Hacker News new | past | comments | ask | show | jobs | submit login

Here's what I use to generate answers to secret questions:

    < /dev/urandom tr -dc a-z0-9 | head -c 16
This leads to things like:

> "What is your first pet's name?"

"q1ry9nftmxb1gmag"

I haven't had it happen yet, but I wonder what a customer service rep's response will be when I spell out "yrlmduihhyju5il0" when asked what my favorite color is.




The guy on the phone laughed. I've moved to providing a few random words, easier to say over the phone than capital y lowercase r number 1.... etc.


Be careful with it. Was dealing with credit card stuff (raising limit to go on travel) and when they were verifying my identity the policy was evidently to combine my questions with a "background check"

Said background check basically being they googled my name.

Which you would think isn't a problem until you get to "What school did you graduate from?" and have to go through four levels of reps to explain that (not actually what I typed) "Omelette Du Fromage" was my way of making it harder to social engineer my account.


The woman on the phone at the utility company that was messing me around didn't laugh when I said the answer to my security question "what do you think of customer service" was "f*cking retards" :-D


Who even makes that a security question? I mean seriously. You might as well ask "What is your opinion on the color yellow?"


"What is your opinion of cargo cult infosec practices, specifically security questions?"


Going to guess they wrote it themselves in this case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: