Skip to content

Comment on Challenge-response: the use of incorrect responses in validating identity

Comments

I usually give a different email address to each service that I sign up to, so I can tell if they are selling my address, but I never thought of giving a different mother's maiden name so I can detect phishing. It's a reasonable strategy, but I have trouble remembering the name of my elementary school, my favorite color (I dont care), the make of my first car (my parent's or the one I actually paid for) ... However, I will trythe strategy of giving a couple of wrong answers to weed out the fakes.

The issue with providing an answer that is a meaningful response is that one can in fact guess and often get it right. Second, most sites that use these secret answers (favorite color, first car, ...) don't have a mechanism to lock out after a certain number of incorrect attempts.

My first car is likely something like x78uyipoqA.

Call me paranoid!

I used a password manager and synchronize my desktop with my PDA.

Check out

http://en.wikipedia.org/wiki/Password_manager

This is a really good idea. You could have all the emails forward to one master account, and then when one started forwarding spam, you could cut it off.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.