Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fuck "secret questions."

I don't remember if i answered "88 Oldsmobile Cutlass Supreme," "1988 Oldsmobile Cutlass Supreme," Cutlass Supreme," "'88 Cutlass Supreme," "cutlass supreme," "1988 Cutlass Supreme," "Oldsmobile" or any other variation or misspelling. I don't remember if i had to tweek my answer to fulfill your dumb requirements (my favorite teacher has a special character in her name! Or the answer is 3 characters long and you have a minimum of four! My elementary school is numbered) I remember what street I lived on in middle school NOW, but I'll probably forget it in five years, I routinely forget much more relevant things. On top of that maybe I just don't want to tell every website I use who my childhood crush was. There's also the problem of most "secret questions" that are available being irrelevant for X% of the population. (ex. loners and people who didn't have a stable home life... they rarely include stuff like "who was your foster mom when you were 8?" Even the international crowd could have trouble with most questions.)

I'm old enough and have enough online accounts (I have 246 accounts saved in my password manager) that i now just write "fuck you" for all the answers and put 'all answers fuck you' in my password manager. Because these questions stress me out way too much and I'm constantly bombarded with them. Answering them becomes a major pain point when everyone wants them. I've completely lost it with the damn "[not so] secret questions."



Even worse are websites/services that impose ridiculous character requirements (you must include 2 symbols, 3 numbers, 5 letters, 2.5 of which must be upper case and positioned at the prime number indices, oh and you have to change your password every 6 months) and then limit your password to 8-12 characters.

The way I remember passwords is by stringing together random English words with random special characters inserted throughout. This means most of them are 30-40 characters. I find these far easier to remember than my PayPal password, which is arbitrarily limited to a random collection of special characters that must be of length less than 12 (or whatever their ridiculously short limit is.)

If you truly care about the security of my account don't impose character limits.


I spent 20 minutes trying to come up with a password for chase.com recently because of insane rules like, you can use more than two characters in ascending or descending order, can't use the same character more than twice. Using a random password generator above about 20 characters, and it's guaranteed to break one of there inane rules; let alone if you want to use a pronounceable passphrase that's simply long. It's really aggravating that big companies are some of the worst at this security stuff.


I use Bitlocker and I can set limits/conditions on pwd generation which is then saved under a master pwd.


Which Bitlocker is that? I'm only familiar with drive encryption by Microsoft. Do you mean Bitwarden?


Opps you're right....BitWarden


I've tried the random word string concept but I can't remember those ones either.

I feel like I filled up my password memory sometime in the late 90s.


It does make sense to impose some sort of upper bound (only so someone doesn't try and DoS you with a crazy long password), but 13 characters isn't going to bring a server to its knees.


I look at security questions and answers as a challenge and response. I stopped answering them logically when I realized I don't have to. So the answer to "Where would you like to retire?" might be "the sky has a long face." I won't ever use them unless resetting a password, and I won't be resetting a password unless I mess up synchronizing my password manager. Except when I do need them, because the dip shit that operates the site doesn't "recognize" the computer (browser session) I'm using. That crap needs to go.


This is fairly effective until the day comes when you use this method on a system that tries to be even nicer about password recovery... and presents your answers in a multiple choice context.

Where would you like to retire?

  ( ) Miami Beach, Florida

  ( ) Nice, France

  ( ) the sky has a long face

  ( ) Bozeman, Montana


What site is doing this, giving your password away?


TransUnion, for one.


Is TransUnion doing this with fill-in-the-blank security questions? Or are you referring to indetity verification questions base on credit report data?


I just generate more passwords for the security questions. Since I’m using a reliable, backed-up password manager, my primary concern is protecting my account from would-be hijackers, not resetting a potentially lost password.


Yes, because there is no way I'm answering what city I was married in. It is public record. A password-like "nonsense" answer is the only way to go.


The one thing I try to do is make sure whatever password generator I use for these produces pronounceable passwords in English that are relatively easy to spell, because so many of the places that want these really mean "Phone password".


1Password integrates with the iPhone's built-in password manager, so I'm never stuck typing in passwords anymore.


The issue isn't typing them. The issue is that many "Security Questions" are secretly "Phone Passwords" because customer service representatives can see them in plaintext and will ask you them if you ever have reason to call them over the phone. Making sure that they are pronounceable (mostly) English words avoids some of the potential awkwardness of reading them out of your password manager over the phone, even if they are intentional random gibberish. It also partly avoids the social engineering trap of "it's just random garbage" because at least if it looks like words a customer service rep may still ask for them anyway rather than not bother to one-at-a-time review a series of random characters.


Ok, gotcha. 1Password can also generate passphrases from dictionary words.

Agreed, the “it’s a bunch of gobbledygook” social engineering hack is a really serious vulnerability.


> Or the answer is 3 characters long and you have a minimum of four!)

"What is your favorite color? (Red is not allowed)"


Also 'tan','oat','yam','jam','ash','fog','ink','oil'

Source : https://digitalsynopsis.com/design/color-thesaurus-correct-n...


But TanOatJam is not bad.


That only has ~23.72 bits of entropy.


I use random passwords for reset questions because they're often the Achilles' heel that people drive around.

PS: 1985 Delta 88 Royale Brougham LS with dark smoke metallic paint, limo tint, more chrome that a Cadillac factory and burgundy velour, and a $20k sound system... what you inherit when your dad is an audiophile and wants a car that could fit 6 dead bodies in the trunk.


Interesting! Do you use astura everywhere on the web?

Just kidding... your approach is a good start, but use a unique password for each one instead of "fuck you".


No, I usually generate a new username per site with a script if a username is required. Either that or use a name generator to pick a random Firstname_Lastname username.

(It's not actually 'Fuck You,' but something similar and I do sometimes change it up with a few different simple phrase answers. I did own an 88 Cutlass Supreme [worst car I ever owned], but it wasn't my first car.)

Maybe that should be a security question, "what the worst car you've ever owned?," now THAT'S easy to remember all the times you're stranded on the side of the road, stalling in the middle of heavy traffic, and all the repair bills.

Problem with "other password approach" is "I just put a bunch of random characters in there" becomes a valid response to an overseas customer service rep if you're talking on the phone.

EDIT: Ok, any English word or phrase would work for "other password" just fine. I guess after idk how many years of trying to use the "secret questions" as intended I just get angry every time I see them.


You're right about the other password approach, it seems like the best alternative is a passphrase.


Yeah. a secret answer is just a secondary password with extra restriction (have to be actual words) and you also get a hint.

it only makes the the account less secured.

the rule should be, you forget your password, say good bye to your account.


Or "show up somehow in person". We have all of this physical infrastructure we could take advantage of for critical accounts: IDs, notaries, passports, post offices, etc.

There are accounts where that may not entirely make sense, but a lot of my accounts I would love the option to state "The only way to recover from a lost password is to send a notarized letter via snail mail explaining the problem."

No one but me should be able to touch my digital bank accounts without having to first show up at a bank location with my ID or a signed certificate of death.

"Immediate" password recovery is part of the problem. A lot of our accounts most people don't need to recover the password immediately, especially if the reason they have forgotten is that they haven't needed the service in months.

Also, phone calls and text messages aren't slow enough.


I feel the same. As a workaround I keep my answers in the password manager notes. Thinking about it it would be more secure in this case to lie.


Apple still does this. So does United Airlines. Many sites do this and I think it reflects badly on the company.


Just put another password in that box!


Problem with that is "I just put a bunch of random characters in there" becomes a valid response to an overseas customer service rep if you're talking on the phone.


I've successfully responded something like "It's a 25 character random string beginning with A#fx and ending with ^tx% - would you like me to read the whole thing out?" to customer service reps. (I've never tried to see if anyone will give me access to an account just by saying "a bunch of random characters", but I wouldn't be surprised if they did...)

These days I just use 1Password's 4 or 5 word password generation option where it works. "What is your mother's maiden name?" "I answered 'griffin accolade stallion catboat' to that question."


That's neat that 1Password does that. I tend to do something like "Clark Dark Bark Park" for "First school?" and record it in LastPass's notes.

A lot of the questions are dumb, like "Favorite Food?" with a pull-down of 8 or 10 answers.


https://iancoleman.io/bip39/ is similar. Press the GENERATE button and grab the first few words off the seed.


OSX Keychain has a "memorable" feature for password suggestion (e.g. getup3_gulag). 1Password has a "words" type of password (e.g. ancestor-dissent-rubdown). I suspect other password managers have similar. That's what I use in this situation.


Also, the classic Diceware lists are great for these. Print one out and roll physical 6-sided dice for the full experience.

http://world.std.com/~reinhold/diceware.html


Good point.


In that case, a series of random dictionary words can suffice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: