I use 1Password as a password vault. Some years ago, I decided to start lying for secret question answer challenges. I use 1Password to generate a string of garbage (without numbers or symbols, 25 characters long) and keep that answer in a custom field in the 1Password vault. I've tagged those entries with a security tag to find all accounts with secret Q&A information. I am paranoid about back ups because if god for…
Don't give away historic details about yourself
161–170 of 207 posts
Re: Don't give away historic details about yourself
#162The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…
I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…
Re: Don't give away historic details about yourself
#163Earlier quoted context omitted.
Yesterday, I was logging onto Australian MyGov site, and forgot the password, it sent SMS code for reset to my mobile phone, but then would not let me proceed without answering the secret questions. I usually put last word of the question sentence as an answer itself because I can't be bothered, but it was not the case this time. Not a great experience when they threaten lock out of account, and you have to go link a…
MyGov is a dumpster fire of bad choices. Some of it is legacy - integrating systems built throughout the last three decades. Some of it is management - they fired multiple teams partway through, with 100% turnover. They also massively underfunded said teams, devoting the majority of funding to PR. Also some... Interesting technical policies, like banning version control and advocating regular backups instead. (Someth…
Re: Don't give away historic details about yourself
#164My approach to this problem is, given the fact that I use a password manager[1], the following: I chose a random question from the proposed set, and then generate a random password and use it as a "secret answer". Given the fact that 99% of the time the security question will be checked by a computer, the security question effectively becomes a secondary password.
But as I write I am just realizing that the security question is probably not stored in a secure manner (salt + hash) anyway, so in the event of a data leak well that account is f*ed up anyway.
Also, this has always seemed problematic to me: my secret question is supposed to be something I "just know" but... Let's assume the question is "what was your favorite teacher at elementary school" and my answer is "Mrs Chtulu"... What if I come back in a year and instinctively type "Miss Chtulu"? Do I have to remember the spelling I used? The capitalization? What if when I was 13 i did not bother capitalizing names and surnames properly but now I do ?
--
[1] - if I happen to lose the password file, I'm probably in the middle of way bigger problems.
Re: Don't give away historic details about yourself
#165Earlier quoted context omitted.
I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.
yup, folks should give plausible but wrong answers to those questions and then put them in your password manager because you'll definitely forget.
Re: Don't give away historic details about yourself
#166Earlier quoted context omitted.
I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…
> Humans are TERRIBLE at remembering passwords This is the main problem and we created this problem. Over the last 30 years we worked so hard to make passwords weird and not even that hard for computers to try find. If your password is a sentence that you know by heart, say your favorite quote, the motto of your country, of your school, or some cool fact etc... your password would be (1) safer and (2) easier for you…
> may the force be with you
> call me ishmael
These are all in my password cracking dictionary.
Re: Don't give away historic details about yourself
#167Earlier quoted context omitted.
This, too, was my problem. I don't want to give out real answers to my security question for two (slightly contradictory) reasons. The first is: what if this site is hacked? Now my security question answers are floating around for use on other sites that ask similar questions. The second is: some of these questions are pretty easy to find the answer to, or guess. So I used a generated string for those questions, too.…
I have a third problem -- often times, the list of questions they ask are non-sense to me. "What is your favorite food?" I don't have a favorite, and can't think of anything that I'd remember later. "What was the name of your first pet?" I never had a pet. "What was the name of your high school sweetheart?" Gee, thanks a lot for stirring up bad memories.
According to them, it's impossible for your mothers maiden name to have less than six characters :/
Re: Don't give away historic details about yourself
#168Earlier quoted context omitted.
This, too, was my problem. I don't want to give out real answers to my security question for two (slightly contradictory) reasons. The first is: what if this site is hacked? Now my security question answers are floating around for use on other sites that ask similar questions. The second is: some of these questions are pretty easy to find the answer to, or guess. So I used a generated string for those questions, too.…
I have a third problem -- often times, the list of questions they ask are non-sense to me. "What is your favorite food?" I don't have a favorite, and can't think of anything that I'd remember later. "What was the name of your first pet?" I never had a pet. "What was the name of your high school sweetheart?" Gee, thanks a lot for stirring up bad memories.
Re: Don't give away historic details about yourself
#169Earlier quoted context omitted.
I have a third problem -- often times, the list of questions they ask are non-sense to me. "What is your favorite food?" I don't have a favorite, and can't think of anything that I'd remember later. "What was the name of your first pet?" I never had a pet. "What was the name of your high school sweetheart?" Gee, thanks a lot for stirring up bad memories.
Here's a fourth that was actually responsible for me starting to just use generated passwords for those as well. They told me my answer wasn't valid. According to them, it's impossible for your mothers maiden name to have less than six characters :/
Re: Don't give away historic details about yourself
#170The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…