Hacker News new | ask | show | jobs
by LilBytes 1429 days ago
My secret questions have nonsensical answers but are all unique per app/website which are recorded.

Makes social engineering nearly impossible.

1 comments

Just don't put random characters as the answer.
True. That makes it very hard when you have to recite it back to a customer service person. Best just to use arbitrary, real words and then store the questions and answers in your password manager.
Once I was on the phone with Blizzard support, and they asked me to verify the answer to one of my security questions. I said “oh, it’s probably just a bunch of random letters” and she said “uh, yeah, it is actually” and let me into my account. So be aware of that as an attack vector too
This is what I was hinting at but not as coherently
Yep, they're all similar to correct horse battery staple or "toilets excite pregnant cabbages".