2 ms·
> I just save these as random values in extra fields in my password manager Unfortunately that opens you open to a social engineering attack, 9 times out of 10
by dtech 2y ago
> I just save these as random values in extra fields in my password manager
Unfortunately that opens you open to a social engineering attack, 9 times out of 10 if you call the helpdesk for a password reset and they ask you the questions and you answer "some random junk I don't remember" they'll reset it for you..
- kibibyte 2y agoMy solution to this attack is to generate random words (what 1Password calls a "memorable password") instead of something totally inscrutable. Most security question fields are long enough to accept 4 words (occasionally 5). I think it should be much harder to convince a customer support agent with "it's just 4 random words from the dictionary" vs "it's 32 random characters, do you really want me to go through it all?". (I'm sure a determined enough attacker will eventually find an agent willing to accept the former excuse, but if it reaches that point, I think I've already lost this battle.)
- askvictor 2y agoI guess the better solution is to make the answers different for each site, and plausible (i.e. childhood street is an actual street name somewhere), but False. Then saving these in your password manager. Given there are typically a few questions in the mix, each answer not having a huge amount of entropy doesn't matter as much.