TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Let’s Kill Security Questions

4 点作者 bozho超过 4 年前

2 条评论

SAI_Peregrinus超过 4 年前
Security questions can be used to reset your password. They are backup passwords. They should be treated as such: randomly generated and stored in a password manager. Different for each account. Any decent password manager will have a &quot;notes&quot; field or other way to store such data encrypted in the vault. Since they&#x27;re almost certainly stored in plaintext on the backend, they should have at least 128 bits of entropy. 20 random printable US keyboard characters, 10 diceware words, etc.<p>Question: What colour was your first car?<p>Answer: SterilityExcitableFifthAbideEnrageGaffeHazilyRecoupSacrificeIllusive<p>Question: What was the first street you lived on?<p>Answer: G]6a)ERXnVd}`&lt;(p&#x27;tY}<p>Etc.
rzzzwilson超过 4 年前
&gt; Almost any security question’s answer is guessable by doing research on the target person online.<p>That&#x27;s why you never answer the question but use some &quot;non sequitur&quot; answer:<p>Question: what colour was your first car?<p>Answer: rumpelstiltskin
评论 #25157752 未加载
评论 #25158951 未加载