Study Shows "Secret Questions" Are Too Easily Guessed 303
wjousts writes "Several high-profile break-ins have resulted from hackers guessing the answers to secret questions (the hijacking of Sarah Palin's Yahoo account was one). This week, research from Microsoft and Carnegie Mellon University, presented at the IEEE Symposium on Security and Privacy, will show how woefully insecure secret questions actually are. As reported in Technology Review: 'In a study involving 130 people, the researchers found that 28 percent of the people who knew and were trusted by the study's participants could guess the correct answers to the participant's secret questions. Even people not trusted by the participant still had a 17 percent chance of guessing the correct answer to a secret question.'" Schneier pointed out years ago how weird it is to have a password-recovery mechanism that is less secure than the password.
My question is: (Score:2, Informative)
Who has more water that we expect to?
Re:Don't use them (Score:5, Informative)
Re:Don't use them (Score:2, Informative)
The name of my first pet, a hamster, was
Spotty'delete from secretquestions;--
Yesterday wants its news back (Score:3, Informative)
I dimly remember I saw something like this on /. before...
It's a no brainer. Or at least it should be. Most of those "secret" questions draw from a limited set of possible answers. Worse, ALL those answers will be found in a dictionary. Because they invariably ask for (*drumroll*) a real, usually English, word.
Now, what do we tell people, what did we tell them for ages? DO NOT use words that can be found in a dictionary. Yet for the "secret answer" (which is in almost all cases as good as the real password) we ask for a word that can be found in one.
Is it me or is this like, you know, STUPID?
There is no "secure" word. Not even your pet's name. My first pet was called ;drop table *;, btw. Yeah, I'm such a geek... sorry 'bout your database, btw.
Re:Its a flawed concept (Score:4, Informative)
Re:Don't use them (Score:5, Informative)
That's the Bible, Genesis 1:1.