{"id":378,"date":"2007-09-22T21:33:52","date_gmt":"2007-09-23T04:33:52","guid":{"rendered":"http:\/\/www.elbeno.com\/blog\/?p=378"},"modified":"2007-09-22T21:38:37","modified_gmt":"2007-09-23T04:38:37","slug":"secret-questions-and-two-factor-authentication","status":"publish","type":"post","link":"https:\/\/www.elbeno.com\/blog\/?p=378","title":{"rendered":"Secret questions and two factor authentication"},"content":{"rendered":"<p>You&#8217;ve seen them. They&#8217;re cropping up all over the place now, and not just for online banking. I&#8217;m talking about those so-called &#8220;secret questions&#8221; that are supposed to authenticate you if you ever forget your password. They are (sort of) based on the principle of two factor authentication. Except they actually make the system <em>less<\/em> secure, not more.<\/p>\n<p>The idea behind two factor authentication is just what it says: authenticating someone based on two factors rather than just one (a password). One key issue is that they be two <em>different kinds<\/em> of thing, e.g.<\/p>\n<ul>\n<li>something you <em>know<\/em> (a password or PIN)<\/li>\n<li>something you <em>have<\/em> (a credit card or RSA fob)<\/li>\n<li>something you <em>are<\/em> (a fingerprint or retinal scan)<\/li>\n<\/ul>\n<p>Part of the security lies in the fact that it is not easy to replicate something you have or are, unlike something you know. A password file can be duplicated and attacked offline. Ever-changing RSA keys cannot. Don&#8217;t get me started on how every online merchant is requiring the 3-digit credit card &#8220;security code&#8221; for online transactions these days, which will end up negating its whole purpose if they ever start storing it.<\/p>\n<p>Anyway, secret questions. Stop and think about it for a minute. If you use a strong password, even the esoteric &#8220;secret question&#8221; answers are a lot <em>less<\/em> secure than your password. Do you really want someone to be able to call up your bank and say &#8220;Oh, hello, this is&#8230; Yeah, I forgot my password. My mother&#8217;s maiden name is&#8230;&#8221; ? Whether it be your mother&#8217;s maiden name, the name of your first pet, the town where you went to high school, or something else, it is certainly a lot easier for someone to find out (or guess) than a well-chosen password.<\/p>\n<p>Whenever a website asks me for a &#8220;secret question&#8221; answer, I mash my hands on the keyboard at random until I have 10-12 characters of nonsense, and enter that. Neither I nor anyone else will reasonably be able to recover my answer. So if I ever forget my password(s), I may have a harder time authenticating myself to the person on the other end of the phone, but at least my account will be secure.<\/p>\n<p>Recently, I was almost caught out by this &#8211; not that I would change my behaviour and give up security if I were &#8211; but I was surprised to actually be asked this secret question as part of the login procedure for one of my credit cards! Of course, I couldn&#8217;t answer it. But I was able to give them the 3-digit card security code as an alternative. This was as well as the password, not instead of, so my security was intact in that case.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You&#8217;ve seen them. They&#8217;re cropping up all over the place now, and not just for online banking. I&#8217;m talking about those so-called &#8220;secret questions&#8221; that are supposed to authenticate you if you ever forget your password. They are (sort of) based on the principle of two factor authentication. Except they&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-378","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=378"}],"version-history":[{"count":0,"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/378\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elbeno.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}