Hacker News new | ask | show | jobs
by staticassertion 1755 days ago
Vanguard also has traditional security questions too. So shit like "where were you born?".
2 comments

I use KeePass, so I make it generate a long random string and just put that as the the answer. It has encrypted storage of additional name value pairs, so I can label each string with the appropriate question.
I suggest using diceware or similar random words, not random strings. Humans are typically processing these, not machines. "What's your mother's maiden name" can be answered by "Oh, I just put a bunch of random letters" if someone knows your stance on security questions.
KeepassXC at least includes passphrase generation using the EFF diceware list. I use that for "security" questions.
Yes! It should be much harder to convince a CSR who can see your plaintext answers that you're legit and don't know you were born in "Peoria" vs "eH2ochomheeVe6ti".
I admit I've only had to fall back to the "security questions" a few times, but I haven't had any issues with the random strings.
The point isn’t that you will have an issue using a random string, it’s that attackers who know you do so will be able to convince a customer service rep they are you by answering the question “I just put in some random keystrokes”
Well that would require fairly detailed knowledge about me, but point taken. Not sure how random words are much better though, if the person on the other side is ready to accept whatever.
Remember that your answer to that need not necessarily be accurate. You can invent a 'security city' perhaps and always give that... or just give a randomly generated password that you store alongside in your password locker.
And if you use a long pseudo-randomly generating string, you will amuse support (and annoy yourself) when you have to read it all out...

(Switched to correct-horse-battery-staple style for those after that.)

Support Operator: We need to answer some security questions. To start with, what was your mother's maiden name?

Scammer: "Oh, I just entered a long stream of random digits, but I can't find where I wrote it down"

Operator: "Good enough. How large a credit line did you say you wanted?"

What happened in my case (password reset for the online account for a credit card) was rather:

Operator: ...

(Real) me: Err.. all of it? [hoping p,q,r-th characters will be enough]

Operator: Yes please.

FWIW, having gone through support with Vanguard, they didn't even acknowledge that they were random strings when I said they would be. They seemed well trained, at least the one I spoke with.
I use a random string and store it in a password manager per-site.