4 ms·
I used to do a presentation called "Shattering Secrets with Social Media" where we'd do a "live attack" on a volunteer from the audience. Starting with their n
by caseysoftware 6y ago
I used to do a presentation called "Shattering Secrets with Social Media" where we'd do a "live attack" on a volunteer from the audience.
Starting with their name from their badge, we'd see how many of the top 10 security questions we could answer. For most people we could get 4-6 in a matter of minutes. For a select few we could only get 1-2.
Despite it all, there were two we could almost never get: street you grew up on and first pet's name. My theory was that those are tied to a time and place that predates social media for many millenials and all gen-x.
But there was another approach.. one of those silly threads from years ago was "What is your porn star name?" which required your first pet's name and the street you grew up on. Yes, that was a social engineering attack at scale.
And even if you didn't answer it, if you had a sibling roughly the same age, odds are theirs were the same.
- fanatic2pope 6y agoOne of the benefits of using a password storing app (in my case keepassxc) is that I answer those kinds of secondary questions with random words.
- lfowles 6y agoIsn't the danger now that someone could call into your bank and say "I forgot them exactly, but the answers are just random strings"
- jakub_g 6y agoThis issue always come up with those discussions indeed. Probably to be safe you could just come up with plausible unique non-random name, and still store it in keepass. > What's your cat's name? Site X: Kareem Abdul-Jabaar Site Y: Cassius Clay Site Z: Franz Beckenbauer
- yohannparis 6y agoThen there is a clear breach of the terms of services from your bank, and it might be easier to get issue on their hands. But you are right, the best solution would something in between.
- caseysoftware 6y agoI had that exact thing with a bank last year. Them: Can you confirm your mother's maiden name? Me: Sure but just a second. I need to open my password manager because it's a long random string. Them: Okay, that's good enough! I reported that to their security and compliance team. Never heard back but moved my accounts from there.
- Moeancurly 6y agoAt one point I did the same, until I also had to read a long random string to a CSR over the phone. Now I use real-sounding fake answers.
- mywittyname 6y agoI've found that goofy answers are both easy to remember / say, but impossible to guess. Like, "what's your mother's maiden name?" "Lady with cheeto-colored hair." Or, "what street did you live on growing up?" "We liked to imagine it was the moon"
- saalweachter 6y agoI like to imagine that one day, after the Singularity, the super-intelligent AI overmind that society merges into will be able to resurrect me from the security answers I've left throughout the internet. And all of the virtual reincarnations of all you security-minded suckers will be stuck thinking your mother's maiden name was X1r$9ox01.
- caseysoftware 6y agoaka Elon's descendants.
- EricE 6y agoThey didn't say random strings, but random words. I use the same technique too and at first I used words until I thought about having to call in, so now I just use two random words. First rule of security questions - never answer them truthfully!
- ggggtez 6y agoIn my experience, I told them I didn't remember, and they told me "yeah it's just a bunch of random letters..." but they didn't let me through and required me to go through different security confirmation instead. In this case, it's as if the security question just didn't exist. That's fine with me. I'd rather the attackers figure out the other security measures (e.g. get access to my email or phone in order to receive a security code) than just get into my account by pure guesses. (Though I like the solutions here of using very uncommon two-word phrases to avoid the chance of an incompetent phone operator accepting "random letters" as an answer).
- Swizec 6y ago> Starting with their name from their badge, we'd see how many of the top 10 security questions we could answer A fun thing I do is to just not use my legal name. Online or in person (unless talking to a doctor and such). Many of my friends don’t even realize. Of course the problem is that at this point I’ve used this name enough that you can probably do all the same tricks with it. That’s why I use yet a 3rd name as a throwaway at coffee shops or with transient strangers. Getting death threats from dad’s business dealings once was enough.
- mxstbr 6y ago> Getting death threats from dad’s business dealings once was enough. I would love to hear that story if you're up for telling it Swizec!
- imoverclocked 6y agoIf I were him, I wouldn't post it here because it's a link between his previous (attacked) identity and his current online identity.
- Kye 6y agoThis happens a lot among furries. Way more people know me as Kye than by my legal name.
- kibwen 6y agoThis is a great idea that I've been coming around to for a while now. 1. Have a legal/professional name. This is what shows up on your birth certificate, your IDs, what the people at your work know you by, etc. 2. Have a personal name. This is what your friends and family know you by, and can be completely disjoint from your legal name. A low-effort way of approximating this is just to go by your middle name among friends, since you're usually not required to divulge your full middle name on formal documents, so you can still maintain some degree of separation. 3. Have a public name, or a variety of public names, that are disjoint from the prior two. These are your social media account names, email address, Twitter handle, etc. Let these be as disposable as possible and, if feasible, rotate them out every few years.
- not2b 6y agoYes, this is how someone "hacked" (if you can call it that) Sarah Palin's Yahoo mail account: the answers to her security questions were all Google-able or easily guessed.
- Minor49er 6y ago> this is how someone "hacked" (if you can call it that) Given that the term "hacker" comes from someone who hacks away at a keyboard until they get a desired result, I would call it that
- MattGaiser 6y agoOne bank of mine has "first job" as a security question. If I put the real one, you could easily get it from my LinkedIn.
- ggggtez 6y agoI think the key to the Street address question is to actually first find their parents and then find the addresses that they lived at. There is a non-zero chance their parents still live at the same address. And if not, there are likely records of home buy/sales which can give more guesses. First pet though, I agree is difficult. I can't think of any public records which would list this kind of info. However, pet names also follow predictable patterns. You can probably get very far with names like "Mittens, Duke, Spike, Spot ..."
- yourapostasy 6y ago> First pet though, I agree is difficult. Someone, somewhere, is mapping out all the sites that ask that as a "security question", and they'll be ready to add to their dictionaries when one of those sites is breached.
- j1elo 6y agoNot sure how common that is, but I simply fill out those questions with random words. No way anybody will find out. At that point, they basically are easily readable passphrases. Of course it helps that everything will end up in a password manager.
- coolgeek 6y ago> "What is your porn star name?" ... was a social engineering attack at scale I can't believe I didn't learn this until now. I can't believe I didn't realize it on my own. A quick search shows that this has been known for at least 10 years, though perhaps not widely. Just, wow.