7 ms·
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
by rev_null 10y ago
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
- brianwawok 10y agoThe sky!!!
- oaktowner 10y agoAT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over time!). I filled in "Dave" ... and the site gave me an error "Your answer must be at least 6 characters." Doh!
- ashitlerferad 10y agoSecurity questions should be treated as secondary password fields, since they are that. Use Diceware for a good tradeoff between entropy and memorability/pronounceability or more complex random passwords and store them in a safe place.
- mundo 10y agoThis works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.
- philsnow 10y agoFor every site that does this, I have a blob of text in my password manager where I write down Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".
- ceejayoz 10y agoAh, but the anti-pattern folks have a way around that. Drop-downs for answers. Just got this on United.com: http://imgur.com/84l0CdU http://imgur.com/84l0CdU
- ashitlerferad 10y agoHow about 5 random questions, 5 random answers and record all of these in your password manager?
- kbenson 10y agoIf you have a password manager that successfully tracks the questions, then there's no reason to need to recover the password, as you'll just track the password in the same system. The catch-22 of these systems is that recovery questions need to be obvious, memorable and unchanging enough to the user that they are useful for recovery, while also being hard for a third party to guess/research. I feel like for the most part those are more often than not mutually exclusive.
- pyre 10y agoI think that the drop-downs are trying to prevent people from mistyping things and locking themselves out because "Accordien" doesn't match "accordion".
- Ntrails 10y agoI had something along those lines tryin to log in to mojang on a new computer. "We've not seen you log into this pc before (although I had on that IP), please answer these three security questions. Of course I don't remember so I just reset them. I imagine the new answers and the old answers had a lot in common - they were composed primarily of expletives.
- deleted 10y ago[deleted]
- Can_Not 10y agoFavorite restaurant! What percent of the full business name did you use? Did you capitalize all the letters the same way or in a consistent predictable way? Did you add a word to meet the minimum character/word count? Did you actually have a favorite when you made this? Is your favorite restaurant public information?
- ultramancool 10y agoThis is why I set all my security question answers to a single answer for low security stuff and random pronounceable strings (in case I ever need to read them to a support person) stored in KeePass for high security stuff.
- mikeash 10y agoI'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child." That answer can change over time!
- miah_ 10y agoBest way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names. What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.
- mjevans 10y agoI did that to my payroll account to try and prevent this very issue. Little did I know that it's one of those services you need the password (I had written that down at the time as it was temporary) AND these questions that are usually used for password resets. I don't think that will ever get fixed until I change jobs again.
- 8_hours_ago 10y agoUntil someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".
- ludamad 10y agoWhile avoidable with training, that brings up its own issue: What if what's being asked of the people taking these calls is outside their pay range?
- deleted 10y ago
- gldalmaso 10y agoI once tried to perform an internet banking task only to find out I had to call in by phone and enable it first. So I did, and I was asked a few security questions about my data, one of them was: what's the name of your spouse? I gave the name, was asked to repeat it, so I did, they informed me I was wrong. I still don't know if they had a name with a typo in the records, a maidem name, or maybe they didn't even have her name (don't remember telling the bank about marital status) and it was some sort of trick question where I was supposed to answer I'm single (even though I wasn't).
- uptown 10y agoDid you by-chance try substituting all "n's" with "m's" in your spouse's name?
- thinnerlizzy 10y agoComcast's password recovery is pretty weak. I just did it last night. They ask for your zip code and your favorite sports team. If I have a Boston zip code there are likely only 4 options for favorite sports team.
- swampthinker 10y agoPoor Revs
- johnchristopher 10y agoStory time: I have been trying for 3 years to figure out what I wanted to hint at with "If it's not this one then it's the other one" as a secret question. I thought I was a clever boy not choosing the usual predetermined "what's your mother's name ?".
- paublyrne 10y ago-1?
- tripzilch 10y agoperhaps it's one of the two "throwaway" passwords you were using at the time?
- johnchristopher 10y agoIt most certainly is but... it doesn't work. At that time I had some kind of semantic combinations for passwords but it doesn't compute for that website.
- qcoh 10y agoI had a similar situation just recently with an old Gmail account. Despite knowing the password, Gmail wants me to answer the security question or log in from a place I logged in ten years ago or list folder names (which didn't exist the last time I used that account) or ... The whole point of this misery was to recover my Steam account to play a few games. Fortunately, Steam lets you recover your account if you can provide proof of ownership (like CD keys of physical copies). I don't want Google to be the safekeeper of my digital identity.
- ndespres 10y agoI might have the answer for you- the security question on some of my unimportant shared accounts where a question was required is "what color is my VGA cable?"
- ludamad 10y agoAnd it wasn't 'the sky'?
- tripzilch 10y agoMaybe ... Eiffel65? :-)