<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; password recovery questions</title>
	<atom:link href="http://www.ghacks.net/tag/password-recovery-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 03:24:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Password Recovery Questions Make Online Accounts Vulnerable</title>
		<link>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/</link>
		<comments>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 20:19:54 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[accounts]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[online security]]></category>
		<category><![CDATA[password recovery]]></category>
		<category><![CDATA[password recovery questions]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[secret questions]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14058</guid>
		<description><![CDATA[Password recovery questions are great to recover a forgotten password in a matter of seconds. All that needs to be done is to answer the password recovery question to receive a new password in the email inbox. This does however make email hacking a profitable business as email accounts are usually connected to online stores [...]]]></description>
			<content:encoded><![CDATA[<p>Password recovery questions are great to recover a forgotten password in a matter of seconds. All that needs to be done is to answer the password recovery question to receive a new password in the email inbox. This does however make email hacking a profitable business as email accounts are usually connected to online stores and other web services. Attackers with access to a compromised email account only need to answer the secret question to retrieve the password of the web account. This matter is definitely more secure than sending out the password without confirmation on the user&#8217;s request. </p>
<p>A recent <a href="http://www.newscientist.com/article/dn17347-secret-questions-leave-accounts-vulnerable.html">study</a> shows on the other hand that password recovery questions are usually answered honestly. Questions about the birth town, mother&#8217;s maiden name or first animal name can sometimes be easily guesses. The study asked acquaintances of 32 webmail users to guess the answer to the secret question. Roughly 20% of these answers were guessed correctly.</p>
<p><span id="more-14058"></span>Password recovery questions should therefor not be answered honestly. Experienced users fill them out with password like characters which makes the answers more or less impossible to guess. These answers can then be stored in password managers as notes.</p>
<p>How do you handle password recovery questions?</p>

	Tags: <a href="http://www.ghacks.net/tag/accounts/" title="accounts" rel="tag">accounts</a>, <a href="http://www.ghacks.net/tag/email/" title="Email" rel="tag">Email</a>, <a href="http://www.ghacks.net/tag/online-security/" title="online security" rel="tag">online security</a>, <a href="http://www.ghacks.net/tag/password-recovery/" title="password recovery" rel="tag">password recovery</a>, <a href="http://www.ghacks.net/tag/password-recovery-questions/" title="password recovery questions" rel="tag">password recovery questions</a>, <a href="http://www.ghacks.net/tag/passwords/" title="passwords" rel="tag">passwords</a>, <a href="http://www.ghacks.net/tag/secret-questions/" title="secret questions" rel="tag">secret questions</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/04/04/password-recovery-speeds/" title="Password Recovery Speeds (April 4, 2006)">Password Recovery Speeds</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/08/outlook-express-password-recovery/" title="Outlook Express Password Recovery (August 8, 2008)">Outlook Express Password Recovery</a> (0)</li>
	<li><a href="http://www.ghacks.net/2006/05/27/ultra-high-security-password-generator/" title="Ultra High Security Password Generator (May 27, 2006)">Ultra High Security Password Generator</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/03/11/truemark-email-identification/" title="Truemark Email Identification (March 11, 2009)">Truemark Email Identification</a> (5)</li>
	<li><a href="http://www.ghacks.net/2007/04/26/temporary-email-from-bugmenot/" title="Temporary Email from BugMeNot (April 26, 2007)">Temporary Email from BugMeNot</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/01/password-recovery-questions-make-online-accounts-vulnerable/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
