back

by privong·12y ago·view on hn ↗
> and save that (along with the question title) in your (properly backed up!) password safe.

To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally secure, location).

5 comments
Security questions are already useless. What's my first pet's name? Depending on the day, I might have any of three or four answers; I'm unlikely to remember which pet was first, 30-35 years ago, even if I think I can, since if you ask me in a month, I might be just as confident the other way! Given the uncertainty, I might well decide that the best answer is a later pet I remember better, but then which one is that?

I remember the names of exactly two teachers from high school, today, but only because I was discussing something about them with someone else who remembered over Christmas. My mother's maiden name is spelled differently on her birth certificate and death certificate, so I can't tell which one future me might use after forgetting a password.

Recently, I've noticed a trend of having 6 or 8 fixed security questions to choose 2 or 3 from, none of which actually apply to me in a reliable way.

There's really no other solution but to treat them as an additional password field.

Strictly speaking, they do have one benefit. If someone steals your password, there is really no way to know. If they reset your account with a security question, you'll know as soon as you access.

Still pretty terrible, though.

I've run into security questions where there were character limits on the answer. "Between 3 and 20 characters, no numbers." The worst of all possible worlds!
"Security questions" are already worse than useless, because they provide an easier attack vector (if they are answered honestly). Things like your pet's name and the street you lived on as a child are easily obtainable online.

Companies should allow security-conscious customers the ability to opt out of this attack vector. Alternatively, just use another 20 character randomly generated string for each of the answers.

You're right, it's not the intended use of the security question - and that's exactly what I want. I feel like entering my pet's name doesn't add to my account security but rather lowers it.

My password safe is stored at many different location so that it's extremely unlikely to loose them all at once. And to secure against amnesia or being-hit-by-a-truck, you should give the passphrase to a person you trust 100%.

The security questions in its current implementation are useless anyhow. Because all those pieces of information are exploitable by your social life these days. "What's the name of your first math teacher" — Take a look into the years schoolbook, which are online.

These security questions are made for us old farts, for days when there was no Internet like today and there were none of this information available online.

Useless for the intended purpose, but when you login to your bank's website from a different IP (or something similar) and it triggers the security question - then you have it without making it something that someone else can figure out.