Security Questions Are a Bad Idea, and Here’s Why

Ever since we had passwords and accounts there have always been hackers trying to get their hands on them. More importantly, people have also been forgetting their passwords. To recover them, the account provider often implements a series of questions that you provide your “secret answers” to. This system has worked fine for many years, but it is riddled with ways to make hackers’ jobs easier. Although the answers are secret, ,,,kk per se, it appears that you’re actually sacrificing your security in the hopes that one day this sacrifice will help you recover your password.

What Makes Security Questions Horrible At Security

securityquestions-forgotpassword

On May 21, 2015, Google published some research regarding the whole security questions scheme. Apparently, “what was your first pet’s name?” can be the single weakest link in your security, and it can bring your account to hackers on a silver platter. While you can make passwords that are impossible to guess, security questions for recovery are designed in such a way that you should be able to answer them easily. This works well when you use obscure answers that no one else can guess, but horribly if your pet (for example) has a very common name like “Max” or “Spot.” If you named your dog “Ulysses” or “Peruggia,” then you might stand a chance, albeit one that isn’t so promising.

You can also choose option B, which is to lie about the answer to your question (i.e. replying “Offram Klingmanstein III” when asked what your mother’s maiden name was). The problem with this is that you end up with yet another thing you must remember. Recalling answers you lied about is just as difficult as recalling the password you forgot in the first place. This is no solution but an added burden.

What Should Replace These Questions?

securityquestions-selection

In addition to the security problems that questions introduce, they just add to the confusion for those who cannot recall the city they were born in or the names of their first pet (it does happen). People who know you well can also easily access your accounts with this method. Hopefully, we’ve come to the conclusion by now that something needs to replace the “secret answer” method. Fortunately, there are many good contenders for replacements, one of the best being two-factor authentication.

The “secret answer” method was invented before people commonly had cell phones that could open SMS messages. At this point in history, virtually everyone with access to the Internet has a cell phone. Out of 7 billion people, there are roughly 6.8 billion phones. Google has adopted a new method for authentication that involves sending a one-time password through SMS for recovery. For those without phones, they could use a backup email either of a trusted person or one that they use themselves for recovery. This method makes it very difficult to “guess” one’s way into an account without the user’s phone.

By using two-factor authentication, you solve two things at the same time:

  • You minimize the risk of a person not remembering their “answer” since the unique SMS code is handed to the user upon request, and
  • You make a recovery method that is nearly unbreakable since the hacker would need to have access to a physical object that the user owns.

Can you think of something else to replace the secret answer method? Leave your thoughts in a comment below!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe