6 ms·
Why my mother’s maiden name is nonsense
- tnash 11y agoHere's what I do: random long strings as answers for each question, and save them with the credentials in KeePass. That way I keep track of each one, and they can't be used against me.
- jobigoud 11y agoI also generate my mother's maiden name.
- nnutter 11y agoAn important point for this is that the answers seem to be stored in plaintext (by companies) so you also shouldn't use the same one in multiple places. Simply substituting easily researched information for less easily researched information only solves half the problem.
- ryandrake 11y agoIf enough people start doing that, sites will just add a third layer of secret questions to let you reset the other secret questions you forgot the answers too, and on and on... It will be secret questions to unlock secret questions all the way down.
- daveguy 11y agoThe key is to use a password locker like keepass or passpack.
- zorked 11y agoMay you never have to call someone to give them your mother's maiden name to unlock your account.
- daveguy 11y agoThat works out pretty well with a "just tell me when you've heard enough" j q r p z v ! ? / b ... They usually say enough about 8-10 chars in and it really isn't that difficult to read off 8-10 chars.
- Symbiote 11y agoI had to explain what the "greater than" symbol meant to someone at my bank, when they wanted the third character from my mother's maiden name. They understood it was more secure though.
- daveguy 11y agoSame plan for me, except I use passpack.com ... However, beware of tradeking as an online trading service. They have the lowest rates, but they have some ridiculous backward security requirements. 1) You have to enter passwords with an on-screen keyboard. Which means long complex computer generated passwords are a pain. 2) They present security questions in multiple choice form. That's right, your clever or unique answers are right there easily identified next to all the mundane answers. Honestly I don't know how they haven't fired their whole security team. I know this kind of security theatre is costing them business, and I bet their back end reflects similarly poor decisions. I am surprised they don't have regular compromise reports.
- morgante 11y agoI literally closed my account because of their ridiculous security requirements. For the record, I'm much happier with Interactive Brokers: https://www.interactivebrokers.com/ https://www.interactivebrokers.com/
- daveguy 11y agoThanks for the heads up. When I looked years ago I had trouble finding a suitably priced company with an available API. This looks like a serious contender.
- deleted 11y ago[deleted]
- mikestew 11y agoYeah, I thought I was clever doing that until the day came to reset my login with my bank. They didn't ask a single one of those questions, and instead asked questions that anyone with my credit report could have answered. </facepalm>
- Zancarius 11y agoThat reminds me. Someone I know once received a notice from the OPM (Office of Personnel Management, for those outside the US, who deal with government hires and the likes) related to the massive data breach over the last couple years, and they offered ID theft protection through a 3rd party for free (oh boy!). The questions were outright absurd--they asked a variety of minutia (largely credit-related) going back 30+ years that no one would likely be able to remember. Except that I'd imagine if the thieves in question had access to a person's history and credit report, they would have been able to answer these same questions with greater accuracy than the person whose data was stolen. For all the effort some companies place on security, it seems wasted when they rely on information that is publicly available--or in this case, part of a corpus of data that may or may not have been stolen.
- CrystalGamma 11y agoI put a 1KB base64 string into my PayPal 'security' questions. Problem now is that it won't accept that string again when I want to change my password. I assume the text was truncated at some point but is no longer now …
- jakub_g 11y agoThere was a discussion about it on HN few weeks ago and someone rightly pointed out this is prone to social hacking by the attacker saying "well yeah I put some random garbage string, don't remember exactly". Remember, human part is the weakest point here.
- ComputerGuru 11y agoI blogged about this last year; the sad reality is that the security of these "security questions" are more important than that of your password since they can be used to reset both your password for this site and everywhere else (as well as gain access to your bank, obtain credit cards in your ID, and more). We need to obscure these in the database. You can't risk losing your ID entirely just because some random site didn't bother securing these details and fixated solely on "best practices" for password storage in the DB. https://neosmart.net/blog/2015/never-store-answers-to-security-questions-in-plain-text/ https://neosmart.net/blog/2015/never-store-answers-to-securi...
- Chefkoochooloo 11y agoI thought this to be really interesting. I found this article making good points and it is incredible that the maiden name is more important that the password itself. Seems backwards in my opinion.
- thowawy3116 11y agoIt's helpful to know that on most services the maiden name can be thought of as a second password. Only on some credit-related services does the answer actually matter, it seems. And then there are those of us who have hyphenated surnames, where the maiden name is there for all to see. I wish my name weren't hyphenated, but I'm stuck with it. It's always silly when someone asks for maiden name: I've already given it to you... Hyphenated names are also longer, making it a perpetual challenge to fit my name on forms. On standardized tests I was always penalized a minute or more as I spent time scratching in all of the letters of my name. Then there are the fields where the hyphen is not allowed, so I have to enter something that is not my legal name, or even worse are the services that accept the hypthenated name but then transparently change it for storage on the backend. This can make verification fun since there's no telling whether the hyphen was removed, replaced with a space, or some other character entirely. Better hope that you don't have a limited number of attempts to access something. It doesn't fit on credit cards either, making the name field of web payment forms a best guess (I usually put my full name regardless of what is actually on my card). Future parents out there: consider expressing your family pride or sense of nonconformity in a different way. Hyphenated names are a nice gesture, but they're totally impractical in a world where data entry matters. I'm only thankful that I don't also have a unicode character in my name...
- emodendroket 11y agoWhat I've always wondered is what happens when two people with hyphenated names marry.
- AndrewOMartin 11y agoThey both take the surname which made from the full concatenation of each original surname with all punctuation stripped, but with a single trailing space for an unknown reason. Any offspring have a surname composed entirely of hyphens.
- lfowles 11y agohttp://www.npr.org/2012/07/19/156923573/when-hyphen-boy-meets-hyphen-girl-names-pile-up http://www.npr.org/2012/07/19/156923573/when-hyphen-boy-meet...
- tzs 11y agoFor sites that let you make up both the question and the answer, Bruce Schneier has suggested having some fun with it [1] to make your conversations with support more amusing. Examples: Q: The Penis shoots Seeds, and makes new Life to poison the Earth with a plague of men. A: Go forth, and kill. Zardoz has spoken. Q: What the hell is your fucking problem, sir? A: This is completely inappropriate and I'd like to speak to your supervisor. Q: I've been embezzling hundreds of thousands of dollars from my employer, and I don't care who knows it. A: It's a good thing they're recording this call, because I'm going to have to report you. While you don't have as much flexibility when you do not get to write the question, I'm sure there are still plenty of amusing answers you could pick. [1] https://www.schneier.com/blog/archives/2010/04/fun_with_secret.html https://www.schneier.com/blog/archives/2010/04/fun_with_secr...
- Eric_WVGG 11y agoI’ve been using rap lyrics for a long time. Had to get on the phone with the bank once and explain that “I like big butts and I can’t deny” and the response from the teller was priceless.
- bostonpete 11y agoYou mean "I cannot lie" or did you intentionally change the lyrics because you were worried about someone guessing the correct Sir Mix-a-Lot lyrics...?
- darkr 11y agoThis is all well and good until you call your bank, and taking a look in your password database you discover that your first pet's name is Adolf Hitler. The conversation that follows becomes somewhat awkward..
- mhurron 11y agoThis really is a retelling of the advice 'Your passwords should not be something that could be guessed by knowing just a little bit about you.'
- Nadya 11y agoWorse is that these answers are stored often in plaintext because they aren't the users "password". I'd argue having them at all puts one at greater risk of being hacked. What I'll never understand is why I can answer these questions with 64-128 characters (typically) but my password is limited to 16-32 characters.
- stordoff 11y ago> I’ve decided to leave the website link out in the interest of discouraging abuse of the tool. I appreciate the sentiment, but I suspect this would be a more powerful demo if people actually found their own mother's maiden name. Anyone wanting to abuse it could find it trivially anyway (Google for "type your details below so we can start tracing your family", and you only get a single result). I do wonder how complete the site's records are. I can find most of my family, but it doesn't seem to think I exist. Edit: seems to be a weird search issue - given name + family name + year of birth returns multiple people who aren't me (with different given names / years of birth), but given name + middle name + family name + year of birth finds my details. Personally not too worried about it, as I use a random name in place of my mother's maiden name for banks etc., and have recommended to family that they do the same.
- notahacker 11y agoOther security questions are often even worse. "What high school did you attend?", for example, is something many friends and acquaintances will know and most others can trivially obtain via LinkedIn or Facebook. "Where were you born?" and "What is the first school you attended?" can be reasonably reliably guessed from the high school as well.
- amyjess 11y agoThis is why you lie. "Where were you born?" "In the fires of Mount Doom." "What high school did you attend?" "Methamphetamine High"
- saturdayplace 11y agoThis is a good idea, if you remember to always tell the same lie. Being required to remember which website I told which lie to can only lead to trouble.
- xenophonf 11y agoYou could store them in a password database (Password Safe, 1Password, whatever). It takes a little discipline, but it isn't any different from managing passwords in general.
- PuffinBlue 11y agoJust stick the question and it's answer in the notes section of your password manager. Some password managers will generate a pronounceable string for you too, saves coming up with anything witty...
- dragonwriter 11y ago> Just stick the question and it's answer in the notes section of your password manager. Since security questions are typically used for things like password recovery, you probably shouldn't manage them with the same tool you use to manage passwords. After all, if you need them, it is likely to indicate a critical failure of your access to (or your data held in) that tool.
- m3andros 11y agoThe site in question is: http://www.genesreunited.co.uk/discover/index?stage=1 http://www.genesreunited.co.uk/discover/index?stage=1
- amyjess 11y agoIt's particularly dangerous for people who actually use their mother's maiden names. Some people were born to unknown fathers, and some people deliberately changed their names to their mothers' maiden names later in life.
- cballard 11y agoThis question is also misogynist. My mother does not have a "maiden name" she has a "last name", which has always been the same. It's not the 1950s, women don't have to subjugate themselves to their husbands name anymore. Oh, and gay people exist. Get with the times.
- msellout 11y agoAnd many countries have never had the the culture of changing family names on marriage.
- AnimalMuppet 11y agoNo. But in those countries, one's mother still had a family name at birth that is different from one's own (in almost all cases), whether she changed it at marriage or not.
- msellout 11y agoAnd therefore one's mother's last name is even more public than a "maiden name".
- xlayn 11y agoI had a related issue with this kind of security measures: I can't remember them after... is your favorite book "ABC" or "A B C"? first car Nissan Fairlady or 350Z? So what I do is that you take the question, put it on an email with the key, put the key into a password generator [0] that creates the answer with a Master key just you know. [0] Password generator pro, FOSS, grab it on FDroid
- ajford 11y agoI generate random answers that fit the question (i.e. best friend: Steven Austin, 1st Car: Hummer H3) and store them in Last Pass (or Keepass). Can use password generator too.
- gonyea 11y agoPersonally, I wouldn't give up the name Mrs. Nonsense.
- AstroJetson 11y agoThis isn't news, I've done this for decades. I have a fake family that I use for Mom, pet's name, fathers birthplace, etc. But unlike the OP, I only have one fake family to track. It's not hard to do, just pretend you are an undercover KBG agent. Alternate plan is to just rotate family by one, so Dad moves to Mom, Mom moves to older sibling, etc and the pet rolls to the top (Dad).
- makecheck 11y agoI’m not sure which is worse, that so many sites require “security” questions (emphasize on quotation marks) or that the questions are frequently paired with asinine password restrictions that prevent the construction of a strong-enough password in the first place.
- emodendroket 11y agoOne of the most frustrating things is that many banks and other financial services seem to have the most antiquated security practices (nothing above twenty characters and no special charcters, for instance). It should be the other way around and yet here we are. That said, I've mostly seen these used as an in-addition question when you want to do something like reset your password. Who's out there using these security questions as the primary mode of authentication?
- lallysingh 11y agoThey value stability highly. So they often go with mainframes and software that was written in decades past. When the software was written, that stuff was often pretty good.
- emodendroket 11y agoSure; I don't want my bank getting too creative either, but that surely has to be balanced with security.
- vinceguidry 11y agoI have to put in a security question answer every time I log in to the Bronto email marketing service. Have to go into LastPass and look up the string I used.
- emodendroket 11y agoBut that's in addition to a password, right? Not instead of one.
- jakub_g 11y agoTalking about password recovery: Google has an interesting attitude. I recently lost password to a dev account on gmail I created few weeks earlier so had to reset password. I went through a process in which they asked questions "when more or less was account created", "when did you last log in successfully", "what last password do you remember", "what google services did you use with this account" etc. which, mixed with some other data they possess (I believe), like IP addresses, made me successfully recover the account without any "maiden name" questions.
- cballard 11y agoAll of those seem fine, except for "what last password do you remember", which is horrifying.
- Diederich 11y agoWhy? I suspect that just means that they keep the various versions of your hashed password. Some regulatory requirements mandate that passwords not be re-used for a period of time; that would be enforced the same way.
- Nadya 11y agoYou're thinking of the wrong attack vector/issue with this. Imagine your account was compromised. You reclaim your account. The previous cracker recovers your account from you because they knew your previous password and went through the recovery process. The above happens more often than you might think.
- kazinator 11y ago> Inevitably, I quite consistently can’t remember the word for each service – a fact that surprised this particular rep, “How do you forget your Mother’s maiden name?”. The rep is looking at the string that you gave them as your maiden's name (so that he or she can compare that with whatever you utter), and what's on the screen is obviously not anyone's maiden's name, being "nonsense", and all. These jobs don't always go to the brightest bulbs in the chandelier, do they. Gee, how on God's green Earth could anyone forget that your mother's maiden name is Z3xYFrd9. It's rude too, implying that the customer is incredibly forgetful; in a customer service role, we should refrain from making such a comment even if the string does look like a viable maiden name. Even some harmless, utterly non-sarcastic comment about anything could be taken the wrong way or take a surprising direction. "Nice tattoo, where did you get that done?" "It's a birthmark, which made me the target of bullying throughout elementary school." Oops!
- chei0aiV 11y agoJust use a diceware password for both those question and answers, like you do for your actual passwords.