Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

111–120 of 207 posts

Re: Don't give away historic details about yourself

#113
post #104

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I have always wondered what happens if the receiving site is someone like IRS or any such government entity. If one of the questions was "where was your father/mother born?" and you gave a fake answer.. are you now "lying to the government"? There are lot of questions that can have provable right/wrong answers - assuming someone powerful is out to get you. Imagine that being used against someone!

I'm not even 100% sure where my mother was born. Her family moved around a lot back then (military) and her and each of her siblings were born in a different city. She passed away almost two decades ago, so it's not like it would ever come up now. I guess I could try to find her birth certificate somewhere in my dad's papers assuming he still/ever had a copy.

Re: Don't give away historic details about yourself

#114

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I know it may be to my detriment some day, but I just use the same answer for all secret questions everywhere. It has nothing to do with anything I've ever encountered, anywhere I've ever been, or anyone I've ever known. I do use a password manager, but my bank will ask secret questions to register new devices, so I've resorted to this tactic to reduce the hassle.

Re: Don't give away historic details about yourself

#115
post #61

Earlier quoted context omitted.

I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there. That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singula…

Bruce Springsteen - Born in the USA lifelong favorite song. (although I must say that the Eye of the Tiger comes very very close)

Now we know your age, too!

Re: Don't give away historic details about yourself

#116
post #61

Earlier quoted context omitted.

I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there. That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singula…

> I'll generally generate additional passwords with my PW manager for each question and store them there. You have to be a bit careful with that, since some banks like to use those answers as "second factors"* when you call them. So I've gotten in the habit of using diceware-style passphrases for those, as those work over the phone better than pure white noise passwords. *extreme air quotes

I also generate additional passwords, but after reading my additional password over the phone to an agent that pretty clearly would have accepted (it's giberish), I've since started storing what I deem to be a reasonable answer to the question. A random movie for the 'favorite movie' question, random name for best friend, etc.

Re: Don't give away historic details about yourself

#117
post #26

I've never provided literal, logical answers to security questions, as even without sharing the answers elsewhere, the logical ones would be entirely too easy to guess. "Make of first car?" There are only so many vehicle brands reasonably accessible in a geographical area - not hard to brute force. "City of birth?" Common knowledge among all my friends. It's too easy. An appropriate answer to "Make of first car?" wou…

So it's a common trope in science fiction that super-intelligences will resurrect historical people using DNA and mumble-mumble to get their memories.

We finally have a plausible answer to how computers a thousand years from now will be able to reconstruct the details of your life: security questions.

Re: Don't give away historic details about yourself

#118
post #4

Underlying this, don't ever answer these stupid 'account security' questions truthfully. Better to make something up and store it in your password manager along with other account info. I'd normally be tempted to put in the same types of random passwords I normally use, eg: > What was the name of the street you grew up on? L9Pro840Of9KNIGfKD4tf8tOwTG9Dcqj Unfortunately, I've heard you can talk to customer support and…

Yep! I use the secret questions as secondary passwords that are also saved to the safe.

Re: Don't give away historic details about yourself

#119
post #85
post #15

Earlier quoted context omitted.

SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.

I'm assuming "SMS" means true, original SMS. Most people with iPhones, for instance, are using encrypted iMessage, but the code sent to you from a service provider (Microsoft, etc) will be done over straight SMS, not iMessage. Those basic SMS messages can be intercepted by a duplicated SIM card or setting a phone up with different firmware to basically listen to everything around it, including receiving SMS messages.…

SMS can also be captured by calling the customer service for your cell company and saying "I'm out of the country and lost my phone, can you forward texts to INSERT NUMBER HERE for me?"

Re: Don't give away historic details about yourself

#120
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

This, too, was my problem. I don't want to give out real answers to my security question for two (slightly contradictory) reasons. The first is: what if this site is hacked? Now my security question answers are floating around for use on other sites that ask similar questions. The second is: some of these questions are pretty easy to find the answer to, or guess. So I used a generated string for those questions, too. Generally worked, but sometimes made for some interesting phone calls. "My mothers maiden name is . You can guess why she took my father's."

Then they started reading back random choices, which made it pretty easy to guess what I picked.

Post reply on HN