Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

101–110 of 207 posts

Re: Don't give away historic details about yourself

#101

I've been really concerned about how freely people seem to give their DNA away to testing services like 23andMe or Ancestry DNA. I just get this feeling that in the next few decades genetic code may become the pinnacle of biometrics as a part of multi-factor authentication. i.e. something I know, something I have, and something I am. And DNA databases that are potentially loosely secured, or at least secured as well…

DNA can be harvested from dead hair, skin or spit even, so anyone with access to your physical environment could obtain your DNA.

Yeah, I was considering more along the lines of massive compromising of remote authentication mechanisms, not spycraft targeting.

Re: Don't give away historic details about yourself

#103

I've been really concerned about how freely people seem to give their DNA away to testing services like 23andMe or Ancestry DNA. I just get this feeling that in the next few decades genetic code may become the pinnacle of biometrics as a part of multi-factor authentication. i.e. something I know, something I have, and something I am. And DNA databases that are potentially loosely secured, or at least secured as well…

DNA can be harvested from dead hair, skin or spit even, so anyone with access to your physical environment could obtain your DNA.

It should really be considered public information. You leave your DNA everywhere you go.

Like all biometrics, the most it should be used for is identification, never authentication.

You're still going to need a secret, and maybe also a token.

Re: Don't give away historic details about yourself

#104

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I have always wondered what happens if the receiving site is someone like IRS or any such government entity. If one of the questions was "where was your father/mother born?" and you gave a fake answer.. are you now "lying to the government"?

There are lot of questions that can have provable right/wrong answers - assuming someone powerful is out to get you. Imagine that being used against someone!

Re: Don't give away historic details about yourself

#105
post #51

I don't know which annoys me more, the easy to guess security questions or those with mutable answers. Things like: What's your favorite vacation spot? What's your favorite food? Often you're stuck having to choose between something other people know or can figure out (where you were born) and something that may well change over time.

I like the idea of trolling people with security questions that you never actually use in a password-recovery workflow. What is your third favorite vacation spot? Would you rather fight a horse-sized duck or 100 duck-sized horses? For how much money would you go to jail for 1 year?

I was always a fan of these nihilist security questions:

https://www.mcsweeneys.net/articles/nihilistic-password-secu...

Re: Don't give away historic details about yourself

#106
post #17

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…

If it is a password to a bank account or a brokerage account I would love to be able to set the system up to only be able to reset my password in person at a branch or office. Charge me for the reset if you think it's too expensive to have that service for free.

For other passwords people should just write them down and store them in a safe place (like in there desk at home).

Re: Don't give away historic details about yourself

#107
post #17

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…

> I agree, secret questions are dumb... but what are the alternatives?

Unless you are running a system intended as the users primary email provider, 2FA + email covers basically all the things that “security question” auxiliary passwords are used for, with both better usability and better security. For high security cases, 2FA + in person recovery may be more appropriate.

Re: Don't give away historic details about yourself

#108

Earlier quoted context omitted.

DNA can be harvested from dead hair, skin or spit even, so anyone with access to your physical environment could obtain your DNA.

Yeah, I was considering more along the lines of massive compromising of remote authentication mechanisms, not spycraft targeting.

LMFAO.

Re: Don't give away historic details about yourself

#109
As others in this thread have stated, security questions are less secure than using a password, and thus, a poor way backup to passwords.

One interesting alternative that's been presented recently is Mooney Images [1]. The example images in the linked slides are fun to test out on yourself and others. They rely on a user's implicit memory of visual imagery and while they are also susceptible to similar sorts of side-channel inquiries, they would be much more obvious.

[1] https://www.mobsec.rub.de/media/mobsec/veroeffentlichungen/2...

Re: Don't give away historic details about yourself

#110
I use 1Password as a password vault. Some years ago, I decided to start lying for secret question answer challenges. I use 1Password to generate a string of garbage (without numbers or symbols, 25 characters long) and keep that answer in a custom field in the 1Password vault. I've tagged those entries with a security tag to find all accounts with secret Q&A information.

I am paranoid about back ups because if god forbid I lost that vault, there are accounts that would be permanently lost to me.

Post reply on HN