Hacker News new | ask | show | jobs
by _2dsr 3092 days ago
Same. It's funny because occasionally when you call support they require you to answer one of those questions.

"That's correct, my childhood pet's name was 1xs3^&szx!@!24"

1 comments

Which makes it less secure. Customer support rep may find it reasonable to dismiss it as random characters and let the attacker bypass the check entirely.

If the attacker knows it looks like gibberish, they can try "Heh, whoops, I just put in random characters at the time. Can we try something else?"

I think a false, convincing, and unlikely answer is reasonable. "My childhood dog's name was Alexander Hamilton."

Yeah, picking something reasonable but extremely unlikely and false, then entering it into the pw manager, seems ideal.