5 ms·
Isn't the danger now that someone could call into your bank and say "I forgot them exactly, but the answers are just random strings"
by lfowles 6y ago
Isn't the danger now that someone could call into your bank and say "I forgot them exactly, but the answers are just random strings"
- jakub_g 6y agoThis issue always come up with those discussions indeed. Probably to be safe you could just come up with plausible unique non-random name, and still store it in keepass. > What's your cat's name? Site X: Kareem Abdul-Jabaar Site Y: Cassius Clay Site Z: Franz Beckenbauer
- yohannparis 6y agoThen there is a clear breach of the terms of services from your bank, and it might be easier to get issue on their hands. But you are right, the best solution would something in between.
- caseysoftware 6y agoI had that exact thing with a bank last year. Them: Can you confirm your mother's maiden name? Me: Sure but just a second. I need to open my password manager because it's a long random string. Them: Okay, that's good enough! I reported that to their security and compliance team. Never heard back but moved my accounts from there.
- Moeancurly 6y agoAt one point I did the same, until I also had to read a long random string to a CSR over the phone. Now I use real-sounding fake answers.
- mywittyname 6y agoI've found that goofy answers are both easy to remember / say, but impossible to guess. Like, "what's your mother's maiden name?" "Lady with cheeto-colored hair." Or, "what street did you live on growing up?" "We liked to imagine it was the moon"
- saalweachter 6y agoI like to imagine that one day, after the Singularity, the super-intelligent AI overmind that society merges into will be able to resurrect me from the security answers I've left throughout the internet. And all of the virtual reincarnations of all you security-minded suckers will be stuck thinking your mother's maiden name was X1r$9ox01.
- caseysoftware 6y agoaka Elon's descendants.
- EricE 6y agoThey didn't say random strings, but random words. I use the same technique too and at first I used words until I thought about having to call in, so now I just use two random words. First rule of security questions - never answer them truthfully!
- ggggtez 6y agoIn my experience, I told them I didn't remember, and they told me "yeah it's just a bunch of random letters..." but they didn't let me through and required me to go through different security confirmation instead. In this case, it's as if the security question just didn't exist. That's fine with me. I'd rather the attackers figure out the other security measures (e.g. get access to my email or phone in order to receive a security code) than just get into my account by pure guesses. (Though I like the solutions here of using very uncommon two-word phrases to avoid the chance of an incompetent phone operator accepting "random letters" as an answer).