Don't give away historic details about yourself
151–160 of 207 posts
Re: Don't give away historic details about yourself
#152Earlier quoted context omitted.
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
Yesterday, I was logging onto Australian MyGov site, and forgot the password, it sent SMS code for reset to my mobile phone, but then would not let me proceed without answering the secret questions. I usually put last word of the question sentence as an answer itself because I can't be bothered, but it was not the case this time. Not a great experience when they threaten lock out of account, and you have to go link a…
Some of it is legacy - integrating systems built throughout the last three decades.
Some of it is management - they fired multiple teams partway through, with 100% turnover. They also massively underfunded said teams, devoting the majority of funding to PR. Also some... Interesting technical policies, like banning version control and advocating regular backups instead. (Something to do with code "theft protection").
Some of it was technical issues - different integration teams were given different browser compatibility goals. Some teams were told they must use PHP and Apache, others they must use NodeJS and nginx. Often for related parts of the UI.
If you want to know how to screw up a multi-million dollar project, look no farther.
(Source: Worked with a team leader during one of the "fire everyone" times.)
Re: Don't give away historic details about yourself
#153Earlier quoted context omitted.
SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.
Doesn’t 2fa mean password + phone? How is getting the phone sufficient?
Re: Don't give away historic details about yourself
#154I use 1Password as a password vault. Some years ago, I decided to start lying for secret question answer challenges. I use 1Password to generate a string of garbage (without numbers or symbols, 25 characters long) and keep that answer in a custom field in the 1Password vault. I've tagged those entries with a security tag to find all accounts with secret Q&A information. I am paranoid about back ups because if god for…
One problem with this is social engineering... someone could call the company to recover their password and say that they entered garbage for the security question... I started to enter passphrases instead
Re: Don't give away historic details about yourself
#155Earlier quoted context omitted.
SMS can also be captured by calling the customer service for your cell company and saying "I'm out of the country and lost my phone, can you forward texts to INSERT NUMBER HERE for me?"
use a burner sim like: https://www.twilio.com/wireless/pricing . presumably twillio is harder to social engineer than [big telecom]
Also, keep in mind that an adversary can grab your text messages even without any social engineering skills; they just need to rent a cell tower somewhere in the world and advertise your number as roaming there [2]
As you implied, it is probably safer to use a different number than your main one for SMS-based 2FA (the much-maligned security through obscurity), but before you go out and buy a second phone plan, consider issues such as whether you will be able to receive SMS messages while traveling internationally.
[1] https://support.twilio.com/hc/en-us/articles/223181668-Can-T...
Re: Don't give away historic details about yourself
#156Earlier quoted context omitted.
SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.
In fact this is a method of stealing people's investment accounts -- a victim with an investment account is identified. That person's phone number is then "captured". The investment account asks for 2FA and the thief now has that phone #, and "authenticates." The next step is to transfer all the money in the account to a third party and disappear. It's disgusting how twisted these criminal activities have become.
Re: Don't give away historic details about yourself
#157Earlier quoted context omitted.
I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there. That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singula…
The ones I love are those with questions like "What was the first city you visited" and they give you a multiple choice of like ten cities, none of which you may ever actually have visited.
Re: Don't give away historic details about yourself
#158Earlier quoted context omitted.
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
This, too, was my problem. I don't want to give out real answers to my security question for two (slightly contradictory) reasons. The first is: what if this site is hacked? Now my security question answers are floating around for use on other sites that ask similar questions. The second is: some of these questions are pretty easy to find the answer to, or guess. So I used a generated string for those questions, too.…
Re: Don't give away historic details about yourself
#159The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…
I'd at least like the option to use Touch ID/Face ID only.
Re: Don't give away historic details about yourself
#160The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
What's worse these days is, ever since the Equifax breach, certain institutions have taken to asking me for the last 6 digits of my social (or even worse... all of them...)