Live data from Hacker News

Schneier on Security: Fun with Secret Questions

schneier.com

11–20 of 20 posts

Re: Schneier on Security: Fun with Secret Questions

#11
post #7
post #6

Entertaining (though I've already read this one...). I have a more interesting game I play with bank security questions that's more useful, though -- and applies to the most common usage (where the bank provides the question to you). Simply this -- for each question, imagine how easily you could guess the answer even knowing nothing about the account owner. I'm not talking about real analysis here, just roughly mappi…

Here is a worse one: > What is the make of your first car? The number of relatively common car makers is really low, and when you factor in the fact that most people don't get a really high-end car as their first car, 5 or 6 makers are going to cover a really high percentage (Ford, Chevrolet, Toyota, and Honda would cover most, I'd guess). If you factor in make AND model, we're still talking in the low hundreds of po…

> What is the make of your first car?

Winston Churchill.

Re: Schneier on Security: Fun with Secret Questions

#12

While entertaining, choosing the question "What is the air speed velocity of a laden swallow?" is not particularly good security.

That applies to many of them. It's clearly just for fun. Quotes are no good. If it's a quote from media like music, movies, book, or TV, the response can usually be googled, if it's not known already. If it's a personal quote, someone who knows you might know it.

Re: Schneier on Security: Fun with Secret Questions

#13
post #11
post #7

Earlier quoted context omitted.

Here is a worse one: > What is the make of your first car? The number of relatively common car makers is really low, and when you factor in the fact that most people don't get a really high-end car as their first car, 5 or 6 makers are going to cover a really high percentage (Ford, Chevrolet, Toyota, and Honda would cover most, I'd guess). If you factor in make AND model, we're still talking in the low hundreds of po…

> What is the make of your first car? Winston Churchill.

If you're clued in on security, you can certainly use the fields to enter unrelated answers. A random 20 characters would be better than Winston Churchill.

But it probably goes without saying that if following the instructions (and putting in an actual answer...) makes you insecure, the model is broken.

Re: Schneier on Security: Fun with Secret Questions

#14
I almost always pick something like "What's your favorite color?" and answer with random noise (say "a3tcuh487wchaowiudh23doch3298ahraui"). The rationale is that if I forget my password, I'll likely forget the secret question as well. I only want the secret question to be as hard, or harder, to guess than my password.

I wonder though, if the human at the other end will accept "just a bunch of letters and numbers" as a correct answer.

Re: Schneier on Security: Fun with Secret Questions

#16

While I have a hard time imagining Bruce just lifted someone else's blog post without crediting (more likely it was passed on to him in conversation?), this post predates Schneier's by over a year: http://tcoverride.blogspot.com/2011/05/security-questions.ht... .

Check the Schneier date again.

Re: Schneier on Security: Fun with Secret Questions

#17

While I have a hard time imagining Bruce just lifted someone else's blog post without crediting (more likely it was passed on to him in conversation?), this post predates Schneier's by over a year: http://tcoverride.blogspot.com/2011/05/security-questions.ht... .

Hardly. Rather, it would seem to be the other way around.

Re: Schneier on Security: Fun with Secret Questions

#19

While I have a hard time imagining Bruce just lifted someone else's blog post without crediting (more likely it was passed on to him in conversation?), this post predates Schneier's by over a year: http://tcoverride.blogspot.com/2011/05/security-questions.ht... .

Check the Schneier date again.

lol, repost. My bad.
Post reply on HN