passwords - Why don't the answers to "security questions" need to be stored securely? -
I have done some work on some places now where the password is salty and is divided into pieces in the database, but for the answer security The questions are stored in plain text Now, I have signed up for our hydro power company online portal, and in the Account Management section, the security question and answer is displayed to me. Given that security questions and answers often allow the use of the user, in an alternative way, without a password, in an account, why are they allowed to store them in plain text? Especially when people often have a limited pool of security questions to choose from, so they use the same answer in many sites.
The problem with security questions is that the designs are completely insecure. Because they are stored in plain text, it is sometimes used by humans to confirm that they should be seen by humans and that some answer is correct. A user's answer to their favorite food is "corn pop", and they answer "popcorn", so this is a valid answer.
Hashing the answers to the security questions will require the user to know his previous answer that absolutely , such as it was a password, and we already know that the user forgot his password (In cases where the user is trying to access the account).
Similarly, because these are not arbitrary answers like passwords, sometimes they are displayed back to the user as you saw them. This is because when he is no longer right then his answer can change. The password is an arbitrary response, but the security questions are not answered unchecked. People's choices and even what or what they think is that they can change over time. A user who is asked from his favorite movie, he can choose one last night, and after a year forgets that he has ever given it such a high status.
For that matter, the answer to the security questions is the hedging limited utility (primarily for security jacks which they know to answer randomly). His very nature is that he is public Hashing the user's latest car model does not just keep hackers from reading his Facebook feed.
Security questions are not safe to use to use them. Technically, they should be treated like passwords, because they are passwords for all practical purposes but if we have taken the answers to the security questions, then the necessary users should choose strong answers And they are not allowed to easily guess the answer, then there will be no meaning for them.
Remember, the purpose of security questions and answers is not bypass password the more they are behaving like a password, the more useless they become for that purpose.
Comments
Post a Comment