Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

131–140 of 207 posts

Re: Don't give away historic details about yourself

#131

What is with perpetuating this idea that people have some duty to be responsible for companies' broken security practices? You're unable to prevent their fuckups - so you can only take steps to make sure you don't end up on the hook or otherwise severely impacted due to their negligence. It's not my job to avoid repeating public information like mother's maiden name, historical addresses, etc. Nor is it my job to wor…

In a perfect world, sure. But unfortunately so many companies don't do security right, so if we want to be safe we have to take the initiative. I mean, it doesn't have to be an either/or thing, we can pressure companies to change while adhering to best practices like not publicly posting your first car and name of your first pet.

Re: Don't give away historic details about yourself

#132

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

Does Apple still do this? I always wondered how they're glorified for Privacy and Security while pulling this off...

Re: Don't give away historic details about yourself

#134

Earlier quoted context omitted.

When I signed up for a new bank account the bank rep had me set up online banking on their computer. When she asked me for my security questions and answers she was baffled when I told her the question selected didn't matter, and the answer was a seemingly random alphanumeric string. I told her that I don't know her, or her machine. For now, I'll be setting it as quick, easy for me to remember, string and I'll change…

I do this too, I was told to add something like "PLEASE MATCH THIS TEXT, THIS IS NOT A RANDOM STRING" at the beginning. Apparently when some very incompetent bank workers ask your security questions if the frauder says "oh it was just a random string, I do not remember" they give access to your account.

For that reason I basically use a fake identity for security questions - all perfectly plausible answers, but actually have nothing to do with me. It's not as secure, because they are shared, but it at least removes the ability to research the answers.

I also just avoid setting them where ever possible -- it's basically only for banks (some random website isn't going to get real answers to security questions).

Re: Don't give away historic details about yourself

#135
post #98

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

Yesterday, I was logging onto Australian MyGov site, and forgot the password, it sent SMS code for reset to my mobile phone, but then would not let me proceed without answering the secret questions. I usually put last word of the question sentence as an answer itself because I can't be bothered, but it was not the case this time. Not a great experience when they threaten lock out of account, and you have to go link all services again on a new account. Also, the site has no option to change mobile number for SMS code, and you will have to create a new account if you change your number.

Re: Don't give away historic details about yourself

#136

Earlier quoted context omitted.

To be fair, to actually exploit this the scammers would have to know you put in a random string. A human customer service process is not really subject to dictionary attacks.

Except customer service is often trying to help you remember, and you can guess a few times.... a scammer will say something like, "Oh man, I can't remember what I picked... sometimes I choose a random car model, but sometimes I just put random characters", and if either is true, the customer service rep might confirm it.

Incidentally, I've also had customer service go the other way. I was doing a security check, and one of the questions was how long have you lived at your current address. We moved when I was about 10, so I said "I think it's XX years, let me double check: Mum, how long have we lived here, is it XX or XX+1 years?", only to get "It has to be YOUR answers". Despite knowing all the other relevant answers (random characters of password, memorable name and date, amount of last Direct Debit, down to the pence, first line of address and post code) first time and without prompting, it ended up with my account being locked.

Definitely more security, but _maybe_ slightly too far in the other direction.

Re: Don't give away historic details about yourself

#137
post #51

I don't know which annoys me more, the easy to guess security questions or those with mutable answers. Things like: What's your favorite vacation spot? What's your favorite food? Often you're stuck having to choose between something other people know or can figure out (where you were born) and something that may well change over time.

I like the idea of trolling people with security questions that you never actually use in a password-recovery workflow. What is your third favorite vacation spot? Would you rather fight a horse-sized duck or 100 duck-sized horses? For how much money would you go to jail for 1 year?

I've just chuckled for far too long visualizing your horses and your ducks. Now everyone here at this cafe thinks I'm some kind of animal murderer.

Re: Don't give away historic details about yourself

#138

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

What's worse these days is, ever since the Equifax breach, certain institutions have taken to asking me for the last 6 digits of my social (or even worse... all of them...)

Re: Don't give away historic details about yourself

#139
I'm filling out a visa application form right now. I kid you not, I'm supposed to keep the username secret too.

And then if you do a password recovery, they email you a new password (which is like 6 characters) WHICH YOU THEN CAN'T CHANGE (except if they email you another new one).

It's a joke. I had to come up with a security question so I just make them sarcastic: "In what world is this secure?"

Re: Don't give away historic details about yourself

#140
post #104

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I have always wondered what happens if the receiving site is someone like IRS or any such government entity. If one of the questions was "where was your father/mother born?" and you gave a fake answer.. are you now "lying to the government"? There are lot of questions that can have provable right/wrong answers - assuming someone powerful is out to get you. Imagine that being used against someone!

I don't think lying to the government is automatically illegal (ymmv, ianal, probably varies with jurisdiction). They are generally pretty explicit about the contexts in which lying is illegal (certain signed forms, being under oath etc) which would imply that lying is at least not illegal in other cases.

This is not, by the way, a strictly government related concern. If you lie on a credit card application (and are caught), you're going to have a bad time. But the signed bit of the application is usually completely different from where you're asked to set up "security questions".

Post reply on HN