TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Let’s Kill Security Questions

4 pointsby bozhoover 4 years ago

2 comments

SAI_Peregrinusover 4 years ago
Security questions can be used to reset your password. They are backup passwords. They should be treated as such: randomly generated and stored in a password manager. Different for each account. Any decent password manager will have a &quot;notes&quot; field or other way to store such data encrypted in the vault. Since they&#x27;re almost certainly stored in plaintext on the backend, they should have at least 128 bits of entropy. 20 random printable US keyboard characters, 10 diceware words, etc.<p>Question: What colour was your first car?<p>Answer: SterilityExcitableFifthAbideEnrageGaffeHazilyRecoupSacrificeIllusive<p>Question: What was the first street you lived on?<p>Answer: G]6a)ERXnVd}`&lt;(p&#x27;tY}<p>Etc.
rzzzwilsonover 4 years ago
&gt; Almost any security question’s answer is guessable by doing research on the target person online.<p>That&#x27;s why you never answer the question but use some &quot;non sequitur&quot; answer:<p>Question: what colour was your first car?<p>Answer: rumpelstiltskin
评论 #25157752 未加载
评论 #25158951 未加载