<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

      <title>Comments on: Algorithms for dumb security questions</title>
      <link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions/</link>
      <description>Comments on MetaFilter post Algorithms for dumb security questions</description>
	  	  <pubDate>Sun, 18 Nov 2007 11:15:41 -0800</pubDate>
      <lastBuildDate>Sun, 18 Nov 2007 11:15:41 -0800</lastBuildDate>
      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>

<item>
  	<title>Algorithms for dumb security questions</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions</link>	
    <description> </description>
  	<guid isPermaLink="false">post:www.metafilter.com,2008:site.66660</guid>
  	<pubDate>Sun, 18 Nov 2007 11:09:58 -0800</pubDate>
  	<dc:creator>nthdegx</dc:creator>
	
	<category>security</category>
	
	<category>web</category>
	
	<category>howto</category>
	
	<category>trick</category>
	
	<category>memory</category>
	
	<category>mnemonics</category>
	
	<category>lifehack</category>
	
	<category>psychology</category>
	
</item>
<item>
  	<title>By: Brockles</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916354</link>	
    <description>From the comments:

&lt;i&gt;

If anyone wants to hack into my accounts, my Mother&apos;s Maiden Name, my first pet, my favourite teacher and my place of birth are usually &quot;ohfuckoff&quot;.

Which was embarrassing the time I had to phone my credit union...

Posted by Rod Begbie [TypeKey Profile Page] | November 15, 2007 12:56 PM

&lt;/i&gt;

Awesome. That&apos;d be worth doing for the amusing reaction on the other end of the phone for me... :)</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916354</guid>
  	<pubDate>Sun, 18 Nov 2007 11:15:41 -0800</pubDate>
  	<dc:creator>Brockles</dc:creator>
</item>
<item>
  	<title>By: ZachsMind</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916365</link>	
    <description>After reading through the link, it&apos;s occurred to me that there is no solution to this. No matter how one tries to solve the whole combating identity theft thing, there will be somebody, somewhere, responding negatively in a snarky way that engenders nervous giggles and the occasional guffaw from likeminded individuals. 

I find comfort in that.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916365</guid>
  	<pubDate>Sun, 18 Nov 2007 11:27:30 -0800</pubDate>
  	<dc:creator>ZachsMind</dc:creator>
</item>
<item>
  	<title>By: shadow vector</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916368</link>	
    <description>I really hate these.  My old bank switched over to a system like this a couple of months before I moved away.  Favorite sports team?  You&apos;re a fucking local credit union, there&apos;s only 4 options, plus a couple of colleges, that&apos;ll cover 90% of your clients.  Good thinking there.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916368</guid>
  	<pubDate>Sun, 18 Nov 2007 11:29:51 -0800</pubDate>
  	<dc:creator>shadow vector</dc:creator>
</item>
<item>
  	<title>By: Foci for Analysis</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916385</link>	
    <description>It pisses me of when people don&apos;t believe that my mother&apos;s maiden name actually is sfdjlfkjshlgfslkjdflhjgljk. Bastards.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916385</guid>
  	<pubDate>Sun, 18 Nov 2007 11:40:01 -0800</pubDate>
  	<dc:creator>Foci for Analysis</dc:creator>
</item>
<item>
  	<title>By: you</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916393</link>	
    <description>Wouldn&apos;t this guy&apos;s method have the same problem as using the same password for every site? (i.e., the admin of any site will be able to guess the answer for every other site)

Hm.. I guess you could combine it with a &lt;a href=&quot;http://www.google.com/search?q=passwordlet&quot;&gt;passwordlet&lt;/a&gt;...</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916393</guid>
  	<pubDate>Sun, 18 Nov 2007 11:47:26 -0800</pubDate>
  	<dc:creator>you</dc:creator>
</item>
<item>
  	<title>By: ZachsMind</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916406</link>	
    <description>If I ever got the question, &quot;what&apos;s your favorite sports team&quot; I wouldn&apos;t have an answer. I couldn&apos;t make up an answer that I would remember later. Honestly. For me that&apos;s like the worst possible security question they could ever ask.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916406</guid>
  	<pubDate>Sun, 18 Nov 2007 11:58:26 -0800</pubDate>
  	<dc:creator>ZachsMind</dc:creator>
</item>
<item>
  	<title>By: chrismear</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916437</link>	
    <description>&lt;i&gt;Wouldn&apos;t this guy&apos;s method have the same problem as using the same password for every site? (i.e., the admin of any site will be able to guess the answer for every other site)&lt;/i&gt;

Not if they&apos;re encrypting the password so that it&apos;s not readable by the admins.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916437</guid>
  	<pubDate>Sun, 18 Nov 2007 12:17:15 -0800</pubDate>
  	<dc:creator>chrismear</dc:creator>
</item>
<item>
  	<title>By: chrismear</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916438</link>	
    <description>Which, admittedly, there is an outside chance they&apos;re not doing.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916438</guid>
  	<pubDate>Sun, 18 Nov 2007 12:18:17 -0800</pubDate>
  	<dc:creator>chrismear</dc:creator>
</item>
<item>
  	<title>By: Gungho</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916455</link>	
    <description>It really is all about protecting stupid people from themselves. Where I work, (and I&apos;m sure where you work) any password can be found by looking for the post-it note. In addition most people tend to use the HR (payroll) site as their home page, so we had to add a 2nd password in order to see any personal info on the site.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916455</guid>
  	<pubDate>Sun, 18 Nov 2007 12:27:56 -0800</pubDate>
  	<dc:creator>Gungho</dc:creator>
</item>
<item>
  	<title>By: limon</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916635</link>	
    <description>StupidQuestion SnarkyComment Booyah</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916635</guid>
  	<pubDate>Sun, 18 Nov 2007 14:00:54 -0800</pubDate>
  	<dc:creator>limon</dc:creator>
</item>
<item>
  	<title>By: sfenders</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916651</link>	
    <description>I was kind of hoping this would tell me what happens if you answer &quot;no&quot; to &quot;did you pack this bag yourself?&quot;</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916651</guid>
  	<pubDate>Sun, 18 Nov 2007 14:11:05 -0800</pubDate>
  	<dc:creator>sfenders</dc:creator>
</item>
<item>
  	<title>By: nicwolff</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916653</link>	
    <description>That &quot;passwordlet&quot; link in you&apos;s comment is a link to a Google search that just points at my &lt;a href=&quot;http://angel.net/~nic/passwdlet.sha1.1a.html&quot;&gt;Passwdlet&lt;/a&gt;. Which wouldn&apos;t really solve this problem since it inserts the generated password only in password fields and fields named &quot;password&quot;. But you could use my &lt;a href=&quot;http://angel.net/~nic/passwd.sha1.1a.html&quot;&gt;Password generator&lt;/a&gt; form to encrypt your answer.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916653</guid>
  	<pubDate>Sun, 18 Nov 2007 14:11:23 -0800</pubDate>
  	<dc:creator>nicwolff</dc:creator>
</item>
<item>
  	<title>By: lemuel</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916923</link>	
    <description>you are supposed to write your password on the underside of the keyboard, not on post-its.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916923</guid>
  	<pubDate>Sun, 18 Nov 2007 16:56:11 -0800</pubDate>
  	<dc:creator>lemuel</dc:creator>
</item>
<item>
  	<title>By: russm</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1916978</link>	
    <description>&lt;a href=&quot;#1916651&quot;&gt;sfenders&lt;/a&gt; - in my experience, it leads to a small room, a *very* thorough search of the bag, your other bags, and your person, and a stern warning to Not Do That Again...

of course, this did happen to be the time I was carrying a pack full of of little summer dresses and similar chick clothes for the friend I was meeting overseas at the time... &quot;seriously, that&apos;s not my dress... I *told* you I didn&apos;t pack this bag myself&quot;...</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1916978</guid>
  	<pubDate>Sun, 18 Nov 2007 17:49:51 -0800</pubDate>
  	<dc:creator>russm</dc:creator>
</item>
<item>
  	<title>By: sdodd</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1917158</link>	
    <description>Computer security is often counter-intuitive. Noted security expert Bruce Schneier (author of the software cryptography bible, Applied Cryptography) recommends you &lt;a href=&quot;http://www.schneier.com/blog/archives/2005/06/write_down_your.html&quot;&gt;write down your password&lt;/a&gt;. Why? Remembering many complex passwords is difficult, but &quot;we&apos;re all good at securing small pieces of paper&quot; on our person: we carry cash.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1917158</guid>
  	<pubDate>Sun, 18 Nov 2007 19:35:36 -0800</pubDate>
  	<dc:creator>sdodd</dc:creator>
</item>
<item>
  	<title>By: vacapinta</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1917330</link>	
    <description>I always thought &quot;mother&apos;s maiden name&quot; was culturally insensitive. As someone with a &lt;a href=&quot;http://en.wikipedia.org/wiki/Spanish_naming_customs&quot;&gt;Latin American surname&lt;/a&gt; my mother&apos;s maiden name is part of my last name - it is there on every piece of ID I have. It is my name.

In other words, if Gabriel Garcia Marquez were asked this question, he would answer &quot;Garcia.&quot; Great security there....</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1917330</guid>
  	<pubDate>Sun, 18 Nov 2007 22:01:01 -0800</pubDate>
  	<dc:creator>vacapinta</dc:creator>
</item>
<item>
  	<title>By: vacapinta</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1917334</link>	
    <description>(..oops, meant he would write &quot;Marquez&quot;..)</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1917334</guid>
  	<pubDate>Sun, 18 Nov 2007 22:02:25 -0800</pubDate>
  	<dc:creator>vacapinta</dc:creator>
</item>
<item>
  	<title>By: Eideteker</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1917534</link>	
    <description>When they ask for your Mother&apos;s Maiden Name, that&apos;s just a password. You don&apos;t need to use the actual name. Me, I like the idea of always using &quot;ZANGIEF&quot;.

Yes, that Zangief.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1917534</guid>
  	<pubDate>Mon, 19 Nov 2007 05:47:22 -0800</pubDate>
  	<dc:creator>Eideteker</dc:creator>
</item>
<item>
  	<title>By: delmoi</title>
  	<link>http://www.metafilter.com/66660/Algorithms-for-dumb-security-questions#1917861</link>	
    <description>Yeah, but of course the problem is if you just make something up, you&apos;ll probably forget it because &lt;i&gt;unlike&lt;/i&gt; a password you don&apos;t use it all the time and you forget it. 

Whatever happened to just letting people pose their own security questions? And then there is the issue of people picking obvious things. 

When I was in highschool one of my fellow students email address was &quot;JesusIsRad@hotmail.com&quot; (slightly changed in case he&apos;s still using it).  His password?  That&apos;s right, &lt;i&gt;Jesus&lt;/i&gt;.</description>
  	<guid isPermaLink="false">comment:www.metafilter.com,2008:site.66660-1917861</guid>
  	<pubDate>Mon, 19 Nov 2007 11:40:07 -0800</pubDate>
  	<dc:creator>delmoi</dc:creator>
</item>

    </channel>
</rss>
