What is with perpetuating this idea that people have some duty to be responsible for companies' broken security practices? You're unable to prevent their fuckups - so you can only take steps to make sure you don't end up on the hook or otherwise severely impacted due to their negligence. It's not my job to avoid repeating public information like mother's maiden name, historical addresses, etc. Nor is it my job to wor…
Don't give away historic details about yourself
131–140 of 207 posts
Re: Don't give away historic details about yourself
#132The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
Re: Don't give away historic details about yourself
#133URL: https://www.youtube.com/watch?v=95jHwnAhHgU
This contains both scenes - how they steal the information and how they abused it.
Re: Don't give away historic details about yourself
#134Earlier quoted context omitted.
When I signed up for a new bank account the bank rep had me set up online banking on their computer. When she asked me for my security questions and answers she was baffled when I told her the question selected didn't matter, and the answer was a seemingly random alphanumeric string. I told her that I don't know her, or her machine. For now, I'll be setting it as quick, easy for me to remember, string and I'll change…
I do this too, I was told to add something like "PLEASE MATCH THIS TEXT, THIS IS NOT A RANDOM STRING" at the beginning. Apparently when some very incompetent bank workers ask your security questions if the frauder says "oh it was just a random string, I do not remember" they give access to your account.
I also just avoid setting them where ever possible -- it's basically only for banks (some random website isn't going to get real answers to security questions).
Re: Don't give away historic details about yourself
#135The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
Re: Don't give away historic details about yourself
#136Earlier quoted context omitted.
To be fair, to actually exploit this the scammers would have to know you put in a random string. A human customer service process is not really subject to dictionary attacks.
Except customer service is often trying to help you remember, and you can guess a few times.... a scammer will say something like, "Oh man, I can't remember what I picked... sometimes I choose a random car model, but sometimes I just put random characters", and if either is true, the customer service rep might confirm it.
Definitely more security, but _maybe_ slightly too far in the other direction.
Re: Don't give away historic details about yourself
#137I don't know which annoys me more, the easy to guess security questions or those with mutable answers. Things like: What's your favorite vacation spot? What's your favorite food? Often you're stuck having to choose between something other people know or can figure out (where you were born) and something that may well change over time.
I like the idea of trolling people with security questions that you never actually use in a password-recovery workflow. What is your third favorite vacation spot? Would you rather fight a horse-sized duck or 100 duck-sized horses? For how much money would you go to jail for 1 year?
Re: Don't give away historic details about yourself
#138The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
Re: Don't give away historic details about yourself
#139And then if you do a password recovery, they email you a new password (which is like 6 characters) WHICH YOU THEN CAN'T CHANGE (except if they email you another new one).
It's a joke. I had to come up with a security question so I just make them sarcastic: "In what world is this secure?"
Re: Don't give away historic details about yourself
#140The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
I have always wondered what happens if the receiving site is someone like IRS or any such government entity. If one of the questions was "where was your father/mother born?" and you gave a fake answer.. are you now "lying to the government"? There are lot of questions that can have provable right/wrong answers - assuming someone powerful is out to get you. Imagine that being used against someone!
This is not, by the way, a strictly government related concern. If you lie on a credit card application (and are caught), you're going to have a bad time. But the signed bit of the application is usually completely different from where you're asked to set up "security questions".