Live data from Hacker News

Your Mother’s Maiden Name Is Not a Secret

nytimes.com

61–70 of 274 posts

Re: Your Mother’s Maiden Name Is Not a Secret

#61

I feel like this article takes a lot of words and time to suggest the reasonable solution: make up fake answers to security questions and store them somewhere, preferably a password manager. Sure, it would be greatly preferable to use 2FA and people should really get on that, but lamenting on all the ways security questions can be inappropriate for people when there's an obvious solution feels like drawing it out for…

Sure there are workarounds we can use as consumers, but getting the message out there will help push the companies to a better system. Something like 2FA over SMS is common in other countries and way better. Journalism is helping give security a bigger mind share in the public eye so they can understand how current systems are flawed and demand better ones. Its a good time to tackle the problem given all the recent hacks/leaks (like SSNs). Corporations will only budget for this stuff when their users demand it.

Re: Your Mother’s Maiden Name Is Not a Secret

#62
post #59
post #49

Earlier quoted context omitted.

I also generate them with a password manager. FWIW, I always start with “it’s a long gibberish string” and no one has ever been satisfied with that. I’ve always had to recite it. Anecdotal I know.

Sure, but you're not spending all day running customer service "DoS attacks" against people's bank accounts. Even if "it's gibberish, and I forgot it, can't you please help me out" only works one time out of a thousand, do you really want to bet your bank balance on a weak link customer service rep who's just a tad too eager to help?

I think it’s all debatable. That human will always be a weak link. It just takes one representative to forget to ask or get convinced with “oh it’s my wife’s mother’s maiden name and my wife isn’t here and I’m in a real bind”.

But in exchange, my security answers are no longer compromisable online. I think overall it’s a positive trade off, but that’s just my hunch.

Re: Your Mother’s Maiden Name Is Not a Secret

#63
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

Australia is fairly similar to this. Particularly the fee free transfers between banks (for both private and business)

What’s interesting is that next year most of the banks seem to be launching an instant bank transfer system - big interbank implementation. Right now it takes generally 1 business day if you’ve transacted with that account before and 3 business days if you haven’t. I assume that’s some kind of anti fraud but not 100% sure.

Re: Your Mother’s Maiden Name Is Not a Secret

#64
post #44

Earlier quoted context omitted.

That may work in cases of online password resets, but I believe it has been demonstrated that they are not great for social engineering reasons. A hacker can just say, "oh I just mashed the keyboard for that" or worse, the agent thinks it is an error or glitch and let's the hacker in. I think best to use a real, but different last name on all your sites.

Do most websites have call centres where you can try to trick agents? Also, how gullible are call centre agents at financial institutions? If they're really giving out access to random people claiming to have forgotten the security answer, it's pretty clear-cut the bank should be on the hook for damages if money gets stolen. Nothing like the prospect of having to pay out damages for gullible call centre agents to mot…

I speak from anecdotal experience here but have seen a bank account password reset using only the confirmation of address, name, DOB and bank card #.

Re: Your Mother’s Maiden Name Is Not a Secret

#65
post #45

Earlier quoted context omitted.

This works great until you call your bank for some reason and they ask you for your moms maiden name. Urgh, it sucks.

I use diceware-type passphrases (a bunch of entirely random real words) for security questions for this reason. Bit weird to say "I was born in 'correct horse battery stapler'" but it doesn't seem to bother banking phone reps much.

I love just how pervasive the influence of xkcd is! I do the same as you by the way, and no one has ever called me on using something that is obviously not a name.

Re: Your Mother’s Maiden Name Is Not a Secret

#66
post #6
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

US banks really hate being required to spend money on things, so they lobby the government against any stringent regulation.

Well, those hefty executive bonuses aren't going to fund themselves!

Re: Your Mother’s Maiden Name Is Not a Secret

#67
post #46
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

A wire transfer(IBAN/BIC transfer) is different from an ACH transfer. ACH(EFTS in EU) in the US is generally free, but has a delay for clearing and has some mechanisms for reversal. This is primarily a digital check, and can be initiated by the receiver in that way. A wire transfer is nearly immediate by comparison and offers almost no option for reversal. This option does usually have a fee and is generally reserved…

>> but has a delay for clearing...

not only is there an ODFI-clearing house - RDFI delay caused by the actual "clearing" process - the whole flow starting from the merchant->payment processor step is a sequence of nightly batches with cutoff times factored in to boot.

from the merchant perspective, however, ACH payment is cheaper to process than a credit card payment and is way less likely to end up in a chargeback.

Re: Your Mother’s Maiden Name Is Not a Secret

#68
post #62
post #59

Earlier quoted context omitted.

Sure, but you're not spending all day running customer service "DoS attacks" against people's bank accounts. Even if "it's gibberish, and I forgot it, can't you please help me out" only works one time out of a thousand, do you really want to bet your bank balance on a weak link customer service rep who's just a tad too eager to help?

I think it’s all debatable. That human will always be a weak link. It just takes one representative to forget to ask or get convinced with “oh it’s my wife’s mother’s maiden name and my wife isn’t here and I’m in a real bind”. But in exchange, my security answers are no longer compromisable online. I think overall it’s a positive trade off, but that’s just my hunch.

Well, for sure it's better than using your mother's actual maiden name. But I'd rather see security questions done away with altogether.

Re: Your Mother’s Maiden Name Is Not a Secret

#69
post #23

Earlier quoted context omitted.

Transfers can be charged, and often are even within the same country. In Spain it is common to have "up to n monthly transfers for free, then you get charged x%". Also, I've received wrong payments on a German account from French people many times, and they claim it's because their bank charges the transaction and I receive the sent amount minus fees, with no possibilities for them to specify otherwise (that's happen…

> bank charges the transaction and I receive the sent amount minus fees Sounds like horrible UX -- how would people be able to pay their bills correctly if the sent value doesn't equal the received value?

It is really terrible. We currently solve it by charging them the missing amount via credit card when this happens.

Re: Your Mother’s Maiden Name Is Not a Secret

#70
Considering the security question forms are brute-force proof, I think it's better to keep fictional answers which cannot be accessed by social engineering for these questions.

In India we have SMS based 2FA for transactions in spite of these questions, Some Chinese banks seems to provide HW based 2FA for general accounts.

Post reply on HN