Earlier quoted context omitted.
> Apparently when some very incompetent bank workers ask your security questions if the frauder says "oh it was just a random string, I do not remember" they give access to your account. This has actually worked for me more than once, so...yeah. I find nonsense/ridiculous answers to be safer than than random letters. Make and model of first car? 2047 MAIBATSU MONSTROSITY Where did you meet the love of your life? A ME…
My problem with that is remembering and generating it. First problem is easy to solve with password managers but you still have to generate an ideally long car name with no bias. If you put some bias, then it might be backtracked. You can have a dictionary of possible car names but then you're open to attack if that dictionary is found or predictable enough that someone else can compile that list. It just doesn't fee…
Don't give away historic details about yourself
141–150 of 207 posts
Re: Don't give away historic details about yourself
#142Earlier quoted context omitted.
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
Who in the world thought this was a good idea!? I can hardly think of a less secure way to ask security questions. You should name and shame; there’s a minimum bar everyone should uphold and this is far below it.
Re: Don't give away historic details about yourself
#143Earlier quoted context omitted.
SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.
In fact this is a method of stealing people's investment accounts -- a victim with an investment account is identified. That person's phone number is then "captured". The investment account asks for 2FA and the thief now has that phone #, and "authenticates." The next step is to transfer all the money in the account to a third party and disappear. It's disgusting how twisted these criminal activities have become.
Every alternative way in is a larger attack area.
Re: Don't give away historic details about yourself
#144The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
What's worse these days is, ever since the Equifax breach, certain institutions have taken to asking me for the last 6 digits of my social (or even worse... all of them...)
http://www.ssofficelocation.com/social-security-number-prefi...
Re: Don't give away historic details about yourself
#145Earlier quoted context omitted.
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
Who in the world thought this was a good idea!? I can hardly think of a less secure way to ask security questions. You should name and shame; there’s a minimum bar everyone should uphold and this is far below it.
This was the wrong solution.
Re: Don't give away historic details about yourself
#146Earlier quoted context omitted.
Are you kidding? Those are terrible passwords, and there’s already some script kiddie out there with a password list containing the top 10 billion book, music, tv show, and movie quotes. A good password has entropy, which is not a property of the alphanumeric string but of the process used to create it. Could your password generation method plausibly have produced 2^60 alternative passwords with equal probability? Pr…
"One ring to rule them all" is a terrible password, but "the dark lord's unique jewelry" might be a good one.
ペルソナは心の力 - read as "perusona wa kokoro no chikara"
Then I've replaced it with the English spelling of Persona -> "persona wa kokoro no chikara"
Then I replace chikara with a misreading - when I first learnt the characters, I mixed up 力 (chikara) with the katakana カ (ka) and often read both as ka -> "persona wa koroko no ka"
Then remove the (unneeded) spaces and add a "!" for good measure -> "personawakokoronoka!"
Dead easy for me to remember, but (I believe) difficult to derive/guess or dictionary attack (especially if I start with a longer sentence).
Re: Don't give away historic details about yourself
#147Earlier quoted context omitted.
They stop making new movies when you answer that question, thus ensuring your answer will remain valid.
That still doesn't stop you stumbling across an older film that you've never watched before, and then finding that you like it more than your "favourite".
Re: Don't give away historic details about yourself
#148Re: Don't give away historic details about yourself
#149Earlier quoted context omitted.
I like the idea of trolling people with security questions that you never actually use in a password-recovery workflow. What is your third favorite vacation spot? Would you rather fight a horse-sized duck or 100 duck-sized horses? For how much money would you go to jail for 1 year?
I was always a fan of these nihilist security questions: https://www.mcsweeneys.net/articles/nihilistic-password-secu...
https://www.newyorker.com/humor/daily-shouts/insecurity-ques...
Re: Don't give away historic details about yourself
#150United Airlines is probably one of the worst I've seen: http://www.slate.com/articles/technology/future_tense/2016/0... Not even free text but only allowing a limited set of answers via dropdown menus (most of the provided answers don't apply to me either, so it's both insecure for them and hard for me to remember as well)
The official United response on FlyerTalk (linked from the Slate article) is naïve to say the least:
> We purposely chose to use preregistered answers as our first form of enhanced authentication to protect against this keystroke logging. We need to ensure that all of our customers have a high degree of security and our research also indicated that some customers had self-entered security answers that would be very easy to guess.
Wow.
Source: https://www.flyertalk.com/forum/26212495-post233.html