4 ms·
It really frustrates me when sites require a question and secret answer like "hometown" or "mothers maiden name". Those are both very easy to find pieces of in
by dsingleton 17y ago
It really frustrates me when sites require a question and secret answer like "hometown" or "mothers maiden name".
Those are both very easy to find pieces of information. Let me select the question myself too. By forcing me to give you answer here you're potentially making my account _less secure_.
Right now I have standard fake answers to those questions, let's hope they never cross reference those with anything else. I'm not sure how I'd convince someone my mothers maiden name is "<insert comedy name here>"
- axod 17y agoBest policy is just to use your password as the answer to these questions.
- there 17y agowhich is stored in plaintext and often viewable by all support staff...
- axod 17y agoRight, good point. I was assuming you were using a unique password for that website. Also depends what sort of site it is and if it has a concept of "support staff".
- dhimes 17y agoI use an answer which has nothing to do with the question.
- saturdayplace 17y agoPresumably, you're not being asked these questions if you remember your password.
- deleted 17y ago[deleted]
- Confusion 17y agoI don't think any site stipulates that you answer such questions truthfully. My solution is just selecting the top secret question, but actually answering my own secret question with an answer that is as good as any password. And of course a different set of those for the actually really important sites.
- jameskpolk 17y agoIf the site allows the user to chose their own security question, the user will find a way to render it useless. They will either input something far more trivial, or they will input something they then forget. Personally, I don't think businesses should implement half-baked security features -- and password request forms are as half-baked as it gets. The best solution would be for important sites (my bank, my stockbroker, ...) to make me come into their office with documentation if I forget my password. The problem, unfortunately, gets more difficult for "unimportant" sites... frankly, short of relying on a centralized ID provider that can ensure identity in person, there isn't a good answer.
- jrockway 17y agoThe problem, unfortunately, gets more difficult for "unimportant" sites... frankly, short of relying on a centralized ID provider that can ensure identity in person, there isn't a good answer. I hear there's this thing called "OpenID".
- s3graham 17y ago"uuidgen | xsel" works for me.