3 ms·
Who gives real information as answers to security questions? The approach I took is to use a hardware device with limited login attempts to generate store most
by jrabone 13y ago
Who gives real information as answers to security questions? The approach I took is to use a hardware device with limited login attempts to generate store most of my (random, 16 character) passwords (an IronKey, in my case).
IronKey have a reset mechanism involving security questions; I've never used it, and I don't know the answers I gave; they're on a sheet of paper, in a safe somewhere. Yes, it's going to be inconvenient if I ever need it, but if it happened tomorrow it would be a once-in-ten-years event.
My bank inconveniently REQUIRES security questions in addition to a PIN for online banking; again, the information they have is made up. I remember it because I use it regularly, so that ISN'T written down anywhere.
For almost anything else less important, I've either just ignored the security questions (ie. entered random data) or noted them in the extra account info field on the IronKey.
For email, I run my own mail server in colo. It's maybe overkill, but I don't care. Credentials are again 16 character random passwords that I couldn't tell you, and authentication is only allowed over TLS. I'm toying with going for full client SSL certificates but device support would be the issue. I've already discovered more than I wanted to about incompatible SSL implementations on mobile devices over the years, which is why I'm still building Debian packages from source linking to OpenSSL instead of GnuTLS... And there's no webmail access. Never did find one that wasn't either written in PHP, half-functional or abandoned.
- ams6110 13y agoWho gives real information as answers to security questions? Most people do. This piece doesn't really point out that people are a "weak link" (though they are) as much as it highlights that these "security questions" do not really add much security in most cases.
- mikeash 13y agoWell no, the point is not that security questions don't add security, it's that they greatly subtract from security. Sometimes security questions are used to augment a password, but in many cases, including the one given in the article, they are provided as an alternative to a password, and one that's often much easier to guess.