Hacker News new | past | comments | ask | show | jobs | submit login

....what kind of crack are you smoking? Can I have some?

So you called customer support to reset the password. You could call them whether or not there were personal security questions. Nothing changes.

OTOH the personal security questions ensure only one person can access the account (when attempting a normal login) instead of any employee at the business. Passwords might be shared but security questions probably wouldn't be (assuming only one person is accessing the account).

The questions are not intended to be impossible to crack. They're an additional data point to verify authenticity. The assumption is that you won't keep the name of your favorite animal next to your password (wherever it is that someone got your password from), thus it's an additional attack vector someone would have to account for. Not impossible, but adds difficulty.

tl;dr: added authentication prompts add to attack complexity, and you're on crack.

[p.s. you might want to change your bank account password and challenge questions when an employee who had it leaves. could be helpful.]




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: