Thursday, November 14, 2019

Toward A More Secure Account

You may have heard of this trick before, but many may have not - or maybe it was heard but didn't quite sink in.

When an account you're setting up demands answers to security questions such as "What was the name of your paternal grandfather?", you often don't need to provide answers that make sense. Very often (and I've never seen a contrary example) these questions accept nonsensical answers or even gibberish.

Consider such answers as...

Favorite flavor of ice cream? Pistachio
Favorite flavor of ice cream? pistachio
Favorite flavor of ice cream? Lyndon B. Johnson
Favorite flavor of ice cream? Johnson B. Lyndon
Favorite flavor of ice cream?
4#$53@6#$%23$35andapartridgeinapeartree

In my experience, any of these answers would be accepted by the script that generated the questions. Try it out to see what will be accepted. The worst that could happen would be to get an error message that would specify the local rules set up by some administrator. But I suspect that what you come up with just goes into a text field that accepts most anything.