• skaffi@infosec.pub
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    As long as you can choose the answer, you can also choose what the question really is. You can just decide that questions about your mum’s maiden name are actually asking you about the last name of the doctor that delivered your first born.

    Or, better yet don’t tie security to personal or externally verifiable information about yourself. In the one or two cases, in recent years, where I’ve had to fill out such (in)security questions, I’ve just treated them as additional password fields, where I just create additional fields for them in my password manager, and generate long, random responses as their correct answers. Why yes, my mother’s maiden name is Correct7Horse@Battery!Staple, why do you ask?

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      I once did that, and had to spell out a 32 character alphanumeric password with special characters over the phone lol

    • Zwuzelmaus@feddit.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      additional password fields, where I just create additional fields for them in my password manager, and generate long, random responses

      Such hassle…
      I guess it means yes, you take that stuff for serious.