Secrets, Lies, and Account Recovery: Personal Knowledge Questions at Google [pdf]
static.googleusercontent.com
static.googleusercontent.com
1. Additional vector of attack with lower than password threshold of security.
2. Questions may have common answers.
3. Few possible answers.
4. Publicly available answers.
5. Social engineering can phish for answers easily.
6. Answers may be easily known or guessed by social proximity (family, friends, coworkers).
Transient information questions like "favorite food", unknown strictness rules like capitalization or character exclusions cause users to pick consistent answers that do not necessarily relate to the question.
This along with inconsistent passwords rules across all sites, and none of them showing the rules on the login page to remind you, piss me off to no end. Please can we start using public key cryptography, and just have our own private keys? Please!!!!
If you ever create password based web apps or work in security please at least watch this MIT lecture.
https://youtu.be/M2gc6b1hmk8?t=5m15s
(cued to start of lecture)
And lots of companies like to screw you in many different and inventive ways using this crap. For example Apple - they asked me for two security questions during registration (and I wrote it down of course), then at some point they added a third one with some random answer that I didn't fill. So now I have to open page with question a few times to get both of the questions that I did fill in and not one known and one not. (this happened to my oldest account, for two new appleIDs apple asked for all 3 questions correctly).
I'd hope they're storing it all as one-way digests, and it occurs to me that their strength metric (% number guessable given X attempts) might in fact be them brute-forcing their own data. Or they could log the inputs and result of each attempt by actual users during their experiment.
Or they could be secretly parsing and storing it all, and consequently know enough about you to guess most of your other services, should they NSL^Wneed to.
" For example, it was estimated that it actually takes over 2^100 guesses to compromise an average password due to the presence of less than one in a million users choosing 128-bit random strings as passwords"
I'll be the one looking smug until I misplace my personal password database.
Example secret answer: Kochoyan::Arev/Petrosyan--lusine_markosyan
Of course it doesn't have to be all human names, and formatting also adds a thin layer of security.
Example secret question: What is the random string I just generated?
Example secret answer: JmoPZGDg3JxpgRTTrHrXD5t5jVfvSm
Probably the worst example of these security questions is Tradeking. Normally, I just answer the security question with a random password stored in 1Password. Unfortunately, Tradeking has the genius practice of displaying your answers as a multiple choice—when 84209t920tq3g is offered as an option for a hometown, it's pretty obvious. Needless to say, this caused me to close my account immediately.