<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tighten the Security of &#8220;Security Questions&#8221;</title>
	<atom:link href="http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/</link>
	<description>Linux.  GNU.  Freedom.</description>
	<lastBuildDate>Fri, 17 May 2013 20:46:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta2-24176</generator>
	<item>
		<title>By: Aaron Toponce</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116483</link>
		<dc:creator>Aaron Toponce</dc:creator>
		<pubDate>Tue, 06 Mar 2012 18:49:01 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116483</guid>
		<description><![CDATA[This doesn&#039;t fall apart at all. It just makes it slightly more difficult to read over the phone.]]></description>
		<content:encoded><![CDATA[<p>This doesn&#8217;t fall apart at all. It just makes it slightly more difficult to read over the phone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Spigarelli</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116482</link>
		<dc:creator>Steve Spigarelli</dc:creator>
		<pubDate>Tue, 06 Mar 2012 15:48:40 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116482</guid>
		<description><![CDATA[Of course, the only time this falls down is when you need to provide a valid representative with your security question&#039;s answer. For password recovery and such this makes a lot of sense.]]></description>
		<content:encoded><![CDATA[<p>Of course, the only time this falls down is when you need to provide a valid representative with your security question&#8217;s answer. For password recovery and such this makes a lot of sense.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Pope</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116481</link>
		<dc:creator>Alan Pope</dc:creator>
		<pubDate>Tue, 06 Mar 2012 15:36:37 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116481</guid>
		<description><![CDATA[I just lie when asked security questions. Much easier :)]]></description>
		<content:encoded><![CDATA[<p>I just lie when asked security questions. Much easier <img src='http://pthree.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Toponce</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116480</link>
		<dc:creator>Aaron Toponce</dc:creator>
		<pubDate>Tue, 06 Mar 2012 13:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116480</guid>
		<description><![CDATA[I wouldn&#039;t recommend using your password as the answer to these forms, for two reasons. First, the point of these forms is in the event that you have forgotten your password, you can recover it. Second, the password SHOULD be hashed with a salt on disk by the provider. The answer to the security questions probably isn&#039;t. So, providing your password in all fields could potentially open your account up for attack by the site administrators. Further, because these form fields are not encrypted, providing answers in the clear could build up an identity about yourself. Best to hash the answers, IMO.]]></description>
		<content:encoded><![CDATA[<p>I wouldn&#8217;t recommend using your password as the answer to these forms, for two reasons. First, the point of these forms is in the event that you have forgotten your password, you can recover it. Second, the password SHOULD be hashed with a salt on disk by the provider. The answer to the security questions probably isn&#8217;t. So, providing your password in all fields could potentially open your account up for attack by the site administrators. Further, because these form fields are not encrypted, providing answers in the clear could build up an identity about yourself. Best to hash the answers, IMO.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ricardo N Feliciano</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116479</link>
		<dc:creator>Ricardo N Feliciano</dc:creator>
		<pubDate>Tue, 06 Mar 2012 12:38:27 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116479</guid>
		<description><![CDATA[Curious, how would you say your idea stacks up against using the password. I usually use my password, or maybe my previous password (I change them every 6 months), as the answer to security questions.

I ask because using a salt, and keeping it private, is sort of like having a password anyway.

In my opinion, sites that force security questions, (usually banks for me), actually weaken the security on my account, as in the example you provided.]]></description>
		<content:encoded><![CDATA[<p>Curious, how would you say your idea stacks up against using the password. I usually use my password, or maybe my previous password (I change them every 6 months), as the answer to security questions.</p>
<p>I ask because using a salt, and keeping it private, is sort of like having a password anyway.</p>
<p>In my opinion, sites that force security questions, (usually banks for me), actually weaken the security on my account, as in the example you provided.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Toponce</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116478</link>
		<dc:creator>Aaron Toponce</dc:creator>
		<pubDate>Tue, 06 Mar 2012 03:58:43 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116478</guid>
		<description><![CDATA[Richard- Good point. I guess you&#039;ll have two hashes to choose from then, if you can&#039;t remember whether or not your mother&#039;s maiden name starts with an uppercase &#039;S&#039; or a lowercase one.]]></description>
		<content:encoded><![CDATA[<p>Richard- Good point. I guess you&#8217;ll have two hashes to choose from then, if you can&#8217;t remember whether or not your mother&#8217;s maiden name starts with an uppercase &#8216;S&#8217; or a lowercase one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116477</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Tue, 06 Mar 2012 00:26:59 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116477</guid>
		<description><![CDATA[Websites usually handle the answers to these security questions case-insensitively. So by using a hash-based answer be mindful that you&#039;re forced into case-sensitivity with your plaintext (including the salt), i.e. the words &quot;Smith&quot; and &quot;smith&quot; are no longer equally acceptable answers.]]></description>
		<content:encoded><![CDATA[<p>Websites usually handle the answers to these security questions case-insensitively. So by using a hash-based answer be mindful that you&#8217;re forced into case-sensitivity with your plaintext (including the salt), i.e. the words &#8220;Smith&#8221; and &#8220;smith&#8221; are no longer equally acceptable answers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tensai</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116476</link>
		<dc:creator>tensai</dc:creator>
		<pubDate>Tue, 06 Mar 2012 00:19:44 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116476</guid>
		<description><![CDATA[I just do the same thing I do for all passwords: generate them randomly (or semi-randomly, as seems appropriate) and write them down in a password database. I just make sure to note which of the questions I gave an answer to.]]></description>
		<content:encoded><![CDATA[<p>I just do the same thing I do for all passwords: generate them randomly (or semi-randomly, as seems appropriate) and write them down in a password database. I just make sure to note which of the questions I gave an answer to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christer Edwards</title>
		<link>http://pthree.org/2012/03/05/tighten-the-security-of-security-questions/#comment-116475</link>
		<dc:creator>Christer Edwards</dc:creator>
		<pubDate>Mon, 05 Mar 2012 23:44:58 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2338#comment-116475</guid>
		<description><![CDATA[Get someone to write a browser plugin to automate this.]]></description>
		<content:encoded><![CDATA[<p>Get someone to write a browser plugin to automate this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
