Secret questions are not foolproof

Opinion
Dec 11, 20063 mins

* Finding ways to make the secret questions work better

A speaker at the recent Marcus Evans Identity Management Conference in Sydney was talking about the use of “secret questions,” which reminded me that I’d wanted to say something about this phenomenon.

These days, secret questions are most often associated with self-service password reset. The questions ask for supposedly secret information that only you would know, such as:

* Your mother’s maiden name

* City where you were born

* Brand of first car

* Name of first pet

And more.

The problem, as many have pointed out, is that this so-called secret information is readily discoverable by anyone who wants to dig a bit. As security maven Bruce Schneier said in “The Curse of the Secret Question” : “I’ll bet the name of my family’s first pet is in some database somewhere.” Bruce’s suggestion? “My usual technique is to type a completely random answer – I madly slap at my keyboard for a few seconds – and then forget about it. This ensures that some attacker can’t bypass my password and try to guess the answer to my secret question, but is pretty unpleasant if I forget my password.” Well that actually defeats the one good purpose of the secret password as well as blocking the bad uses – an example of tossing out the baby with the bathwater. I’ve got a better suggestion.

Lie.

Always claim your mother’s maiden name was Chicago, your first pet was named Buick, you were born in Spot and your first car was an O’Leary. Or anything else – the important thing is that you consistently apply the same answer to the same question and that there’s a method for remembering it. Or adopt a different spelling, 0’L3ary for your mother’s maiden name, perhaps. It’s not foolproof, of course. A determined cracker could – given enough time – eventually arrive at the proper word but crackers are just as lazy as the rest of us – they prefer to go after the low hanging fruit first.

I was telling Brian Brannigan, managing director and co-founder of Australia identity management firm Agreon, about my wonderful idea – and he managed to top it!

Brian suggested that he’d be very willing to support the first self-service password reset vendor that not only provided the secret question method but allowed you to specify “trigger words” – words that would trigger an immediate clampdown. So if someone did do their “due diligence” and discover your mother’s actual maiden name, entering it would immediately lock down their access, set off alarms and capture all relevant data to their session. Brilliant!

So, identity management vendors, who’s going to step up and be first?