Skip to Content
Carry On: Sound Advice from Schneier on Security
book

Carry On: Sound Advice from Schneier on Security

by Bruce Schneier
December 2013
Intermediate to advanced
384 pages
10h 40m
English
Wiley
Content preview from Carry On: Sound Advice from Schneier on Security

Chapter 3

Human Aspects of Security

Secret Questions Blow a Hole in Security

Originally published in ComputerWeekly, April 4, 2008

It's a mystery to me why websites think “secret questions” are a good idea. We sign up for an online service, choose a hard-to-guess (and equally hard-to-remember) password, and are then presented with a “secret question” to answer.

Twenty years ago, there was just one secret question: What's your mother's maiden name? Today, there are several: What street did you grow up on? What's the name of your favorite teacher? What's your favorite color? Often, you get to choose.

The idea is to give customers a backup password. If you forget your password, then the secret question is a way to verify your identity. It's a great idea from a customer service perspective—users are less likely to forget their first pet's name than some random password—but terrible for security.

The answer to the secret question is much easier to guess than a good password, and the information is much more public. I'll bet my childhood address is in some database somewhere. And worse, everybody seems to use the same series of secret questions.

The result is that the normal security protocol (passwords) falls back to a much less secure protocol (secret questions). The security of the entire system suffers. I'm sure the designers of the system thought the fallback system would only be used rarely, when a user forgot their password. But any good security engineer realizes that bad guys ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

The Ransomware Threat Landscape

The Ransomware Threat Landscape

Alan Calder
Schneier on Security

Schneier on Security

Bruce Schneier
How to Cheat at Configuring Open Source Security Tools

How to Cheat at Configuring Open Source Security Tools

Michael Gregg, Eric Seagren, Angela Orebaugh, Matt Jonkman, Raffael Marty

Publisher Resources

ISBN: 9781118790823Purchase book