Columnist asked researchers what they could find out from just his cell number
nytimes.com
nytimes.com
That's why you don't answer those questions honestly. My mother's maiden name is always a random 32 character string living in my KeePass database...
I know this is often asked over the phone, so that'll be a little awkward, especially if using non alphanumeric characters. Interestingly though, I wonder how easy is it to reset your mother's maiden name to a new name if it go out in the wild.
For them, maybe, but I would relish reading each individual character to them in a slow deadpan monotone.
Social Engineering.
Q: "What is your mothers maiden name?"
A: "Do not provide access under any circumstances unless this exact key is provided: WEWQEWQ321312"
Definitely more plausible as a pets' name than a maiden name.
</pedant>"Sorry I did not hear, but there seems to be a problem with our computer system I am getting an error message instead of a name, please can you call back later".
Screen shows them: "Do not provide access und" 25 character silent truncation.
[0]: https://github.com/bbusschots/hsxkpasswd
[1]: https://www.bartbusschots.ie/s/2015/09/06/using-the-hsxkpass...
Perhaps that's just the way it should go down in a case like this. But there are costs to making the decision to close off the potential for social engineering as thoroughly as possible.
As a follow-up to my experience, I guess I should expand on the consequences for us. The bank admitted fault, but to protect themselves from a bad employee doing it again in the future, now when we call we have a special voice-only password and PIN, and we have to answer a battery of questions that are clearly pulled from a credit bureau (you know, the types of questions like "You had a mortgage in 2005, what was the street the property was on" and such things. Takes 10 minutes to get to "Thank you sir, how can I help you today" if we ever have to call customer service.
Based on that experience, I think perhaps the bank should make that the answer to recover a deeply lost account. They gave a stranger the credentials to our account -- not just the password, but they had to tell them the login, and disable two-factor authentication (because the login is built from a PIN and RSA code) based on a plea for help. I can see forgetting your password, but who forgets everything? That should be a huge red flag.
I could rant for a long time. I had a pointed discussion with a manager at the bank about how getting five repeated, fruitless requests to change credentials on an account didn't somehow trigger any protective response. How hard would it be to implement a counter that says "okay, after the second attempt to gain access by voice to an account that is denied for lack of authentication, all future calls for this account go directly to the security department for personal attention"? I got no good answer other than a lot of "yes sir, this was completely wrong, sir, I'm sorry, sir" etc.
Obviously, access to a banking account should have a pretty high bar even if that means some people may well end up in difficult situations where they've lost access to their money and the bank can't/won't do anything about it based on a phone conversation.
It's security through obscurity, with a bonus that the people who use this technique can't seem to keep quiet about it so it's not even obscurity.
Personally I include many literary/media characters. Even my name on this site.
Combine this with similar unique answers to other questions and the chances of someone guessing them all become really small.
One thing I never tried is to just put something like Anyone_trying_to_reset_this_password_is_a_hacker_DQWIqw12E^1&UTFD@&$. Might be an inconvenience if you actually need to reset yourself.
Instead of a gibberish generator (ala password managers' defaultly-generated passwords), use a _word generator_. Something like "correct horse battery staple" except, you know, not the popular words.
Then, of course, make sure to include those secrets in your password manager.
How would the call center know if your mother's maiden name is actually Smith if you never answered the question honestly?
I could see the "It's a lot of random letters and numbers" response working by itself though.
Operator: What is your mother's maiden name?
Hacker: Smith (let's say this is the real name, gleaned from public records)
Operator: That's not what I have here
Hacker: Oh, you know what, I think I just put gibberish when I signed up. I thought that would add some extra security, but I forgot what I wrote, ha ha, joke's on me. The real name is Smith though.
Operator: Story checks out, I'm giving you access to the account now.
Operator: Story checks out, I'm going to reset it to "Smith" for you.
"Hello Mr Thombat, I can see your account number but first I just have to ask you some security questions...what was your grandfather's occupation?"
"Sasquatch"
"That's fine ... now what was the name of your first school?"
"(nervous giggle) Sasquatch"
"Ahhh...and was your first pet's name?"
"Sasquatch, too. I mean too as in also, not two as in the number...I really didn't expect I'd be telling these to a person, it was just a nice word to say..."
He kindly overlooked my embarrassed tittering, didn't go all jobsworth about this horrific breach of security best practice, nor yet accuse me of lying to one of Her Majesty's civil servants for pecuniary advantage. And (in my defense) no amount of dumpster diving or Facebook scraping would have revealed my family's secret shame that grandpa used to roam the American woods in a monkey suit.
I also use a random combination of words instead of just characters; Yellow Mountain Bad Hernia 13
Call center employees will generally think it's my own connotations (if it's school they will think there is a yellow mountain nearby and maybe I had a hernia... words tend to have associations)
The bank person was really weirded out when I said it back.
a. Have your name tied to your Hackernews profile
b. Have your bank account security question tied to your Hackernews profile
You appear to have done both, which does not seem like an excellent idea.
Earlier this year, I opened a new account with the (new) bank and discovered that they already had my mother's maiden name, were going to use it for identity verification, and wouldn't allow me to change it to something arbitrary (even another fake name that I sometimes use). Quite frustrating, this security based on insecure information.
Then I confirmed and started reading it out to her, and she hung up on me. I think I should move to correct-horse-battery-staple style in the future.
That's... troubling. I would have called back specifically to complain about that person. That's absurd.
The KeePass plugin Readable Passphrase Generator[1] is great for generating Diceware[2] passwords/usernames/security question & answers
Source: Found on KeePass plugins page[3]
[1] https://bitbucket.org/ligos/readablepassphrasegenerator/wiki...
This effectively allows using the security question as something that can be more reliably recalled by the user, but largely avoids the security issues of an easy to guess secret.
It seems strange to me that peoples names, addresses, and phone numbers used to be freely distributed in a large book to every house in town yet now any one of those details can be used to assume someone's "identity." It seems the only thing stopping this from happening en-masse is that nobody has tried.
You can go to a bank, say "hi im John, my social is 123456789, I'd like to take a ten thousand dollar loan" and they'll give it to you if their records show that the name belongs to that number.
If that's so, why isn't this happening in massive numbers, given for example the 143 million SSNs that leaked through equifax?
I think it's harder these days than the other poster says, but there is still plenty of financial fraud.
When I had my identity stolen the crooks still had some Fake ID with my name and info. They found small cellphone kiosks (a makeshift promotional tent) inside large stores with lax security to make their purchases.
(They remember it, or they write it down and store it with their other valuable pieces of paper.)
In practice, by just marking the damn pages.
Edit: latest statistics show >95% have BankId on a smartphone. See https://www.bankid.com/assets/bankid/stats/2019/statistik-20...
A super high end hotel in Singapore would leave client bookings at the check in counter with address, name, credit card also.
https://hackernoon.com/nextcaller-what-does-your-phone-numbe...
Although I think NextCaller no longer has this Twilio integration, there are similar services that provide these details at this price point.
Of course, they probably contractually cannot do this and would get cut off immediately if they did.
Edit: Didn't know, nextcaller is a YC company. LOL
(I should caveat, I'm having a "pessimist day" today, so even sunshine and rainbows aren't as pretty today as they normally are.)
Yeah, sounds like credit bureaus :).
With the shear quantity of data analysis that goes on behind the scenes and affects citizens, I think we need a much better handle on transparency. We already have some level [inadequate IMO] of control over the established credit bureaus, I think that should be expanded to all data brokers that sell personal data like this. If I can't keep it from being sold, then I should at least be able to see what it is and make sure it's accurate.
Maybe it's time to look into how to pollute the data set instead.
I recently found a lost wallet. The only things in it were cash and some credit cards (and a Kohl's loyalty card). The person had a semi unique name, only 4 in my state, and it was easy to find all of the data listed in this article about them. Whitepages-style sites usually have age, relatives, sometimes phone numbers and addresses, and you can put together the pieces from different sites:
I found the wallet at a Dude Perfect Tour show with my kids, so out of the matches I found, I assumed it was less likely to be the 67 year old. Another came up repeatedly for crimes: Domestic Assault & Battery, and drug crimes. I doubted this was the owner, and wasn't sure I wanted contact with anyone like that. Anyway, that left two people. The first one I called had lost the wallet, and I mailed it to him.
Again, all I needed was a name.
In the list of info gleaned from your phone # the writer forgot your online purchase history, vehicle VIN & plate number and pretty much EVERY MOVE YOU MAKE day-to-day thanks to O/L retailers, your cell provider, your TV/provider, your DMV, your insurance provider, your city/county/state/Fed & everyone else under the sun selling your info. Many ask for your phone # "for security reasons" and then immediately sell it. TFA states it is better than your "full name"... that's nothing, as I have >7 same-names in my metro alone. It is, indeed, better than your social security #(in the States, anyway).
Layers of security-levels to access records and appropriate log trails for audit shouldn't be that difficult to set up in this day & age.
I suppose, it's hard to implement in pure capitalistic economy.
- The New York Times