Hacker News new | ask | show | jobs
by BinaryIdiot 3340 days ago
This is sorta what I do except I use a unique answer for each one and I store the question and answer in my password manager.

Sometimes I use a straight up password generator for the answers. Hope I never have to give those out over the phone.

4 comments

> Sometimes I use a straight up password generator for the answers. Hope I never have to give those out over the phone.

I filled the security answer for my Blizzard account with random ascii garbage, which I didn't record, confident that I would always know my password.

That was true. But Blizzard disabled my account for purchasing time codes with a credit card other than the one that my account designated "preferred payment". (The card I was paying with was also listed under my account, but it wasn't "preferred". I have no idea what attack they think they're defending against.)

I had to call in. Phone-based customer service accepted "I don't think I can give you the answer to the security question" as a valid answer.

Security!

https://twitter.com/xargsnotbombs/status/858068758379868164

"PRO TIP: To hack the account of a network security engineer, call support and tell them your mother's maiden name is a bunch of hex digits."

I've had to do it a few times, because I do that same thing. They usually respond with exasperation and say something like, "No, sir we need your security answer not your password." Then it's my turn to be exasperated and say, "No, check again, that's the answer." Very fun.
Same here.