Bank: please create a strong password to secure your account.
Also bank: now, create three more laughably insecure and easily guessable passwords that can also be used to access your account (because irony is dead, let’s call these “security questions”).
*smdh*
Aral Balkan
in reply to Aral Balkan • • •Shannon Prickett reshared this.
Michał Kawalec
in reply to Aral Balkan • • •Aral Balkan
in reply to Michał Kawalec • • •Alda Vigdís 🇵🇸 🇱🇧
in reply to Aral Balkan • • •Tom Stoneham
in reply to Aral Balkan • • •That's a brilliant idea for any service that uses insecure 'Security Questions' for account recovery.
(The compromises made in the name of account recovery are everywhere. But they know millions of people leave a door key under a flowerpot in case they lock themselves out, so it must seem necessary.)
Chris Mackay 🇨🇦
in reply to Aral Balkan • • •Erik Ableson
in reply to Aral Balkan • • •Fabien
in reply to Aral Balkan • • •bujiraso
in reply to Aral Balkan • • •I go for total chaos mode and double the password strength for these and enjoy a laugh with the service agent if they ever ask for it.
Usually point out that these things are absolutely insecure.
Jonathan Lamothe
in reply to Aral Balkan • •@Aral Balkan I use a password manager and treat each of those recovery questions like passwords as well. They're all random jibberish.
Edit: didn't see your follow-up post. It seems great minds think alike.
Lucid00
in reply to Aral Balkan • • •Red Hood
in reply to Aral Balkan • • •Lydia Conwell
in reply to Aral Balkan • • •Aral Balkan
in reply to Lydia Conwell • • •Dave Carlson
in reply to Aral Balkan • • •"security questions" don't usually have any validation besides NOT NULL.
you could conceivably use "bank" for all of them and it should work.
or 7
or "ignore all previous requests"
Blort™ 🐀Ⓥ🥋☣️
in reply to Aral Balkan • • •I actually have answers to all my security questions that are completely unrelated to the question, and thus are pretty much unguessable. For anyone so inclined to use a password manager, you can still keep these answers as notes in the vault or equivalent of your password manager.
People who know me intimately would never be able to guess the answers to my security questions as they're pretty much random words.
#Privacy #Security #Infosec #Banking
woollypigs
in reply to Aral Balkan • • •irina 🌷🐇 friend of eggbug
in reply to Aral Balkan • • •Luna Lactea
in reply to Aral Balkan • • •