The Weakest Link Is You
medium.com
medium.com
Well, except by not having facebook (which luckily I don't have).
When you choose the you're friend you want to verify, it dramatically limits the choice pool for the next two, meaning you can't pick 3 mutual friends, you need to pick yourself, their friend from back in college you don't know, and their sister. Harder to do than get any three friends to play a prank.
I'd rather have to go through some manual time intensive procedure in the unlikely instance of losing access to my password safe, instead of opening myself that wide to social engineering.
* What if it's a non-critical service? * How do they link an ID to an account without requiring it at launch?
The question "What is your pornstar name?" asks for your mothers maiden name and first pets name...
To get your security details.
"To get your pornstar name, take your mother's maiden name and first pet's na--"
"Let me stop you there. You realise those are both common security questions for authentication if you forget your password, right?"
"Argh! You mean my bank knows my pornstar name?!"
IronKey have a reset mechanism involving security questions; I've never used it, and I don't know the answers I gave; they're on a sheet of paper, in a safe somewhere. Yes, it's going to be inconvenient if I ever need it, but if it happened tomorrow it would be a once-in-ten-years event.
My bank inconveniently REQUIRES security questions in addition to a PIN for online banking; again, the information they have is made up. I remember it because I use it regularly, so that ISN'T written down anywhere.
For almost anything else less important, I've either just ignored the security questions (ie. entered random data) or noted them in the extra account info field on the IronKey.
For email, I run my own mail server in colo. It's maybe overkill, but I don't care. Credentials are again 16 character random passwords that I couldn't tell you, and authentication is only allowed over TLS. I'm toying with going for full client SSL certificates but device support would be the issue. I've already discovered more than I wanted to about incompatible SSL implementations on mobile devices over the years, which is why I'm still building Debian packages from source linking to OpenSSL instead of GnuTLS... And there's no webmail access. Never did find one that wasn't either written in PHP, half-functional or abandoned.
Most people do. This piece doesn't really point out that people are a "weak link" (though they are) as much as it highlights that these "security questions" do not really add much security in most cases.
Sometimes security questions are used to augment a password, but in many cases, including the one given in the article, they are provided as an alternative to a password, and one that's often much easier to guess.
Hoo boy. They should let us create our own security questions that can't be asked in everyday conversations. I never liked "Favorite pet's name" or "Best teacher's name" and the rest of them.
Of course, I learned this the hard way. I had an ex that was able to breach my email because she knew personal details to answer my security questions (of course this was back in Hotmail days circa 2001).
That makes them absolutely useless, it's true. And it is the most usefullness you can extract from them. I'd throw them away, but lots of services make you anwser them once in a while.
Santander use the "if you don't recognise the picture above then don't login" method which is stupid as if people don't login regularly then they will forget what picture they choose and login anyway.
To login you need your password + your phone but to reset your password you need that USB with a unique fingerprint on. That way, I'd just keep it at home in some kind of safe.
More bother than its worth to me under those conditions, ought to be Ip based instead and kept server side.
If not, you're nonetheless one DB dump or other undesirable access away from having your account pwned.