3 ms·
So they had Mult Factor Authentication, OTP, and Yubikey all and they still used his mother's actual maiden name and place of birth. With all of that you would
by moocows 14y ago
So they had Mult Factor Authentication, OTP, and Yubikey all and they still used his mother's actual maiden name and place of birth. With all of that you would think they would do what everyone else does or should do on that. !@3f49 for place of birth and Erjsh99 for her maiden name. Using real information is just a weak point in a weak system.
- smsm42 14y agoThe problem with the latter would be when you call in and try to convince some service rep that your mother's name is actually Erjsh99.
- signed0 14y agoAs long as it matches the name they have on record, why would they care?
- moonlighter 14y agoAgreed; I'm using the same approach of my own 'recovery keys'. Usually it's possible to provide them in a recovery UI online. And in the case you need to talk to an actual human being, it's easy enough to explain the reason behind it.
- dopamean 14y agoThey probably shouldn't but I had an instance with an ISP back in the day where they wouldnt accept my answer to a security question because the answer was ridiculous. The question was "in what city was your high school?" I put "Upyourassville." The ISP thought there was a problem and wouldnt accept the answer. These days I use my grandmother's maiden name as my mother's maiden name to answer these questions. There are people in my own family who dont know the answer to that.
- moocows 14y agoI actually see that as a plus. If for whatever reason I forgot my own password and can't get onto my account it should be difficult. More so if the guy on the other end should be doubly sure that I am the real account holder if my esoteric answers match up.
- drcross 14y agoThere was a time in the early days of the 'net where using your actual name (and by extension your mothers maiden name) would have been considered perverse- "It's the internet, we can be whoever we want to be". Sadly the powers that be have shifted that away to the point where you are a misfit if you are using accounts that are not linked in some way.
- rgbrenner 14y agoI use gibberish for the answers.. but once (forgot the name of the company.. a few years ago) I lost the answer to the question... so I said "I can't find the answer, but I know it's a bunch of random letters"... and the customer service rep, said 'Ok', and accepted it as the answer. So maybe use real words in the future
- kylebrown 14y agoReading the article, I don't think bitInstant ever gave that information as valid answers to security questions. The attackers convinced site5 to accept that information as security questions and answers.