Lie your way to password security

Opinion
Oct 12, 20103 mins

* Protect yourself from hackers and Web sites that collect personal identity information

My friend Martin Kuppinger (of the Kuppinger-Cole analyst firm) recently blogged about “security questions.” You know, those things you’re asked in order to prove that you’re you whenever you forget your password (or, in my case, simply get fumble-fingered and mistype it).

Martin said: “When working with my colleagues Sachar Paulus and Sebastian Rohr on a comprehensive piece on strong authentication which will be published soon, we discussed the privacy aspects of all these (more or less strong) authentication approaches — and struggled… The answers on all the typical questions are privacy-relevant data. They unveil some important knowledge about the user. The more questions, the more knowledge. You could argue that this isn’t that sensitive information — but first of all, it is personal data and second, this depends on the questions.”

41% of Web users share online passwords

Many have questioned the ease of how hackers could acquire these answers through Web searches or social engineering. But Martin raises another question — what are the sites that collect this information doing with the Personally Identifiable Information (PII) they are collecting? Kuppinger notes: “Have you ever seen something around privacy-related disclaimers, buttons to accept the privacy policies of the organization or something like that around these questions?”

Well, I’ve got the answer and it works for both cases — both the scammers and the Web sites. It’s real simple — lie!

There’s three different approaches to the lie; you can take your pick. First, you can use the same answer for all of the questions, possibly a made-up word (mother’s maiden name? Bumfuzzle, First car? Bumfuzzle, etc.) The drawback is that once someone learns your word they have access to everything.

The second approach is to use the key word from the question as the answer, sort of like using “password” as your password. Thus: mother’s maiden name? Mother. Street you grew up on? Street, etc. It’s potentially guessable, but not easily so.

Third, and the approach I use, is to use what appears to be real data (Mother’s maiden name? Jones. First car? Honda, etc.) but is false. No amount of searching could turn up these answers to these questions. And, of course, the data is worse than useless to any Web site hoping to cash in on demographics that might be revealed as it throws their calculations off. It’s really a big win for you, the liar.

In other news from the German company, Kuppinger’s partner Tim Cole has moved back to the United States to open an office in Boston (halfway between Germany and Silicon Valley, according to Cole) to better serve their growing North American clientele.