I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
https://www.logmeininc.com/legal/privacy
it basically says they collect everything possible to collect and will use it for anything they want including sharing with 3rd parties
The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?
attacker accesses recovery answers for site A. Sees that it is random characters. Attacker has access to site A.
Attacker phones sites B,C,D and E, trys social engineering. Attacker now has access to site B,C,D,E also.
Support: what is your fathers middle name?
Hacker: Michael
Support: sorry that is wrong
Hacker: oh shoot, I forget I always put the incorrect information in this one... i can't remember, did I put a fake name or random characters? Or was this the one I put a bunch of words into?
Support: yeah, it looks like random characters... let's move on
"Computers are hard, and I'm just not very good with them!"
"identity theft high risk 2fZMbjL1lLZgnS8La"
As an earlier comment pointed out [1], random responses to security questions are a bad idea. I've personally tested this by entering a random security answer, calling the service, saying I forgot my password and entered gibberish as my security answer, and being let through. I presume technically-savvy people think this is more secure; if I can guess that, an attacker can too.
In social engineering, it is common to call back multiple times looking for a gullible customer service rep. Even using a recording of a crying baby in the background to Garner sympathy is something I've seen done.