5 ms·
I can't remember seeing security questions securing a system in the last decade. Are they still used and I just don't see them or this was some unusual company
by jowea 2y ago
I can't remember seeing security questions securing a system in the last decade. Are they still used and I just don't see them or this was some unusual company config?
- throw16180339 2y agoUSPS uses them. Their customer service rep wasn't amused when I told her my favorite food is heroin.
- nkrisc 2y agoAnd here I am with all answers to my security questions as random strings of letters and numbers stored alongside my password in my password manager. I hope I don’t have to give someone that answer over the phone.
- oefrha 2y agoI probably raised a fair bit of suspicion last week when I told the Wells Fargo rep handling a declined CC transaction that I had to look up my mother’s maiden name in my password manager.
- bee_rider 2y agoAt this point anyone handling passwords must have encountered enough of us to know that some family names need to be looked up in a password manager, and it isn’t that suspicious. Isn’t that right, my cousin? I can never remember how to spell grandma 38!;&,90-@3!;8,’s name.
- SoftTalker 2y agoI don't remember where now, but I have run into sites that disallow numbers and non-alpha characters in the "secret" question answers. They were actively trying to thwart people from entering random gibberish there. Of course that's silly, but so is thinking that a person's maiden name is some kind of secret, or that people will be able to reliably remember things like "the title of their favorite book."
- chgs 2y agoMy uncle is called Robert'); DROP TABLE Students;--
- whaleofatw2022 2y agoDuhangit Bobby
- pkaeding 2y agoYeah, it is pretty awkward. My forst car, sure: Capital-double-you, dollar sign, eff, nine, you, bee, gee, capital kay...
- accrual 2y agoMy only fear of doing this is that someone could call in and say "oh sorry, I just typed in a bunch of random numbers and letters" and the rep will go "haha, don't we all!" and let them reset the password.
- nkrisc 2y agoIf that happens then I don’t think my mother’s maiden name was going to protect me either.
- AnotherGoodName 2y agoThey were pretty much only ever used as a blocker for your email being spammed. As in there's very very few sites that would reset a password on a security question alone. The security questions purpose was just to avoid people triggering emails/resets to the wrong second factor. Despite the common belief they are worthless security questions they are perfectly fine when they don't reset the password directly and merely block users from mistakingly triggering a reset to a second factor on an incorrect account. Do you know the common alternative to not using security questions in the above step? Doing absolutely nothing and allowing randoms to annoy you hitting your second factor with password resets. The ultimate place you rely on either way was the second factor and the questions were always better than nothing at all.
- ptsneves 2y agoAs a ceo, you just call the IT department directly and that is that. In the it’s just tubes analogy sense, it is all just people at the end of those tubes eventually.
- warhorse10_9 2y agoWhat you just described is incredibly prone to social engineering.
- ptsneves 2y agoHave real people go to the office of the CEO and have the CEO make the reset request in person. Even by phone a reset is harmless if the computer the ceo is using is known to be trusted and company managed. The defense is in depth not circumstantial to one single phone call or method. You can also authenticate the request through other channels.
- jowea 2y agoOh so I guess the "please fill in your reset email" counts as a security question. Makes much more sense thank you.
- oefnak 2y agoWindows still uses them when creating a local account.
- 71bw 2y agoAnd yet, it still allows a single-character answer that is the same across all three. Or skips them alltogether when signing up for a local account with no password and adding one later.