Hacker News new | ask | show | jobs
by bdc 4846 days ago
To paraphrase: the question 'What is your mother's maiden name?' is intrinsically insecure as a security measure; instead of answering it directly, make up some unguessable string that has nothing to do with the question.

Sound advice, but... but... but.....

This is his own website using this as a security question!

1 comments

It's about the target audience. Most normal people aren't going to be using their registered domain name for extremely high-value and highly targeted stuff, and they'll be upset if you say "Oh, you forgot your random string? Well, I guess you're screwed bub, sorry". But if you're doing something involving btc, you should be conscious enough to know "maybe I shouldn't put the security of my account behind easily locatable public info like the name of myself or family members".