. To set a new password, you had to go through the forgot password flow, receive the email, and then answer the security questions. You would think that if the passwords were compromised, the (probably plain text) security questions were certainly compromised.

Re: Don't give away historic details about yourself

#70
What is with perpetuating this idea that people have some duty to be responsible for companies' broken security practices? You're unable to prevent their fuckups - so you can only take steps to make sure you don't end up on the hook or otherwise severely impacted due to their negligence.

It's not my job to avoid repeating public information like mother's maiden name, historical addresses, etc.

Nor is it my job to worry about whether a bank will bypass confirming "secret question" strings for anyone stating they're just random letters.

As an non-responsible third party to any possible identity-based fraud, the only thing I see the need/ability to do to protect myself is watch transactions on my accounts (automation helps here, eg OFX), and be prepared to send demand letters/sue the surveillance companies for libel if they start spouting off that "I" opened accounts that I did not.

Feeling any more responsible than this is just helping to continue their negligent/lazy/broken-ass business processes.

Post reply on HN