Hacker News new | ask | show | jobs
by mikestew 3477 days ago
No, I pull up the answer out of 1Password and read it off to them.
3 comments

I thought Klathmon was pointing out say that they an attacker could say that they just mashed on the keyboard and that would be good enough for the fallible human on the other end of the phone.

Anecdotally, I had a time where I couldn't remember may answer to a secret question except that it was a type of food. I called in and the human on the other end let me reset my password with just that explanation. Take that for what you will, but it seems like if someone knows you use passwords that are random strings, they can use that to break in.

Sorry, I meant to imply that the support person will hear the explanation and let you reset the password without the actual answer.
Fair enough, as I believe I've had that happen. Random string for one of my financial institutions, needed to reset something. Pull up 1PWD, with random string at the ready and...they asked me questions that could have been pulled from a copy of my credit report. I didn't ask, so I'm not entirely sure, but I wonder if they didn't look at the answer, said to themselves "fuck that" and went with Option #2.
Diceware is a decent option for security questions. They work fine over the phone.
"Charlie capital-echo lima peru capital-october..."