Why 'Secret Questions' Suck as a Security Measure
jamesburkhart.com
jamesburkhart.com
So worst of all worlds: harder to remember, easier to break.
I'm talking about the scenario where someone either has your answer from another corrupted site, or tracks down the information publicly, like the kid who 'hacked' Palin's email.
Assuming you're using legit info, it's easy enough to try several reasonable variations of, say, University of Iowa, in the way a human would abbreviate it.
The whole concept has always been silly; glad to read a well-rationed argument against it. But honestly, why should we even need such an argument?
I also deeply resent random ecommerce sites asking for personal information like the name of my dog or high school. My answer is always a random variation of "none of your damn business." This has caused me some problems when I do need to reset my password, but contacting support resolves it.
The exception is any website that doesn't require use of their prescribed questions.
I stopped using them then.
If at all possible, however, I don't fill out the secret question. There are actually a good amount of major sites that let you skip that step.
I'd rather just be locked out if I forget the password, than have that be another vector for taking over the account.
So, I definitely agree with the article, there has to be a change. You sure can beat security questions (at least in their current state), but it's probably much harder to get around something like email or SMS verification.
Chase.com and cardmemberservices.com are good examples of SMS/email account verification done right, which I've used with great success, but both of these sites already had my personal phone number, so SMS verification just makes sense for them.
I suppose SMS verification is probably the closest thing we've got to real user verification at the moment, am I silly to consider this the ideal venue for account recovery?
The big issue, then, is it's definitely harder to get a user's phone number than to get their mother's maiden name, but skipping all that extra input and having a simple account recovery email should do the trick, shouldn't it? Most of the times you're already collecting user emails.
Well, the biggest issue with email is that an email account can also be compromised. Perhaps getting big email companies like Gmail to remove security questions from their apps in lieu of SMS verification is the next step, while everyone else just relies on email-based account recovery (unless SMS is an option). If email security was more rock-solid, then email verification is all we need, right?
Names? http://www.census.gov/genealogy/names is a good database for the US; 1,711 names will get you the top 50% of last names for "Mother's maiden name", questions. 59 male names and 138 female names also represents 50% of the population (Yes, we're pretty unoriginal). There are <100,000 first and last names in total which cover 90% of the population. (not combinations)
Birthdates? There are 365 days in a year, so 36,500 numbers will cover this one.
Last N digits of your drivers' license/social security number/credit card? There are 10^N such numbers. N is often 4, which is a measly 1,000 numbers.
Pretty measly stats.
Thankfully, Chase does email as well.
(Verizon: 20¢ ea., so 1GB / ( 160 bytes/ea) * 20¢/ea = $1,342,177.28. Though you can get a plan for 250 for a mere $134,217.73/GB.)
I hope I did the math above wrong.
Oh, they're also requiring that we encrypt the answers in the database. With encryption keys stored on the same server. But that's a separate (and arguably sillier) issue.
Well, that's fine. Just keep the decryption key somewhere else, or don't use an algorithm that can be decrypted.
The only thing required is a well-designed text normalization algorithm, which will neglect all variations in case, spacing, punctuation, spelling (i.e. "color" vs "colour") and other similar sort of issues.
(In edge cases, where this may fail, the plaintext answers could be recovered by authorized person from off-site write-only-API "secret storage" server, where the data should lay encrypted with asymmetric crypto. Less convenient, but more secure.)
So now there are a lot of accounts with some very strange answers to their secret questions - answers so far out that I would have to write them down along with the complex password... which makes them completely redundant.
The secret question is an attempt at the first method. However, "what's your mother's maiden name" fails because it's so easily discovered through web sites (Ancestry.com!) and via social engineering.
Problem was that the card had been ditched months ago, so there was no way I was going to remember that. I eventually remembered the password, but I wonder how I would have gained access to my account otherwise.
Some people are too creative with password "security" for their own good.
Lets say that my computer gets keyloged and the attacker gets the account/password of site X and my email info aswell. Now the attacker wants to take over both of the accounts. Lets see how things will go if no secret question is involved: At best site X for a password change will require a e-mail confirmation, probably by just providing the old password the attacker will be able to change it. On top of that the site that hosts my e-mail can't be linked to something else, because of that i guess by simply providing my old password the attacker will get over my e-mail too.
HOWEVER if the sites require a secret question/answer verification the attacker wont be able to take over my accounts. And i am able to change both the password and get full control of the accounts.
Secret question/answer feature should be treated as a MASTER password. You have your casual password which allows you to identify yourself to the system etc but if you want to change some critical information of the account you will have to provide you master password.
If both the site and the user make good use of the feature there is nothing wrong with it.
The article also reminds me of another anecdote.Many years ago in the last millennium I checked out this German teenage forum (bravo.de) because well, I was a German teenager. Anyway, on that forum you could not only give the answer to the security question. They even allowed you to specify the question you want.
That feature amused me a lot and I checked out other people's self-made security questions. Being a teenager forum in the later 90s this is what happened. A very substantial number of forum users had the security question 'what is my favorite Backstreet boy' or a variation thereof. And, well, pretty much everybody loved Nick Carter. Nobody liked the others. In just one our I was able to log on to many, many accounts just with the phrase 'Nick'.
If they really wanted to get clever, 1Password should offer an option to perform this task automatically when you're filling out a registration form.
Fast forward a few months, and I call the site's billing department. The decide to verify my account by asking me my secret question. Queue the CS rep on the other end being extremely confused when I successfully name out a long string of characters that he thought was just corrupt data.
Excellent point about the plaintext though.
Also, I don't recognize a lot of my friends because we all graduated high school together a quarter century ago and I haven't seen them since, unless we both attended the same reunion at some point.
It's upto you what to use as questions and answers