<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: &#8220;Secret&#8221; Questions</title>
	<atom:link href="http://afongen.com/blog/2008/08/30/secret-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://afongen.com/blog/2008/08/30/secret-questions/</link>
	<description>Sam Buchanan's weblog</description>
	<lastBuildDate>Fri, 11 Sep 2009 21:36:51 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ian</title>
		<link>http://afongen.com/blog/2008/08/30/secret-questions/comment-page-1/#comment-27975</link>
		<dc:creator>Ian</dc:creator>
		<pubDate>Thu, 19 Feb 2009 19:09:48 +0000</pubDate>
		<guid isPermaLink="false">http://afongen.com/blog/?p=1006#comment-27975</guid>
		<description>It&#039;s worse than that.  If I was a bad guy, I&#039;d be loving the current exhibitionist trend on FaceBook and other sites, of the &quot;25 things about me&quot; which are FULL of secret question answers.

In fact, you could phish someone pretty easy with one of those... 

1.  Guess one of your &quot;friends&quot; bank.  
2.  Write down the questions you have to choose from when creating an account.  
3. Insert into the &quot;25 things ..&quot; list.  
4.  PROFIT!!!</description>
		<content:encoded><![CDATA[<p>It&#8217;s worse than that.  If I was a bad guy, I&#8217;d be loving the current exhibitionist trend on FaceBook and other sites, of the &#8220;25 things about me&#8221; which are FULL of secret question answers.</p>
<p>In fact, you could phish someone pretty easy with one of those&#8230; </p>
<p>1.  Guess one of your &#8220;friends&#8221; bank.<br />
2.  Write down the questions you have to choose from when creating an account.<br />
3. Insert into the &#8220;25 things ..&#8221; list.<br />
4.  PROFIT!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: delia ayon</title>
		<link>http://afongen.com/blog/2008/08/30/secret-questions/comment-page-1/#comment-27902</link>
		<dc:creator>delia ayon</dc:creator>
		<pubDate>Thu, 12 Feb 2009 09:21:44 +0000</pubDate>
		<guid isPermaLink="false">http://afongen.com/blog/?p=1006#comment-27902</guid>
		<description>My problem with my &quot;secret question&quot; is that instead of asking a question, it reads &quot;Question:  question&quot;.  so I do not know what to answer.  I have tried all the answers I can think of but I have been locked out several times.</description>
		<content:encoded><![CDATA[<p>My problem with my &#8220;secret question&#8221; is that instead of asking a question, it reads &#8220;Question:  question&#8221;.  so I do not know what to answer.  I have tried all the answers I can think of but I have been locked out several times.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://afongen.com/blog/2008/08/30/secret-questions/comment-page-1/#comment-26533</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Thu, 04 Sep 2008 04:05:03 +0000</pubDate>
		<guid isPermaLink="false">http://afongen.com/blog/?p=1006#comment-26533</guid>
		<description>Sorry you wasted your time.

As I said at the outset, I hesitated to write this post, in part because of what may be perceived as the obviousness of the problem. But in the past couple months, I&#039;ve had several conversations with developers to whom this is all completely new. A couple of those conversations happened just last week. So I decided to write it and wreak suffering upon the unsuspecting.

Solutions? Read those last two paragraphs again:

* choose good questions. Nope, no guidance on that right now.
* multiple questions, although that just adds a speed bump by making it a trifle harder to crack with brute force.
* Expect demonstrated control of a resource.
* closely related to that, multi-factor authentication, although man-in-the-middle attacks render it less than ideal.
* Lock accounts for failed password retrieval attempts, or at least treat them the same way as failed logins.

Silver bullet? No. Just small design considerations that make small improvements. I&#039;m not trying to suggest a good password retrieval system in this post, although maybe I should another time.</description>
		<content:encoded><![CDATA[<p>Sorry you wasted your time.</p>
<p>As I said at the outset, I hesitated to write this post, in part because of what may be perceived as the obviousness of the problem. But in the past couple months, I&#8217;ve had several conversations with developers to whom this is all completely new. A couple of those conversations happened just last week. So I decided to write it and wreak suffering upon the unsuspecting.</p>
<p>Solutions? Read those last two paragraphs again:</p>
<p>* choose good questions. Nope, no guidance on that right now.<br />
* multiple questions, although that just adds a speed bump by making it a trifle harder to crack with brute force.<br />
* Expect demonstrated control of a resource.<br />
* closely related to that, multi-factor authentication, although man-in-the-middle attacks render it less than ideal.<br />
* Lock accounts for failed password retrieval attempts, or at least treat them the same way as failed logins.</p>
<p>Silver bullet? No. Just small design considerations that make small improvements. I&#8217;m not trying to suggest a good password retrieval system in this post, although maybe I should another time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sy</title>
		<link>http://afongen.com/blog/2008/08/30/secret-questions/comment-page-1/#comment-26515</link>
		<dc:creator>Sy</dc:creator>
		<pubDate>Tue, 02 Sep 2008 06:36:04 +0000</pubDate>
		<guid isPermaLink="false">http://afongen.com/blog/?p=1006#comment-26515</guid>
		<description>Thanks for wasting my time. We already know this. I thought you had solution.</description>
		<content:encoded><![CDATA[<p>Thanks for wasting my time. We already know this. I thought you had solution.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
