Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Proof that security questions on websites are one of the most garbage "security" practices out there.


When forced to provide answers to dumb “security questions”, I will typically use a password manager to both generate a random “answer” and to store the question-answer pairs. I generate new strings for each site that asks the same dumb question.

For sites that demand to know my birthday when all they really need is a boolean declaration of adulthood I use 1 January 1901. (I’ll admit that when I first started this practice I used 1 April 1901).


I'm probably sure everyone knows my first pet's name by now.


My first dog t7xW6q+WX-i9$G4*&^sY was a beautiful creature. I remember her fondly.


only if you tell the truth


Most people do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: