The Importance of Security Questions
Posted in Security on April 2nd, 2009 by Justin CaseFrom experience and research, I have found security questions are often weaker and easier to crack than passwords are. More often than not, the answers to a person’s security question can easily be looked up online. These questions should never be something anyone else would know.
Here are some examples of common security questions I have run across.
What is my social security number?
What was my first phone number?
What is my favorite sports team?
What school did i go to?
Social security numbers are an easy find for even the most basic script kiddie out there. Old phone numbers can be looked up at most public record sites. Schools and favorite sport teams are easily found on most people’s profiles on social networks.
Here are some examples of good examples of security questions.
Who was my hottest teacher?
When was I most afraid in my life?
What was the name of my first grade teacher?
What was my first pet’s name?
Following these rules and the ones found in Elements of a Secure Password will stop 99% of crackers in their tracks.

April 10th, 2009 at 10:48 am
[...] This type of attack will work with almost any kind of an account that uses security questions. To protect yourself, make sure you choose a good security question. See The Importance of a Security Questions. [...]
May 26th, 2009 at 4:50 pm
[...] while ago my colleague blogged about the importance of security questions in keeping your online accounts safe. We came to the conclusion that security questions, in many [...]