The best systems I have seen are the ones that use your credit history to ask you several questions like "Which one these four streets have you lived on?" or "Which one of these four employers have you never worked for?", but even those are gameable with some research. There has to be some better solution out there.
It could be the same one I use for 2FA to the website. Or, an entirely offline flow would work too where they sent a dead-tree mail with the shared secret in QR code format.
So clearly it can be done. Swedish banks have been doing it for at least 20 years.
At least with simple "mother's maiden name" type questions, you could, if you were concerned by its insecurity, choose to use a secret value. With the automation of the process, that is not an option, while the security value of this pseudo-secret information will be eroded by its inevitable over-use.
I have both recorded in password vault and both are random.
The benefit is it they've reset my password for some reason or it was hijacked. I've been able to recover accounts. Not because I forgot a password but because it was essentially a harder to change 2nd "secret"
That is, indeed, the problem that these questions are supposed to avoid, but they only offer sort-of security to the extent that the information is sort-of confidential. Anything that the automated validation service can find from public sources can also be found by the black hats, and the more common these automated services become, the more worthwhile it will be for the black hats to similarly automate their search for them.
The end result is that real security that is based on something you know has to depend on secrets.
Given how bad the credit companies are at distinguishing me and my father (we share a name), I don't have much faith in this process either. What if you don't have a credit history?
Realistically most businesses don't have a need to pin an identity to a real-world person.
The assumption that you have, that the system "just works" is awful. Because when it turns out the system actually doesn't work, it's a fucking clusterfuck just to get someone to listen to you because they don't believe you are who you say you are, and government issued ID is apparently insufficient.
And the government seems to think I am the same person as my deceased father and grandfather because we share a name, and holy fuck is it frustrating come tax season (I have never in my life had my taxes accepted the first try and have had to physically visit the IRS before) or any time anybody tries to do any sort of background check on me.
Their founder is going to jail but the tech was OK - take a photo of your ID with your phone and look into the camera. Do the faces match?
Cool!
Other systems require you to record a video of you saying a particular sentence which is then checked (presumably) by a human. And others require a video call to a real person.
None of them were true, because when I was first opening my credit karma account was when I first got a credit card; up to that point I had no credit history at all. When it asked me these questions, and I believe it implied one of the questions was true, I assumed my identity was stolen and got a report from transunion and equifax.
Turns out my identity was never stolen and credit karma was just being obtuse.
(And to your point, I literally had to provide it earlier this week to Chase’s fraud department.)
Searching your name and city+state in Google shows several websites that collect public records and show relatives. Some include age with names. The only people that showed up as relatives that were plausibly your parents (based on age) were two people: one with your same last name (probably your father), and one with a different name (Klass) (most likely your mother).
Having a pretty rare last name makes it really hard to stay anonymous, especially when you engage in public activities like entering road races, buying a home, and voting. Guess it’s a bit late to start using a pseudonym.
Edit: mylife is insane. I’ve googled myself in the past and this much information didn’t used to be so readily available in search results.
I don’t know how a right to disappear would even work when a bunch of the results are curated straight from public records.
Edit 2: I think if I cared more about this I’d have to engage in a prolonged disinformation campaign to muddy the search.
Actually, no. It only takes 2-3 years to disappear from most casual google searches. I know people always say 'the internet is forever' and for some things it might be, but I was suprised how much of my online traces just faded over time after I started being more careful with my identity.
The worst is doubtless to share an uncommon but not unique name with someone who could plausibly be you who is controversial/a criminal/etc. Pre-Web I went to school with someone who shared a name with a very unpopular figure in the same city. My schoolmate got literal death threats left on his answering machine.
So it literally only works for this purpose the first time you do it, now it's not private anymore (even if it was to begin with). Now it's on file just waiting to be leaked.
For example, how many of us are suckers who have submitted scans of our passport and drivers license to a website like coinbase.com?
It's only a matter of time until https://haveibeenpwned.com/ lets you type in your DL/passport number and it'll tell you how many scans it found in data dumps.
Someone doing social engineering may answer "It was a bunch of random characters/words, I'm sorry I don't have it in front of me" and have that accepted. If they don't accept it, hang up and try again with another rep until someone does.
Picking a random real place off Wikipedia (different for each website, and store that in 1password) avoids this.
My hope would be their training largely prevents "oops I can't remember" getting through, but I suspect you'd eventually get someone quitting tomorrow who doesn't care, or someone having an off day.
[1] Stephen M. Bellovin. 'Frank Miller: Inventor of the One-Time Pad'. Cryptologia 35(3), pp. 203–222, 2011. DOI: 10.1080/01611194.2011.583711
I generate random strings for these and store them in my password manager. On several occasions I've called companies for whatever reason and they've asked these questions to verify my identity. When I say "oh it's a random string let me open my password manager to confirm it" they often reply with "oh it's ok, you're right it's gibberish" and consider me verified.
Just don't answer the questions basically.
Also, you don't need to type gibberish. If your mothers maiden name is Jones, you can enter her maiden name as Steenberger and store that in your password manager.
Though it isn't as bad as; 'You can't cheat an honest man'. You hear someone saying that, you start counting your fingers before you shake hands and check them again as soon as your done.
Encountering men with hyphenated last names is uncommon enough (for me) that I don't know the rules for that, so if that's the case, I don't know either.
It really is a pretty outdated and sexist system, really.
If you know the person's name and roughly when they were born (which you can get from the age) and where, you can get the Mothers Maiden name easily.
I found mine here https://www.freebmd.org.uk/cgi/search.pl in a couple of clicks.
But looking up myself (and my brother) I noticed that the record date is a month or two past the actual month. So for me being born in March seeing myself listed as June and in my Brothers case seeing September listed as December. Well, makes me wonder if they had backlogs back then. But most happy it is that way, I know my actual birth certificate has the correct date (still have the original) and those are accessible in some form or another. Just mindful that not all records are that accurate.
BankId is a 2FA mechanism that proves that you are who you say you are. Before you can download the mobile app (Mobilt BankId) and assign a password, the bank must issue you a card with a certificate on it (BankID på kort[0,1]).
You use this card to then validate the Mobilt BankId, since it creates a chain-of-custody for identity, as it were.
In other words, someone with your personnummer on-hand can't just download Mobilt BankId and then assign their own password because they're lacking the physical evidence [read: the BankId på kort], which prevents them from falsely representing that they are you.
How Mobilt BankId works with BankId is that it houses a certificate (much the same as BankId på Kort) and leverages the same auth prompting mechanisms for challenge/response to authenticate the user. Essentially, it "replaces" the kort but only in the sense that the kort is required to be physically present in the system. With the Mobilt BankId app, the certificate is always present.
Sorry for the long-winded explanation but it isn't as simple as downloading the app and assigning a password and don't want people to get the wrong idea. :(
You also don't lose it or forget it, like you would password or 2FA device.
However, I do agree that in general several "security questions" that are meant to be hard-to-guess data points are actually easy to find the answer to frequently. Maiden names, and school names/cities/mascots, are often found in online profiles in one way or another.
At the same time, I'm not sure the risk is as large as it seems. These security questions help prevent bulk identity theft and add a friction point to the process, they are certainly not equal alternatives to real 2FA, but they are also less "brute forceable".