Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

191–200 of 207 posts

Re: Don't give away historic details about yourself

#191
post #186

Earlier quoted context omitted.

Here's a fourth that was actually responsible for me starting to just use generated passwords for those as well. They told me my answer wasn't valid. According to them, it's impossible for your mothers maiden name to have less than six characters :/

Funny story - I had an old short-length insecure password on a website that I hadn't used for years. I decided to log in and change it to a randomly generated secure password. However, they had upgraded their off the shelf software some time over the last 4-5 years to a newer version. The problem was, on their password change page the "new password" field had a minimum length of 8 characters, however the "OLD passwor…

> edited the javascript validation

You probably broke law there O_O

Re: Don't give away historic details about yourself

#192
post #191
post #186

Earlier quoted context omitted.

Funny story - I had an old short-length insecure password on a website that I hadn't used for years. I decided to log in and change it to a randomly generated secure password. However, they had upgraded their off the shelf software some time over the last 4-5 years to a newer version. The problem was, on their password change page the "new password" field had a minimum length of 8 characters, however the "OLD passwor…

> edited the javascript validation You probably broke law there O_O

[deleted]

Re: Don't give away historic details about yourself

#193
post #98

Earlier quoted context omitted.

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

Who in the world thought this was a good idea!? I can hardly think of a less secure way to ask security questions. You should name and shame; there’s a minimum bar everyone should uphold and this is far below it.

If my bank had such weak security I wouldn't want to tell the internet where I bank.

Re: Don't give away historic details about yourself

#194
post #186

Earlier quoted context omitted.

Here's a fourth that was actually responsible for me starting to just use generated passwords for those as well. They told me my answer wasn't valid. According to them, it's impossible for your mothers maiden name to have less than six characters :/

Funny story - I had an old short-length insecure password on a website that I hadn't used for years. I decided to log in and change it to a randomly generated secure password. However, they had upgraded their off the shelf software some time over the last 4-5 years to a newer version. The problem was, on their password change page the "new password" field had a minimum length of 8 characters, however the "OLD passwor…

I had a similar experience with a city bill pay website, except in this situation it was a new account and they simply didn't prevent me from setting the password to something long in the first place, so once my account was created I wasn't allowed in. And because you need to log in once to verify your email, I couldn't reset the damn thing either.

Re: Don't give away historic details about yourself

#195
post #193

Earlier quoted context omitted.

Who in the world thought this was a good idea!? I can hardly think of a less secure way to ask security questions. You should name and shame; there’s a minimum bar everyone should uphold and this is far below it.

If my bank had such weak security I wouldn't want to tell the internet where I bank.

[deleted]

Re: Don't give away historic details about yourself

#196
post #116

Earlier quoted context omitted.

> I'll generally generate additional passwords with my PW manager for each question and store them there. You have to be a bit careful with that, since some banks like to use those answers as "second factors"* when you call them. So I've gotten in the habit of using diceware-style passphrases for those, as those work over the phone better than pure white noise passwords. *extreme air quotes

I also generate additional passwords, but after reading my additional password over the phone to an agent that pretty clearly would have accepted (it's giberish), I've since started storing what I deem to be a reasonable answer to the question. A random movie for the 'favorite movie' question, random name for best friend, etc.

That's probably the best solution. It would be nice to have a dictionary of answers to these sorts of things (a dictionary of names, a dictionary of cities, etc) to quickly generate these in a truly random way to try and eke a little bit more entropy out of it.

Re: Don't give away historic details about yourself

#197
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

What bank is it?

Re: Don't give away historic details about yourself

#198

Earlier quoted context omitted.

DNA can be harvested from dead hair, skin or spit even, so anyone with access to your physical environment could obtain your DNA.

It should really be considered public information. You leave your DNA everywhere you go. Like all biometrics, the most it should be used for is identification, never authentication. You're still going to need a secret, and maybe also a token.

[deleted]

Re: Don't give away historic details about yourself

#199
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

Then don't make it stick out.

Some people think they're too smart for putting a random string as their mother's maiden name. I'd rather just put something that looks like a name there.

Re: Don't give away historic details about yourself

#200
post #11

So let's get rid of security questions and we can just carry on? There should be no harm in disclosing information which is already known by dozens of people, like your mother's maiden name or your first pet. Going around and telling everyone " keep your history concealed! " is just silly and will get you the tinfoil hat label, making any future security advice useless. I typically agree with him but this just seems…

I am not entirely sure I agree. Maybe it's slightly paranoid, but I find it shocking how much information people share on the Internet.

I still abide by the old idea that you never share personal information on the Internet.

Post reply on HN