Security questions are salt
blog.jgc.org
blog.jgc.org
"Hi, I need to make a change to my account."
"All right, ma'am, I'll have you just answer this security question first: What is the make of your first car?"
sigh "So, look, this is going to sound really stupid, but for these questions I always use random words, and I lost the paper where I wrote them down... I'm really sorry, I just don't remember what they are. It's not a real car make, if that helps, it's just some random nonsense words."
"Uh, let me just talk to my supervisor." [hold] "What can I help you with today?"
If multiple sites use the same security question, they will contain the same answer. Therefore if one site has been compromised, someone could use it to login as you at another site.
To fix that you need to add the site itself to the data to hash.
Just store your "random" Security Question answers alongside the login credentials - they'll be encrypted safely.
--
Keepass, on the other hand, is useless unless you have the database file with you.
Also, on the same subject, it's the "all you need is your memory" bit that makes me smile. If you could rely on your memory then why would you need to have these hashing functions in the first place? (:
[1] http://portableapps.com/apps/utilities/keepass_portable/
If I'm at a cybercafe somewhere, there's a high degree of probability that it won't let me just run some untrusted binary from my USB stick or the web.
Also, carrying an USB stick still defeats the point of being able to recreate them with nothing. I've lost more than one USB stick in my life.
Also, on the same subject, it's the "all you need is your memory" bit that makes me smile. If you could rely on your memory then why would you need to have these hashing functions in the first place? (:
If you can't rely on your memory, how will you know the master password to open the Keepass container?
Simply put, it's hard to remember a password for each and every site, but it's easy enough to remember a single algorithm (plus a master password) for all of them.
1. You shouldn't be typing in high value passwords at <random cyber-cafe>.
2. You can get KeyPassDroid for your smartphone.
3. writing your master-password down somewhere may be useful to your next of kin.
2. I don't have a smartphone
3. Not really, due to (1).
Password management is not a technical problem. All these 'solutions' to passwords being 'insecure' massively miss the point - which is that people just forget things, especially when they need to remember dozens or hundreds of them. Use a password manager and get rid of these nonsensical hacks.
This is used for the few times where I have to do password recovery / phone support, I just grab the book.
For normal password usage I use automated hashing system in Firefox.
ymmv
Instead of paper I do use a password program, and ensure that the encrypted data files are replicated to several different places.
A workaround may be to just simplify the phrase to "first car" and use that.
# gsort -R /usr/share/dict/words | head -n 2
inductory
thingstead
"What was the make and model of your first car" - turns out, I was driving a brand new Inductory Thingstead, and changing the minute details of the secret question (or me changing the password) won't affect anything.(One potential downside is having to tell an operator that your car was a "trichroic somatopsychic", which would just take extra time to spell out, unless they see the answer in plaintext.)
> unless they see the answer in plaintext
I think they do.
Good thing about security questions is that they don't have to stand up to offline attacks, so a few tens of thousands of options for each might well be sufficient.
If I'm talking to someone on the phone and giving them my secret answer, I doubt they're going to be giving me the third degree about why my mother's maiden name is "antireligious electrocardiograph", especially if the computer accepts it.
I die a little inside every time some site emails me my own password.
If you're in the EU, and are storing personal data, you are legally required to protect it. Think carefully about how you set up your EU based web app.
Example: In Ireland it's probably against the Data Protection Acts to use a date of birth/mother's maiden name as a 'security question' for personal data. (cf. http://www.dataprotection.ie/viewprint.asp?DocID=1212&St... http://www.dataprotection.ie/viewdoc.asp?DocID=1062&m=f )
I'm looking at you, Citibank.
IOW: When designing a scheme like this, the fact that you'll be angry when trying to actually use it at some point in the future becomes an important design constraint.
I'd a neat (imo) idea for this, though not everyone agreed: http://news.ycombinator.com/item?id=4349116