<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Password Recovery Questions Make Online Accounts Vulnerable</title>
	<atom:link href="http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 04:56:36 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: La opción de recuperar el password por preguntas secretas hace las cuentas más vulnerables</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-860545</link>
		<dc:creator>La opción de recuperar el password por preguntas secretas hace las cuentas más vulnerables</dc:creator>
		<pubDate>Sat, 01 Aug 2009 22:05:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-860545</guid>
		<description>[...] Vía: Ghacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Vía: Ghacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roman ShaRP</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-844838</link>
		<dc:creator>Roman ShaRP</dc:creator>
		<pubDate>Sat, 04 Jul 2009 19:26:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-844838</guid>
		<description>I always choose custom questions and put in them things that nobody else can know.</description>
		<content:encoded><![CDATA[<p>I always choose custom questions and put in them things that nobody else can know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tobey</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-844701</link>
		<dc:creator>Tobey</dc:creator>
		<pubDate>Sat, 04 Jul 2009 09:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-844701</guid>
		<description>True indeed. This leads me to an idea to use the same string for the answer as for password itself and of course, for the worst case, have the password backed up in KeePass/alternative. Will start implementing that as of now since forced question-answer measures are a serious vulnerability, all the more if you&#039;re not offered a more &quot;safe&quot; question. IMHO asking for mother&#039;s maiden name is one of the stupidest options, literally anyone can find out, possibly even using the Net/social networks.

Thanks for the tips</description>
		<content:encoded><![CDATA[<p>True indeed. This leads me to an idea to use the same string for the answer as for password itself and of course, for the worst case, have the password backed up in KeePass/alternative. Will start implementing that as of now since forced question-answer measures are a serious vulnerability, all the more if you&#8217;re not offered a more &#8220;safe&#8221; question. IMHO asking for mother&#8217;s maiden name is one of the stupidest options, literally anyone can find out, possibly even using the Net/social networks.</p>
<p>Thanks for the tips</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-843314</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Thu, 02 Jul 2009 12:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-843314</guid>
		<description>If you have a password manager that you are storing answers to recovery questions in, wouldn&#039;t you already have the forgotten password in the manager as well?

Regardless, one of my greatest pet peeves about password recovery questions is the use of subjective questions.  &quot;What&#039;s your favorite movie&quot; will probably be different 3 years from now when I forget my password and need to recover it.  They should be more concrete like &quot;What city was your father born in?&quot;  That will never change.

So anyway, I *love* the idea of putting an answer completely unrelated to the question.  That&#039;s brilliant.  Thanks for the suggestion.</description>
		<content:encoded><![CDATA[<p>If you have a password manager that you are storing answers to recovery questions in, wouldn&#8217;t you already have the forgotten password in the manager as well?</p>
<p>Regardless, one of my greatest pet peeves about password recovery questions is the use of subjective questions.  &#8220;What&#8217;s your favorite movie&#8221; will probably be different 3 years from now when I forget my password and need to recover it.  They should be more concrete like &#8220;What city was your father born in?&#8221;  That will never change.</p>
<p>So anyway, I *love* the idea of putting an answer completely unrelated to the question.  That&#8217;s brilliant.  Thanks for the suggestion.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-843200</link>
		<dc:creator>Greg</dc:creator>
		<pubDate>Thu, 02 Jul 2009 10:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-843200</guid>
		<description>Yeah, to be honest a lot of the questions are things like

&quot;what&#039;s your mother&#039;s maiden name?&quot;
&quot;what&#039;s your first pet&#039;s name?&quot;
&quot;in what town was your high school?&quot;

This is all stuff that people close to me would know, particularly family members and as you can pick your friends, not your family.... I would trust my family the least out of anyone!</description>
		<content:encoded><![CDATA[<p>Yeah, to be honest a lot of the questions are things like</p>
<p>&#8220;what&#8217;s your mother&#8217;s maiden name?&#8221;<br />
&#8220;what&#8217;s your first pet&#8217;s name?&#8221;<br />
&#8220;in what town was your high school?&#8221;</p>
<p>This is all stuff that people close to me would know, particularly family members and as you can pick your friends, not your family&#8230;. I would trust my family the least out of anyone!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Transcontinental</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-843135</link>
		<dc:creator>Transcontinental</dc:creator>
		<pubDate>Thu, 02 Jul 2009 09:00:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-843135</guid>
		<description>The last password recovery question I encountered was the name of my pet : I admit I never had a pet named: $WSo,)EEI4KMy_#YUS\wUba-Bd9+a62(
Poor cat!</description>
		<content:encoded><![CDATA[<p>The last password recovery question I encountered was the name of my pet : I admit I never had a pet named: $WSo,)EEI4KMy_#YUS\wUba-Bd9+a62(<br />
Poor cat!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xdmv</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-842925</link>
		<dc:creator>xdmv</dc:creator>
		<pubDate>Thu, 02 Jul 2009 04:16:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-842925</guid>
		<description>A useful tip is think that you are ANOTHER person. Then the answer would be honest, but not for YOU... ;-)</description>
		<content:encoded><![CDATA[<p>A useful tip is think that you are ANOTHER person. Then the answer would be honest, but not for YOU&#8230; ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DanTe</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-842845</link>
		<dc:creator>DanTe</dc:creator>
		<pubDate>Thu, 02 Jul 2009 02:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-842845</guid>
		<description>The answer to all my password recovery question is: sakljg;aghjk&#039;sl;ksfhgait
q4\=q3i5

I keep all my passwords in one master encrypted spreadsheet stored on a detached Ironkey USB drive.</description>
		<content:encoded><![CDATA[<p>The answer to all my password recovery question is: sakljg;aghjk&#8217;sl;ksfhgait<br />
q4\=q3i5</p>
<p>I keep all my passwords in one master encrypted spreadsheet stored on a detached Ironkey USB drive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-842722</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 02 Jul 2009 01:00:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-842722</guid>
		<description>About time someone saw sense on this matter.  Banks are even worse than websites.  These days I lose my temper when they ask for my mother&#039;s maiden name as a security marker - half the financial institutions on this planet (and their staff) must have that info by now - as a security device it gets 1/10.

But - as a more sensible bank employee assured me - the answer doesn&#039;t of course need to be literally correct.  You can say your mother&#039;s name was Chewbacca just as long as you remember that.

But that still doesn&#039;t, of course, address the issue that a large proportion of the security problem originates from WITHIN banks and financial institutions where - I am MOST reliably informed - the standards of internal security are often laughable.</description>
		<content:encoded><![CDATA[<p>About time someone saw sense on this matter.  Banks are even worse than websites.  These days I lose my temper when they ask for my mother&#8217;s maiden name as a security marker &#8211; half the financial institutions on this planet (and their staff) must have that info by now &#8211; as a security device it gets 1/10.</p>
<p>But &#8211; as a more sensible bank employee assured me &#8211; the answer doesn&#8217;t of course need to be literally correct.  You can say your mother&#8217;s name was Chewbacca just as long as you remember that.</p>
<p>But that still doesn&#8217;t, of course, address the issue that a large proportion of the security problem originates from WITHIN banks and financial institutions where &#8211; I am MOST reliably informed &#8211; the standards of internal security are often laughable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cmpm</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comment-842554</link>
		<dc:creator>cmpm</dc:creator>
		<pubDate>Wed, 01 Jul 2009 21:39:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=14058#comment-842554</guid>
		<description>I have an answer that has nothing to do with the security question.
It&#039;s not likely any one could figure out the answer to any question,
when the answer is totally unrelated to the question or any question.
But I also try not to confuse myself as well, :)</description>
		<content:encoded><![CDATA[<p>I have an answer that has nothing to do with the security question.<br />
It&#8217;s not likely any one could figure out the answer to any question,<br />
when the answer is totally unrelated to the question or any question.<br />
But I also try not to confuse myself as well, :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
