Hacker News new | ask | show | jobs
by always_good 3092 days ago
Which makes it less secure. Customer support rep may find it reasonable to dismiss it as random characters and let the attacker bypass the check entirely.

If the attacker knows it looks like gibberish, they can try "Heh, whoops, I just put in random characters at the time. Can we try something else?"

I think a false, convincing, and unlikely answer is reasonable. "My childhood dog's name was Alexander Hamilton."

1 comments

Yeah, picking something reasonable but extremely unlikely and false, then entering it into the pw manager, seems ideal.