5 ms·
Pro tip: You shouldn't be answering those questions truthfully.
by fvargas 11y ago
Pro tip: You shouldn't be answering those questions truthfully.
- vinchuco 11y agoBut you have to remember the answers correctly. How do you keep track ?
- hobs 11y agoI usually store it as another password field in keepass http://keepass.info/ http://keepass.info/
- fvargas 11y agoThe lazy way (which is still arguably better than answering truthfully) is to use the same answer for all the security questions. The better way is to treat each answer as another password and encrypt and store the answers somewhere safe.
- thirdsun 11y agoRealistically how many people outside (or even inside) HN are going to do that? No matter how you spin it, security questions are a very bad "security pattern" in my opinion and we should get rid of them.
- K0nserv 11y agohttps://twitter.com/K0nserv/status/689169965526700032 https://twitter.com/K0nserv/status/689169965526700032
- veidr 11y agoThe same way as you keep track of any secure password: either with a password manager like 1Password, etc, or else through some Byzantine scheme that you manage yourself.
- danieldk 11y agoI use 1Password for this as well, but I recently had a security questions form (can't remember where) that tried to reject random strings because they didn't look like words. Luckily, 1Password has a 'correct horse battery staple'-generator these days as well.
- jlebrech 11y agoyou only have to remember that for password resets, if you already store your password in 1password you're golden.
- iam-TJ 11y agoI 'time shift' each number in date of birth so neither the day, month, or year are correct. My secret key is the formula I use. For other questions I use answers that 'belong' to a friend or relative. My secret key is the formula for figuring out who that is.
- JoeAltmaier 11y agoI wonder how many 'bits' those secret keys have? Maybe one or two? E.g. how long to brute force those answers.
- philipov 11y agoIf it's only 2 bits, you're assuming the attacker already knows that the formula is "Using someone else's information" and that there are only 4 possible people whose information you would use. Even knowing that you're using a formula is a bit of information. The type of formula is potentially thousands of bits of information. An attacker doesn't know whether it's a cipher, or a code, or something more complex, and only then can they begin figuring out the parameters to that formula.
- JoeAltmaier 11y agoPretty sure lots of people use relatives' info. Very, very few use ciphers in their head. Friend used to have a car with a keycode door lock. He just used 5555 or whatever. I suggested he use the address where the car was parked, or some hash of that. Wouldn't have to remember it! And it would vary some at least.
- philipov 11y agoWell, sure, 8 bits of entropy isn't going to help you much if your password is "password". Those bits only provide the opportunity for randomness. At the end of the day you still have to apply that entropy effectively by picking something that can't be guessed easily. The point is that there are opportunities for people savvy enough to recognize them.