28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

been in use as a securityy question since at least 1882. 14 As I’ll discuss

below, companies can and do scan the Internet and collect personal

information that makes answering these basic securityy questions a piece of

cake. A person can spend a few minutes on the Internet and have a good

chance of being able to answer all the securityy questions of a given

individual.

Onlyy recentlyy have these securityy questions improved somewhat. For

example, “What is the state where yyour brother-in-law was born?” is prettyy

distinct, though answering these “good” questions correctlyy can carryy its

own risks, which I’ll get to in a minute. But manyy so-called securityy

questions are still too easyy, such as “What is yyour father’s hometown?”

In general, when setting these securityy questions, tryy to avoid the most

obvious suggestions available from the drop-down menu. Even if the site

includes onlyy basic securityy questions, be creative. No one sayys yyou have to

provide straightforward answers. You can be clever about it. For example,

as far as yyour streaming video service is concerned, mayybe tutti-frutti is

yyour new favorite color. Who would guess that? It is a color, right? What

yyou provide as the answer becomes the “correct” answer to that securityy

question.

Whenever yyou do provide creative answers, be sure to write down both

the question and the answer and put them in a safe place (or simplyy use a

password manager to store yyour questions and answers). There mayy be a

later occasion when yyou need to talk to technical support, and a

representative might ask yyou one of the securityy questions. Have a binder

handyy or keep a card in yyour wallet (or memorize and consistentlyy use the

same set of responses) to help yyou remember that “In a hospital” is the

correct answer to the question “Where were yyou born?” This simple

obfuscation would thwart someone who later did their Internet research on

yyou and tried a more reasonable response, such as “Columbus, Ohio.”

There are additional privacyy risks in answering veryy specific securityy

questions honestlyy: yyou are giving out more personal information than is

alreadyy out there. For example, the honest answer to “What state was yyour

brother-in-law born in?” can then be sold byy the site yyou gave that answer

to and perhaps combined with other information or used to fill in missing

information. For example, from the brother-in-law answer one can infer that

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!