Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

121–130 of 207 posts

Re: Don't give away historic details about yourself

#122

Earlier quoted context omitted.

When I signed up for a new bank account the bank rep had me set up online banking on their computer. When she asked me for my security questions and answers she was baffled when I told her the question selected didn't matter, and the answer was a seemingly random alphanumeric string. I told her that I don't know her, or her machine. For now, I'll be setting it as quick, easy for me to remember, string and I'll change…

I do this too, I was told to add something like "PLEASE MATCH THIS TEXT, THIS IS NOT A RANDOM STRING" at the beginning. Apparently when some very incompetent bank workers ask your security questions if the frauder says "oh it was just a random string, I do not remember" they give access to your account.

Mistakes happen, people miss-key, database entries get put in the wrong field, ... I imagine that if the entry didn't match the format for the field then you're open to the bank clerk being socially engineered more easily.

It's like if a password field said 'no punctuation, maximum 8 characters' and your password was much longer with lots of characters; particularly if it looks random it could appear to be a corruption.

I imagine the range of given names gives most password entropy, so "family pet" might be the best question to choose, especially if you never had a family pet.

Re: Don't give away historic details about yourself

#123
post #64

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

Exactly. But having to come up with fake answers to stupid questions and track them, is just proof of how bad some people are at their job. Apple still does this kind of crap. Actual questions: In what city did your parents meet? What is the first name of your best friend in high school? Recently an airport public WiFi in a major city in Europe wanted my birthdate and the agreement language said that I acknowledge ev…

One thing that really drives me crazy is that Apple asks me my security questions even if I enter my correct password because I haven't logged in for a while. I didn't saved the answers (and this is my fault) but anyway I would have done it in the KeePass database that contains also the password, so no additional security.

Re: Don't give away historic details about yourself

#124
post #85

Earlier quoted context omitted.

I'm assuming "SMS" means true, original SMS. Most people with iPhones, for instance, are using encrypted iMessage, but the code sent to you from a service provider (Microsoft, etc) will be done over straight SMS, not iMessage. Those basic SMS messages can be intercepted by a duplicated SIM card or setting a phone up with different firmware to basically listen to everything around it, including receiving SMS messages.…

SMS can also be captured by calling the customer service for your cell company and saying "I'm out of the country and lost my phone, can you forward texts to INSERT NUMBER HERE for me?"

use a burner sim like: https://www.twilio.com/wireless/pricing. presumably twillio is harder to social engineer than [big telecom]

Re: Don't give away historic details about yourself

#125
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

yup, folks should give plausible but wrong answers to those questions and then put them in your password manager because you'll definitely forget.

Re: Don't give away historic details about yourself

#126
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

Who in the world thought this was a good idea!? I can hardly think of a less secure way to ask security questions. You should name and shame; there’s a minimum bar everyone should uphold and this is far below it.

Re: Don't give away historic details about yourself

#127

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I know it may be to my detriment some day, but I just use the same answer for all secret questions everywhere. It has nothing to do with anything I've ever encountered, anywhere I've ever been, or anyone I've ever known. I do use a password manager, but my bank will ask secret questions to register new devices, so I've resorted to this tactic to reduce the hassle.

Let's hope you won't have to regret sharing this information too publicly...

Re: Don't give away historic details about yourself

#129

What is with perpetuating this idea that people have some duty to be responsible for companies' broken security practices? You're unable to prevent their fuckups - so you can only take steps to make sure you don't end up on the hook or otherwise severely impacted due to their negligence. It's not my job to avoid repeating public information like mother's maiden name, historical addresses, etc. Nor is it my job to wor…

I don't really see "responsibility" as a useful lens. If you give away information that can be used to reset your passwords, you make it more likely that someone can reset your passwords.

Assigning blame is something people do to make themselves feel better after bad things happen. Making it less likely for bad things to happen in the first place may or may not be worth the time and effort, but whether or not you're morally responsible is a pretty meaningless question.

Re: Don't give away historic details about yourself

#130

I use 1Password as a password vault. Some years ago, I decided to start lying for secret question answer challenges. I use 1Password to generate a string of garbage (without numbers or symbols, 25 characters long) and keep that answer in a custom field in the 1Password vault. I've tagged those entries with a security tag to find all accounts with secret Q&A information. I am paranoid about back ups because if god for…

One problem with this is social engineering... someone could call the company to recover their password and say that they entered garbage for the security question...

I started to enter passphrases instead

Post reply on HN