openssl rand -hex 8 | sed 's/..../&-/g;s/-$//'
Or if you like upper-case letters: openssl rand -hex 8 | sed 's/..../&-/g;s/-$//;y/abcdef/ABCDEF/It's either that or pick a random dictionary word.
grep --perl-regexp '^[a-z]{4,7}$' /usr/share/dict/words | \
shuf -n 5 | tr '\n' ' '
Although maybe just 2 or 3 words would be best for avoiding a support agent skipping the question. bless clench moraine shuf /nix/store/ny99jkpl3r9zgkkdv5apprzl18i8rb4m-scowl-2019.10.06/share/dict/wbritish.txt \
| grep '^[A-Za-z]\+$' \
| head -n 3 \
| sed -e 's|\(.\)\(.*\)|\u\1\2|g' \
| tr -d '\n' \
| sed -e 's|$|\n|g'
Which gives you for example: OmegasInsentientPantheons
I only use this for “secret” questions though, not passwords.Many people are, contrary to all pretense, mostly paid to not give any actual fucks.
But I was relieved to find my CC provider calling me to verify I was just up to shenanigans.
I was also curious how many thieves they had run across that signed for purchases as stolen in large cap letters.
The saddest thing is banks can't be too secure. If they were, then they would be too hard for normal people to use and they would get locked out of their funds.
I would literally close out my account in that very moment if my bank did that. Not only because that's horribly inconvenient and I would never put up with it, but it also shows they have no idea what are sane security measures or not.
Yes.
They also force users to install literal malware into their computers masquerading as a "security module". Not only is it invasive, it slows down everything to a crawl. I tried to reverse engineer one such module and caught it intercepting every single network connection. It also used to force install itself into browsers as an extension, no doubt in order to intercept data.
> I would literally close out my account in that very moment if my bank did that.
That's exactly what I did. Chose a smaller bank that somehow didn't use this malware. The least bad option.
As for the asking birthday for security reasons, relic from the past, getting more useless as time goes by. With so many websites asking for that information, and then they get hacked, sold or leaked. Yes, this said the completely obvious, but it still amazes me that any organisation that I have a financial relationship with asks that for identification over the phone, usually my address as well, but that is almost as public.
- authenticating using a 'client number' (different from your 'account number', sent to you once by a physical mail you lost long ago) combined with a 4-to-6 digit (numeric-only) passcode that you have to input on a virtual keyboard
- confirming web-initiated transactions via their app on your phone... but when it's app-initiated, well, you don't have to confirm anything other than just retype your passcode
- in the end, introducing some awfully long delays between some actions e.g. creating a new beneficiary and being able to send money to her... because 'it's for your own protection that we degrade your client experience'
This just bugs me.