{"id":188,"date":"2008-10-02T12:42:09","date_gmt":"2008-10-02T12:42:09","guid":{"rendered":""},"modified":"2008-10-02T12:42:32","modified_gmt":"2008-10-02T12:42:32","slug":"security_questions_for_online_authentica","status":"publish","type":"post","link":"https:\/\/blogs.ncl.ac.uk\/isg\/?p=188","title":{"rendered":"Security questions for online authentication &#8211; lying is the best policy!"},"content":{"rendered":"<p>When you sign up for practically anything online these days that has a password, you&#8217;ll be asked to provide answers for additional security questions, whether it&#8217;s for an additional level of authentication (for online banking), or just as a way of allowing you to authenticate to change a password that you&#8217;ve forgotten.<\/p>\n<p>The trouble with these is that it&#8217;s relatively easy these days to find the answers to the most common security questions for another individual. In a world of social networks and Google, you can probably find out someone&#8217;s mother&#8217;s maiden name, where they were born and what their first school was fairly easily; perhaps they have a blog where you can find out the name of their pets, or other information that&#8217;s sometimes used.<\/p>\n<p>The news that someone had <a href=\"http:\/\/www.time.com\/time\/business\/article\/0,8599,1843984,00.html\">gained access to Sarah Palin&#8217;s Yahoo account<\/a> last month reminded me of <a href=\"http:\/\/blogs.technet.com\/steve_lamb\/archive\/2007\/08\/03\/i-d-like-to-change-my-mother-s-maiden-name-please.aspx\">this earlier post<\/a> by Microsoft UK&#8217;s Steve Lamb, who tried to change his mother&#8217;s maiden name with his bank to avoid this very issue.<\/p>\n<p>For a while, I&#8217;ve been using a <a href=\"http:\/\/people.howstuffworks.com\/spy1.htm\">legend<\/a>, with a fake mother&#8217;s maiden name, first school, pets, etc, which only I know. This is of course something else that I need to remember, but if you&#8217;re going to take security seriously, you&#8217;re going to have to make a bit of an effort with it. Of course if you were going to get really serious about this, you&#8217;d have to use a different legend for each authentication system &#8211; it&#8217;s up to you how far you want to go &#8211; but I&#8217;d definitely recommend using a few little white lies to keep your online accounts safe.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When you sign up for practically anything online these days that has a password, you&#8217;ll be asked to provide answers for additional security questions, whether it&#8217;s for an additional level of authentication (for online banking), or just as a way &hellip; <a href=\"https:\/\/blogs.ncl.ac.uk\/isg\/?p=188\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":4741,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[],"class_list":["post-188","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=\/wp\/v2\/posts\/188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=\/wp\/v2\/users\/4741"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=188"}],"version-history":[{"count":0,"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=\/wp\/v2\/posts\/188\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ncl.ac.uk\/isg\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}