this post was submitted on 23 Jun 2026
177 points (98.4% liked)

Technology

87279 readers
3023 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Zwuzelmaus@feddit.org 20 points 1 month ago* (last edited 1 month ago) (9 children)

By wrapping standard bank security questions, like your mother's maiden name, your first pet, or the street you grew up on

These questions have made me wonder ever since I first saw them. So I want to ask you all:

Do you take them for serious?

It seems a cultural difference maybe, but I could never remember what I have answered to one of them. I don't even know the true answers to most of them, and if I know it, then I would still not want my bank to know it.

The only way where this kind "security" makes sense to me is when I can freely type in both the question and the answer. Then I choose a question that does not make sense to most other people, only to me personally, and then I won't ever forget the answer.

[–] skaffi@infosec.pub 9 points 1 month ago (7 children)

As long as you can choose the answer, you can also choose what the question really is. You can just decide that questions about your mum's maiden name are actually asking you about the last name of the doctor that delivered your first born.

Or, better yet don't tie security to personal or externally verifiable information about yourself. In the one or two cases, in recent years, where I've had to fill out such (in)security questions, I've just treated them as additional password fields, where I just create additional fields for them in my password manager, and generate long, random responses as their correct answers. Why yes, my mother's maiden name is Correct7Horse@Battery!Staple, why do you ask?

[–] Zwuzelmaus@feddit.org 1 points 1 month ago (1 children)

additional password fields, where I just create additional fields for them in my password manager, and generate long, random responses

Such hassle...
I guess it means yes, you take that stuff for serious.

[–] skaffi@infosec.pub 1 points 1 month ago

A hassle, huh?

Security questions are an idiotic type of "security", so of course I never enable them if they're optional, which they almost always are. As I said, I can count on half a hand how often I've used them in recent years.

Occasionally, though, they can be the least bad two-factor option available on a service that either requires 2FA or which makes itself, indeed, a hassle to use when you don't have any 2FA enabled, such as by throwing captchas at you up the wazoo. If such a service only offers 2FA by email, text message or security questions, then hell yeah, I'll take the latter option any day of the week. Needing an emailed link or code to log in, now that's a hassle. Same deal with text messages, but with the additional benefit of them being insecure as hell. You know what's not a hassle, though? Having one extra field auto-filled by your password manager. That's the hassle-free option.

As for taking things seriously or not - are you really trying to tell me that you don't have anything that's important enough to care about keeping secure? And if not, why would you not care about keeping anything that's important secure? Especially when it's so easy, and indeed, hassle-free, to have that security fully automated and handled by your password manager. If your gut reaction to security is that it's a hassle, then I'm sorry to say that you most likely have both poor security, and unnecessarily difficult or annoying-to-use security, too. Do you subject yourself to the mental load of having to remember all of your hundreds of passwords in your head? Talk about a hassle. Or do you just use the same password for everything? Now that would be a hassle, to have not just one random account somewhere compromised, but to have all of your accounts, everywhere at once, compromised.

load more comments (5 replies)
load more comments (6 replies)