BankInfoSecurity.com - Banking Information Security News, Regulations, & Education  

Username:
Password:
 

Using Secret Questions

Identity Theft
Management Guidelines
Risk Management
STRONG Authentication

To help verify a user's identity in the case of a lost password, many Web applications use secret questions. By answering a pre-selected question, a user can demonstrate some personal knowledge of the account owner. A classic example is asking to provide a mother's maiden name.

Answering secret questions requires some knowledge of the user account, but secret questions break all the rules for strong passwords and have some significant weaknesses:

" An attacker can somet

> Read entire article (log in required - registration is free)



Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2007 BankInfoSecurity.com