Them: Can you confirm your mother's maiden name?
Me: Sure but just a second. I need to open my password manager because it's a long random string.
Them: Okay, that's good enough!
I reported that to their security and compliance team. Never heard back but moved my accounts from there.
Like, "what's your mother's maiden name?" "Lady with cheeto-colored hair." Or, "what street did you live on growing up?" "We liked to imagine it was the moon"
And all of the virtual reincarnations of all you security-minded suckers will be stuck thinking your mother's maiden name was X1r$9ox01.
> What's your cat's name?
Site X: Kareem Abdul-Jabaar
Site Y: Cassius Clay
Site Z: Franz Beckenbauer
I use the same technique too and at first I used words until I thought about having to call in, so now I just use two random words.
First rule of security questions - never answer them truthfully!
In this case, it's as if the security question just didn't exist. That's fine with me. I'd rather the attackers figure out the other security measures (e.g. get access to my email or phone in order to receive a security code) than just get into my account by pure guesses. (Though I like the solutions here of using very uncommon two-word phrases to avoid the chance of an incompetent phone operator accepting "random letters" as an answer).