I don't remember if i answered "88 Oldsmobile Cutlass Supreme," "1988 Oldsmobile Cutlass Supreme," Cutlass Supreme," "'88 Cutlass Supreme," "cutlass supreme," "1988 Cutlass Supreme," "Oldsmobile" or any other variation or misspelling. I don't remember if i had to tweek my answer to fulfill your dumb requirements (my favorite teacher has a special character in her name! Or the answer is 3 characters long and you have a minimum of four! My elementary school is numbered) I remember what street I lived on in middle school NOW, but I'll probably forget it in five years, I routinely forget much more relevant things. On top of that maybe I just don't want to tell every website I use who my childhood crush was. There's also the problem of most "secret questions" that are available being irrelevant for X% of the population. (ex. loners and people who didn't have a stable home life... they rarely include stuff like "who was your foster mom when you were 8?" Even the international crowd could have trouble with most questions.)
I'm old enough and have enough online accounts (I have 246 accounts saved in my password manager) that i now just write "fuck you" for all the answers and put 'all answers fuck you' in my password manager. Because these questions stress me out way too much and I'm constantly bombarded with them. Answering them becomes a major pain point when everyone wants them. I've completely lost it with the damn "[not so] secret questions."
Even worse are websites/services that impose ridiculous character requirements (you must include 2 symbols, 3 numbers, 5 letters, 2.5 of which must be upper case and positioned at the prime number indices, oh and you have to change your password every 6 months) and then limit your password to 8-12 characters.
The way I remember passwords is by stringing together random English words with random special characters inserted throughout. This means most of them are 30-40 characters. I find these far easier to remember than my PayPal password, which is arbitrarily limited to a random collection of special characters that must be of length less than 12 (or whatever their ridiculously short limit is.)
If you truly care about the security of my account don't impose character limits.
I spent 20 minutes trying to come up with a password for chase.com recently because of insane rules like, you can use more than two characters in ascending or descending order, can't use the same character more than twice. Using a random password generator above about 20 characters, and it's guaranteed to break one of there inane rules; let alone if you want to use a pronounceable passphrase that's simply long. It's really aggravating that big companies are some of the worst at this security stuff.
It does make sense to impose some sort of upper bound (only so someone doesn't try and DoS you with a crazy long password), but 13 characters isn't going to bring a server to its knees.
I look at security questions and answers as a challenge and response. I stopped answering them logically when I realized I don't have to. So the answer to "Where would you like to retire?" might be "the sky has a long face." I won't ever use them unless resetting a password, and I won't be resetting a password unless I mess up synchronizing my password manager. Except when I do need them, because the dip shit that operates the site doesn't "recognize" the computer (browser session) I'm using. That crap needs to go.
This is fairly effective until the day comes when you use this method on a system that tries to be even nicer about password recovery... and presents your answers in a multiple choice context.
Where would you like to retire?
( ) Miami Beach, Florida
( ) Nice, France
( ) the sky has a long face
( ) Bozeman, Montana
Is TransUnion doing this with fill-in-the-blank security questions? Or are you referring to indetity verification questions base on credit report data?
I just generate more passwords for the security questions. Since I’m using a reliable, backed-up password manager, my primary concern is protecting my account from would-be hijackers, not resetting a potentially lost password.
The one thing I try to do is make sure whatever password generator I use for these produces pronounceable passwords in English that are relatively easy to spell, because so many of the places that want these really mean "Phone password".
The issue isn't typing them. The issue is that many "Security Questions" are secretly "Phone Passwords" because customer service representatives can see them in plaintext and will ask you them if you ever have reason to call them over the phone. Making sure that they are pronounceable (mostly) English words avoids some of the potential awkwardness of reading them out of your password manager over the phone, even if they are intentional random gibberish. It also partly avoids the social engineering trap of "it's just random garbage" because at least if it looks like words a customer service rep may still ask for them anyway rather than not bother to one-at-a-time review a series of random characters.
I use random passwords for reset questions because they're often the Achilles' heel that people drive around.
PS: 1985 Delta 88 Royale Brougham LS with dark smoke metallic paint, limo tint, more chrome that a Cadillac factory and burgundy velour, and a $20k sound system... what you inherit when your dad is an audiophile and wants a car that could fit 6 dead bodies in the trunk.
No, I usually generate a new username per site with a script if a username is required. Either that or use a name generator to pick a random Firstname_Lastname username.
(It's not actually 'Fuck You,' but something similar and I do sometimes change it up with a few different simple phrase answers. I did own an 88 Cutlass Supreme [worst car I ever owned], but it wasn't my first car.)
Maybe that should be a security question, "what the worst car you've ever owned?," now THAT'S easy to remember all the times you're stranded on the side of the road, stalling in the middle of heavy traffic, and all the repair bills.
Problem with "other password approach" is "I just put a bunch of random characters in there" becomes a valid response to an overseas customer service rep if you're talking on the phone.
EDIT: Ok, any English word or phrase would work for "other password" just fine. I guess after idk how many years of trying to use the "secret questions" as intended I just get angry every time I see them.
Or "show up somehow in person". We have all of this physical infrastructure we could take advantage of for critical accounts: IDs, notaries, passports, post offices, etc.
There are accounts where that may not entirely make sense, but a lot of my accounts I would love the option to state "The only way to recover from a lost password is to send a notarized letter via snail mail explaining the problem."
No one but me should be able to touch my digital bank accounts without having to first show up at a bank location with my ID or a signed certificate of death.
"Immediate" password recovery is part of the problem. A lot of our accounts most people don't need to recover the password immediately, especially if the reason they have forgotten is that they haven't needed the service in months.
Also, phone calls and text messages aren't slow enough.
Problem with that is "I just put a bunch of random characters in there" becomes a valid response to an overseas customer service rep if you're talking on the phone.
I've successfully responded something like "It's a 25 character random string beginning with A#fx and ending with ^tx% - would you like me to read the whole thing out?" to customer service reps. (I've never tried to see if anyone will give me access to an account just by saying "a bunch of random characters", but I wouldn't be surprised if they did...)
These days I just use 1Password's 4 or 5 word password generation option where it works. "What is your mother's maiden name?" "I answered 'griffin accolade stallion catboat' to that question."
OSX Keychain has a "memorable" feature for password suggestion (e.g. getup3_gulag). 1Password has a "words" type of password (e.g. ancestor-dissent-rubdown). I suspect other password managers have similar. That's what I use in this situation.
I don't remember if i answered "88 Oldsmobile Cutlass Supreme," "1988 Oldsmobile Cutlass Supreme," Cutlass Supreme," "'88 Cutlass Supreme," "cutlass supreme," "1988 Cutlass Supreme," "Oldsmobile" or any other variation or misspelling. I don't remember if i had to tweek my answer to fulfill your dumb requirements (my favorite teacher has a special character in her name! Or the answer is 3 characters long and you have a minimum of four! My elementary school is numbered) I remember what street I lived on in middle school NOW, but I'll probably forget it in five years, I routinely forget much more relevant things. On top of that maybe I just don't want to tell every website I use who my childhood crush was. There's also the problem of most "secret questions" that are available being irrelevant for X% of the population. (ex. loners and people who didn't have a stable home life... they rarely include stuff like "who was your foster mom when you were 8?" Even the international crowd could have trouble with most questions.)
I'm old enough and have enough online accounts (I have 246 accounts saved in my password manager) that i now just write "fuck you" for all the answers and put 'all answers fuck you' in my password manager. Because these questions stress me out way too much and I'm constantly bombarded with them. Answering them becomes a major pain point when everyone wants them. I've completely lost it with the damn "[not so] secret questions."