4 ms·
A lesson we can take from this is just because they are supposed to be security questions based on private and personal information, doesn't mean you should pla
by n3rdy 14y ago
A lesson we can take from this is just because they are supposed to be security questions based on private and personal information, doesn't mean you should play along.
Why should the answer to where me and my spouse met really be where we met? Why couldn't my answer be where Lucille Ball met Ricky Ricardo? Why couldn't my childhood street address be Evergreen Terrace?
Add a layer of security by creating an entirely different alter ego with a whole history behind it, and use their birthday, maiden name, etc, instead of what somebody can look up in public records, or find out from people close to you.
- charlieok 14y agoI usually just generate additional random passwords to put in those fields, and store those in the password manager right alongside the primary password. Sure it defeats the purpose of those fields as a secondary layer if you should lose the password (if I lose everything in my password manager I have bigger problems) but at least an attacker has no more chance of guessing those than of guessing the primary password.
- mctx 14y agoIs there a best practice for keeping a secure copy of one's password manager database? USB key in a safe? Single use Dropbox with an anonymous email? Encrypted file container by yubikey?
- roblev 14y ago1password integrates with dropbox so your (encrypted) passwords are available on all systems that you install the 1password client on.
- hollerith 14y agoI humbly suggest leaving it with a friend but only if the friend understands security sufficiently well, e.g., a competent professional sysadmin.