iSnare.com - Free Content Articles Directory
Authors Contents [Advanced Search][Add OpenSearch][Job Search]
Distribute your articles to thousands of article sites for only $2 and below! Read more...

Index  Internet
 

Why Security Questions Can Be Bad News

 
[ Contact the Author] [ Send to a Friend] [ Article Publisher] [Make PDF] [ Print] [ Bookmark & Share]
 
Read our Terms of Service before reprinting this article. The submitter specified above has claimed the rights to this article.
Andrew Malek

If you access web-based services such as social networking websites, message forums, or online banking applications, you've probably had to register for a user account. This sometimes drawn-out process required you to enter a login name as well as a password (or get one assigned to you), providing some sense of security when accessing the service.

Since good passwords (not the words 'computer' nor 'secret') can be almost impossible to remember (such as a ten character combination of letters, numbers, and punctuation), many services now use a "security question" you can answer in case you forget your username and/or password and need to retrieve or reset them. By offering a security question, these services can help ensure it is really you when a request is made for your login information.

Some websites may even require answering this security question as well as your password every time you use their services, offering a supposed second level of account security.

Security questions are normally facts that supposedly only you can recall, information that should not change. Several common examples are listed below:

* First School Attended
* Mother's Maiden Name
* Name of First Pet
* Where a Spouse was First Met

Some websites force you into answering a predefined question, a popular one being your mother's maiden name. Others offer a list of questions from which you may choose, but some may allow you to type your own questions and answers. This allows you to enter private information such as the name of your favorite musical group, the name you gave a pet rock, or the celebrity poster you placed on your wall as a kid.

Unfortunately, the answers to some security questions are well-known, easy guessed, can be obtained online, or can be found via public records or a private investigator (and if someone truly wants access to your account they may go through a lot of trouble). Thus, these questions, while provided to either offer a second level of security or remove the need for customer service representatives to otherwise verify identity when you request a new password, can cause all sorts of trouble.

Especially if only a security question is required to obtain or reset a password, or even a combination of a security question and other pieces of personal information, if someone can guess or obtain the answers to your questions, it is open season on your account!

This type of secret question and answer hacking can and has affected many individuals, including famous people. As an example, according to reports, 2008 Republican Vice-Presidential candidate Sarah Palin had her e-mail account breached when someone allegedly answered a few questions during a password reset request. The questions were her birthday, zip code, and where she met her spouse (Wasilla High), information available on the web or easily guessed.

Now that you know how easy it may be for others to access your account via a security question, what can you do to help protect yourself?

* If offered the choice, pick the most obscure security question offered or type your own question and answer if this feature is available. Pick something you and only you may know - something you are positive is not available in public records, your Facebook page, or elsewhere online. Never use your mother's maiden name, social security number, or birthplace, as these can either be found or cause other security and privacy problems if someone does hack the account and read the answers to your security questions.

* Use different security questions for each and every service. No matter how secure you make your account, it can get hacked due to lackluster security procedures of the web service provider or even due to an inside job. Someone could read the answers to your security questions and use these to gain access to your accounts on other websites!

* Consider treating your security question's answer as a second password. You can either encrypt the answer by replacing the letter 'O' with a number 0, the letter 'l' with a number 1, the letter 'a' with the @ symbol, etc., though as dictionary attacks become more advanced this may become less effective. Or "go crazy" and create nonsensical answers just like your passwords as a combination of letters, numbers, and punctuation symbols.

The downside to this method is that your answer may be impossible to remember so you'll have to store it somewhere. And if you do forget your security question answer or cannot find it, you may never be able to reset your password! As a best case scenario you might be able to call customer service or send a copy of your ID to prove your identity. These processes could take a long time, problematic if, for example, you need to use an online banking service to pay your utilities bill today. And remember that some sites may require you to answer your security question every time you login, not just if you forget your password.

While website user account security used to revolve around just a login ID and a password, security questions have become very commonplace, especially as user verification when retrieving a lost password. If you are forced to answer such a question, try to pick the most obscure information possible so it is not easily guessed or found. Use different security questions on each and every website in case your account does get hacked and your answers read. Finally, consider treating your security question as a second password, making it cryptic thus difficult to hack. Security questions have become a modern fact of life on the Internet, so learn how to use them to your advantage.

Copyright 2009 Andrew Malek.

Important NoticeDISCLAIMER: All information, content, and data in this article are sole opinions and/or findings of the individual user or organization that registered and submitted this article at Isnare.com without any fee. The article is strictly for educational or entertainment purposes only and should not be used in any way, implemented or applied without consultation from a professional. We at Isnare.com do not, in anyway, contribute or include our own findings, facts and opinions in any articles presented in this site. Publishing this article does not constitute Isnare.com's support or sponsorship for this article. Isnare.com is an article publishing service. Please read our Terms of Service for more information.

Andrew Malek owns the MalekTips computer and technology help site at http://www.malektips.com/. MalekTips offers thousands of computer tips for beginners and experts including advice on searching the Internet at http://malektips.com/internet-search/, websites to browse, and how to stay safe when online.

Article Tags: password [See Dictionary], question [See Dictionary], security [See Dictionary]
Got a question about this article? Ask the community!
Article published on March 10, 2009 at Isnare.com
 
Rate this article:

7 Reasons People Tell You Not to Switch Web Browsers
Submitted by: Andrew Malek

When you purchased your computer or installed a new operating system, more than likely it came bundled with a web browser such as Internet Explorer or Apple Safari...

Smilies and Abbreviations in Email and Instant Messaging
Submitted by: Andrew Malek

Electronic mail and instant messaging seem very different from phone conversations or postal mail In fact, it's almost as if a new language has been born from these mediums...

Pros and Cons of Using Free Web-Based Email Providers
Submitted by: Andrew Malek

Nowadays, more Internet users are turning away from software-based e-mail programs run on their own computers such as Outlook and Windows Mail and towards web-based e-mail services like Yahoo...

Top 7 Ways to Help Make Sure Your E-Mail Gets Read
Submitted by: Andrew Malek

While e-mail is an extremely important tool that helps friends, family members, and coworkers communicate, the rampant spread of unsolicited commercial e-mail has made this communication medium less useful...

Is it a Hoax Or is it Real?
Submitted by: Andrew Malek

Many of us have received e-mail from friends, family members, or coworkers that seemed too shocking, funny, or weird to be true...

Think That Attachment is From Your Friend?
Submitted by: Andrew Malek

Did someone you know just send you an electronic mail attachment that you weren't expecting Perhaps it's a picture to go along with a joke, a song they want you to hear, or a program that displays fireworks on your screen...

Be Careful With Social Network Invite E-Mails
Submitted by: Andrew Malek

Nowadays, many of us receive e-mail invitations to join social networking websites such as Facebook, LinkedIn, or MySpace...

Stop Spending Your Money On Higher Gas Prices - Use The Internet
Submitted by: Andrew Malek

Gasoline prices continue to rise, costing you money At the risk of dating this article, previously unseen U...

Basics Of Search Engine Optimisation (SEO)
Submitted by: Lijo George

What is SEO Search Engine Optimization is a step by step process in which a web site is optimized to the expectations of Search Engines...

Ebook - E For Environmental
Submitted by: Roberto Sedycias

The emphasis on going green is highlighted as writing books are one of the contributors for depleting natural resources...

How to Optimize Your Website Keywords - SEO
Submitted by: Sebastian Warnke

What does it take to be in the top 10 search engine results on Google or Yahoo The answer is finding the right keywords and optimizing your site accordingly...

Who Needs a Website Builder?
Submitted by: Jason Kay

If you are planning your first website you have no doubt heard of a website builder, but perhaps you are not sure of what it is or if you need one...

How Much You Need to Pay For Domain Redemption
Submitted by: John Khu

At times, people may simply forget to renew their domain names on time It is possible that the owner simply neglected the importance of renewing the domain name...

Making Money Online With Expired Domain Names – Some Practical Ways
Submitted by: John Khu

As an internet entrepreneur, you can make money in several ways Expired domains are few of the tools that can help you create enough online income...

How to Get Google Page Rank?
Submitted by: Jack Wylde

Making the most of Google’s page rank can totally bring your business or website to the forefront This is immense with a lot of toolbars and page rank facilities that can now work with Google rank escalating for many website owners...

Paid Survey Strategies That Do Not Benefit Users
Submitted by: Scott Lindsay

Paid surveys are offered as a premier way to make money by sharing an opinion A counter product is known as paid emails...

Understanding and Implementing Sound SEO Principles
Submitted by: Scott Lindsay

Search Engine Optimization (SEO) is often talked about as if it is understood completely The trouble is there are some who are just being introduced to online marketing that have very little idea what SEO is and why it is important...

Article Writer - Do You Need One?
Submitted by: Enzo F. Cesario

Content is king Your web presence needs content that your audience will be interested in, period...

How to Find Quality Web Directories
Submitted by: Jason Kay

When you promote your website one of the first things you will want to do is to submit your website to a number of different web directories...

Review of Mozy Online Storage
Submitted by: Jason Kay

Every year people just like you lose countless documents and important files because of the unforeseen, but with online storage companies such as Mozy, this scenario can be avoided forever...

You Can Still Make Good Money on Ebay
Submitted by: Mark Thomas Walters

The banning of the sale of digital products on eBay has led to many online marketers abandoning the use of eBay as one of their revenue streams...

Secrets to Using Social Bookmarking For Link Building
Submitted by: Blake Evans

Social bookmarking became popular as a tool to share your favorite websites with others on the internet...

What is Pagerank?
Submitted by: Blake Evans

The Internet is a vast expanse of space which contains matter on anything you can think of Due to the instantaneous nature of the Internet, anyone who has access to a computer and a phone line indulges in some browsing on various subjects...

Isnare.com Footer Divider

© 2004-2009. Isnare Free Articles - An Isnare Online Technologies Free Articles Project. All Rights Reserved.   Privacy Policy