Slashdot Mirror


Secret Security Questions Are a Joke

Hugh Pickens writes "Rebecca Rosen writes that when hackers broke into Mat Honan's Apple account last week, they couldn't answer his security questions but Apple didn't care and issued a temporary password anyway. This was a company disregarding its own measure, saying, effectively, security questions are a joke and we don't take them very seriously. But even if Apple had required the hackers to answer the questions, it's very likely that the hackers would have been able to find the right answers. 'The answers to the most common security questions — where did you go to high school? what is the name of the first street you lived on? — are often a matter of the public record,' writes Rosen, 'even more easily so today than in the 1980s when security questions evolved as a means of protecting bank accounts.' Part of the problem is that a good security question is hard to design and has to meet four criteria: A good security question should be definitive — there should only be one correct answer; Applicable — the question should be possible to answer for as large a portion of users as possible; Memorable — the user should have little difficulty remembering it; and Safe — it should be difficult to guess or find through research. Unfortunately few questions fit all these criteria and are known only by you. 'Perhaps mother's maiden name was good enough for banking decades ago, but I'm pretty sure anyone with even a modicum of Google skills could figure out my mom's maiden's name,' concludes Rosen. Passwords have reached the end of their useful life adds Bruce Schneier. 'Today, they only work for low-security applications. The secret question is just one manifestation of that fact.'"

5 of 408 comments (clear)

  1. Simple solution by Anonymous Coward · · Score: 5, Insightful

    Let people design their own question.

    1. Re:Simple solution by NeutronCowboy · · Score: 5, Insightful

      Even simpler solution: design your own answers. Yes, you'll get funny silences over the phone when you tell that the rep that you were born "On the moon", that the street you grew up on was "the yellow brick road", and that your mothers maiden name was Humpty Dumpty. The upshot is that no one can guess, the answers are meaningful to only you, there is only one answer (the fake, important name and place), and, because the answers are whatever you think they should be, applicable.

      --
      Those who can, do. Those who can't, sue.
    2. Re:Simple solution by fredprado · · Score: 5, Insightful

      And they are within their rights to do so and suffer the consequences for it.

    3. Re:Simple solution by Isaac-1 · · Score: 5, Insightful

      And as long as you always answer 42, or 416 what is the problem with that?

  2. Re:BYO by X0563511 · · Score: 5, Insightful

    I'd rather just be able to disable the questions entirely, relying on a good password and if that is lost/whatever, account specific information being verified by a human on the phone.

    My problems with these "secret questions" are:
    1. They are obviously stored cleartext
    2. They can be used to "substitute" for your non-cleartext password
    3. Because 1+2=3, if someone breaks in and grabs a dump of the table, they now effectively have your account. These "insecurity questions" are more of a liability if you are not one to just lose passwords. Crutch for the stupid, barrier for the secure.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...