Do authentication questions protect you?
What is your mother's maiden name? It seems like that question has been used as secondary authentication to verify identity since the dawn of time.
David Jeffers | Thursday, September 06 2012 | 1 CommentWhat is your mother's maiden name? It seems like that question has been used as secondary authentication to verify identity since the dawn of time. Over time, authentication questions have become much more diverse. Sites now ask for things like what city you went to high school in, or who was your favorite teacher, or what was your first car.
The problem with most authentication questions, though, is that the information can often be found with a simple Google search or two. Ten years ago, or even five years ago, it might have been much harder to learn the answers to such obscure questions. But, in the current age of sharing - and oversharing - on social networks it's entirely possible all your intimate details are out there somewhere.
Have you ever participated in an internet meme that gets you to answer a series of questions about yourself and then pass the results on to a group of friends? Many have. The purpose of the exercise is to share information and get to know people better, but the fallout is that those questionnaires often target the same sort of semi-obscure information that authentication questions ask for.
The real problem with authentication questions is that they can be guessed or breached the same way a password can. An attacker may not know who your favorite sports team is. But, given a few contextual clues from your social networking profiles, conducting a search of your tweets on Twitter, or simply trying different sports teams out until the right one is discovered, the attacker can probably get past the authentication questions.
Like a username, the authentication question might seem like it adds a layer of security -- and to some extent that's true. But, usernames are easily guessed, and authentication questions are becoming increasingly trivial to bypass thanks to social networking. The password should be the toughest part of this equation, yet many people still use their cat's name or "123456" despite years of security experts drilling about choosing better passwords.
One solution that might help a little is to make up a fictitious answer. For example, maybe you went to high school Omaha, and everyone online knows you went to high school in Omaha. But, for the purposes of your authentication security question you could change the answer to "Metropolis" or "onion rings" and just keep that information to yourself.
Some sites and services let you create your own custom authentication questions. This can also be an opportunity to create something unique that nobody but you would know the answer to. The sillier you are with both the question and the answer, the less likely it is that an attacker could guess it.
To protect your data from viruses, phishing attacks, and other malware -- whether its on your PC, smartphone, or tablet -- you should have some sort of cross-device security tool in place. But, when it comes to preventing unauthorised access to information stored elsewhere, two-factor authentication provides better protection.
An attacker may be able to guess your username, Google the answers to your authentication questions, and crack your password. But, if access to your data also requires a unique PIN that can only be sent to the mobile phone you have registered with the account for that purpose it makes it much harder to get in.
Windows vs. iOS vs. Android:How to choose the best tablet for you
101 great websites:
You haven't heard of yet
DIY desktops:
We ask the pros for building tips
Hot Products || PC World editors iPhone 4S launch pics and unboxing
The iPhone 4S launched at midnight through both Vodafone and Telecom. ... READ MORE
Tux Love || Geoff Palmer Google : Starting to be evil?
Google recently deleted AdBlock Plus from its Android Play Store. This is ... READ MORE
Tech Guy || Juha Saarinen Small balls of solder
The idea that desktops might change forever is enough to send geeks into a ... READ MORE
In a Nutshell || Zara Baxter Logging, not login
At an event in Singapore yesterday, Seamus Byrne, the editor of CNet ... READ MORE
Harley O'Gyver || Harley Ogier Pay for internet by-device? Not on my watch.
So as those of you who follow my twitterstream will know, I'm currently in ... READ MORE
The Arcade || PC World editors New Year, new games
You'er going to laugh. Or at the very least, you're going to scoff and ... READ MORE
Dumb Terminal Live! || PC World editors New Zealand memes: We think we're real funny
We New Zealanders love the internet, and we have a pretty good sense of ... READ MORE





Posted by Michael at 2:22:36 on September 19, 2012
Flag abuse