# Website "security" questions with no add-your-own-question option

**URL:** <https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153>\
**Category:** The BBQ Pit\
**Created:** [February 17, 2012, 4:52pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153 "2012-02-17T16:52:00Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rhythmdvl](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Rhythmdvl](https://boards.straightdope.com/u/Rhythmdvl)\
**Post date:** [February 17, 2012, 4:52pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/1 "2012-02-17T16:52:00Z")

</div>

You’ve go to be fucking kidding me. Adding an open text field to allow me to enter something other than what’s easily found via the Internet isn’t that hard. Security theatre of the unsecure.

---

<div class="post-metadata">

**Author:** ![Kimballkid](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@Kimballkid](https://boards.straightdope.com/u/Kimballkid)\
**Post date:** [February 17, 2012, 4:57pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/2 "2012-02-17T16:57:22Z")

</div>

I can easily find the city I was born in or the make and model of the first car I had on the internet, but I really doubt anyone would know I had any connection to them.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 17, 2012, 5:10pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/3 "2012-02-17T17:10:23Z")

</div>

It’s a valid point though. We’re not supposed to use the same password in different places, so we shouldn’t be constrained to use the same security verification questions all over the place.

I’ve been asked for my mother’s maiden name so many times and places, I can’t seriously consider it an even slightly secure piece of information any more.

---

<div class="post-metadata">

**Author:** ![Kimballkid](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@Kimballkid](https://boards.straightdope.com/u/Kimballkid)\
**Post date:** [February 17, 2012, 5:20pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/4 "2012-02-17T17:20:07Z")

</div>

Yeah, **Mangetout** I see your point. But, for instance, you could always put in different names on the maiden name question on different sites. How are they going to know? I think web sites use the same ones to retain a level of consistency for the users who aren’t tech savvy or don’t want to spend a lot of time making up a question.

---

<div class="post-metadata">

**Author:** ![W0X0F](https://avatars.discourse-cdn.com/v4/letter/w/b77776/32.png) [@W0X0F](https://boards.straightdope.com/u/W0X0F)\
**Post date:** [February 17, 2012, 6:01pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/5 "2012-02-17T18:01:42Z")

</div>

It doesn’t even have to be wrong names. If the site is at all important (e.g. bank), I’m using those security questions as another password field and putting in the same scramble of alphanumeric and special characters as I would for a password. Sure, I don’t automatically remember it, but I’m using a password manager for all the different accounts I have anyway and this just becomes one more item in the list.

---

<div class="post-metadata">

**Author:** ![Dr.Drake](https://avatars.discourse-cdn.com/v4/letter/d/ad7895/32.png) [@Dr.Drake](https://boards.straightdope.com/u/Dr.Drake)\
**Post date:** [February 17, 2012, 6:05pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/6 "2012-02-17T18:05:10Z")

</div>

Sallie Mae, the education loan people, ask “what is your grandmothers maiden name?” No apostrophe (hey, we’re only in the business of education), but what really bothers me is that on the rare occasion I have to answer the question, I can never remember which grandmother I chose: like all humans, I have a maternal and a paternal grandmother, and like most people, they had different names.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [February 17, 2012, 6:08pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/7 "2012-02-17T18:08:37Z")

</div>

> [@Kimballkid](#):
>
> … you could always put in different names on the maiden name question on different sites…

It boggles me that people would actually do this - it’s like making up two passwords for each site. :eek:

This one site I went to a few weeks ago had security questions that either (a) did not apply to me, or (b) was so vague I couldn’t even begin to remember. The idea of creating our own security question+answer is a good one.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [February 17, 2012, 6:09pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/8 "2012-02-17T18:09:38Z")

</div>

> [@Dr.Drake](#):
>
> Sallie Mae, the education loan people, ask “what is your grandmothers maiden name?” No apostrophe (hey, we’re only in the business of education), but what really bothers me is that on the rare occasion I have to answer the question, I can never remember which grandmother I chose: like all humans, I have a maternal and a paternal grandmother, and like most people, they had different names.

The person who wrote that was Faye Dunaway’s kid from _Chinatown_, I bet.

---

<div class="post-metadata">

**Author:** ![Rhythmdvl](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Rhythmdvl](https://boards.straightdope.com/u/Rhythmdvl)\
**Post date:** [February 17, 2012, 6:12pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/9 "2012-02-17T18:12:05Z")

</div>

> [@W0X0F](#):
>
> It doesn’t even have to be wrong names. If the site is at all important (e.g. bank), I’m using those security questions as another password field and putting in the same scramble of alphanumeric and special characters as I would for a password. Sure, I don’t automatically remember it, but I’m using a password manager for all the different accounts I have anyway and this just becomes one more item in the list.

:smack: Good idea. Much better than petulantly answering “what was your childhood nickname?” _Fuckyou_; “what was your grammar school?” _Fuckyouelementary_ and so on. Habit changes today.

---

<div class="post-metadata">

**Author:** ![Unpronounceable](https://avatars.discourse-cdn.com/v4/letter/u/9de0a6/32.png) [@Unpronounceable](https://boards.straightdope.com/u/Unpronounceable)\
**Post date:** [February 17, 2012, 6:47pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/10 "2012-02-17T18:47:43Z")

</div>

I think the favorite one I’ve seen was:

> [@](#):
>
> Please answer the following security question to recover your password:  
> _For security reasons, all security questions have been removed_  
> A:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_

Yeah, that helps, guys.

---

<div class="post-metadata">

**Author:** ![percypercy](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@percypercy](https://boards.straightdope.com/u/percypercy)\
**Post date:** [February 17, 2012, 7:10pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/11 "2012-02-17T19:10:30Z")

</div>

My aunt always puts the name of her Shar Pei in the “what was the name of your first pet?” even though he wasn’t the first or last pet she’s owned just the most memorable. A lot of the security questions ask for more than three letter answers, but that’s not going to work if the answer only has three letters say Jon or May for example.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 17, 2012, 7:56pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/12 "2012-02-17T19:56:35Z")

</div>

> [@Kimballkid](#):
>
> Yeah, **Mangetout** I see your point. But, for instance, you could always put in different names on the maiden name question on different sites. How are they going to know?

Well, you could, but then you’ve just got to remember what you put there, with no meaningful prompt. The whole point of security questions is that they’re meant to be triggers to something you _already remember_ - and thus useful for retrieving accounts when you’ve forgotten the password you just made up.

> [@](#):
>
> I think web sites use the same ones to retain a level of consistency for the users who aren’t tech savvy or don’t want to spend a lot of time making up a question.

Probably, but that’s like saying people should leave the door key under the mat if they don’t fancy carrying it around. It’s supposed to be a security measure.

---

<div class="post-metadata">

**Author:** ![GargoyleWB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gargoylewb/32/199_2.png) [@GargoyleWB](https://boards.straightdope.com/u/GargoyleWB)\
**Post date:** [February 17, 2012, 8:04pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/13 "2012-02-17T20:04:18Z")

</div>

I just use the same easy-to-remember word for everything across all websites. For example…

What is your mother’s maiden name?  
wallaby  
What town were you born in?  
wallaby  
What is your favorite color?  
wallaby

…and so on. I’ve only come across one site so far (damn you HR Block!) that annoyingly rejects duplicates.

---

<div class="post-metadata">

**Author:** ![ZipperJJ](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zipperjj/32/211_2.png) [@ZipperJJ](https://boards.straightdope.com/u/ZipperJJ)\
**Post date:** [February 17, 2012, 8:05pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/14 "2012-02-17T20:05:00Z")

</div>

I got really mad at a security question interface once because it refused to recognize my best friend’s name as a valid answer to “What is your best friend’s last name?” I was like “I’ve had the same best friend for 15 years! How could it be anything else?! Fuck, is he mad at me or something?”

---

<div class="post-metadata">

**Author:** ![Cheshire\_Human](https://avatars.discourse-cdn.com/v4/letter/c/5f8ce5/32.png) [@Cheshire\_Human](https://boards.straightdope.com/u/Cheshire_Human)\
**Post date:** [February 17, 2012, 8:10pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/15 "2012-02-17T20:10:19Z")

</div>

I’ve never seen a security question my brother couldn’t answer. What about someone who has a lying, stealing leech for a brother? I can make up a security question that _no one_ but me could answer, but that I could answer in my sleep. Why can’t I use it?

---

<div class="post-metadata">

**Author:** ![panache45](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/panache45/32/64_2.png) [@panache45](https://boards.straightdope.com/u/panache45)\
**Post date:** [February 17, 2012, 8:31pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/16 "2012-02-17T20:31:14Z")

</div>

> [@Dr.Drake](#):
>
> Sallie Mae, the education loan people, ask “what is your grandmothers maiden name?” No apostrophe (hey, we’re only in the business of education), but what really bothers me is that on the rare occasion I have to answer the question, I can never remember which grandmother I chose: like all humans, I have a maternal and a paternal grandmother, and like most people, they had different names.

I can neither spell nor pronounce the maiden names of either of my grandmothers.

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [February 17, 2012, 8:31pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/17 "2012-02-17T20:31:21Z")

</div>

Since I save all my passwords in a password program, I’ve started treating my answers to security questions as extra passwords: I make up random answers and write down those answers too.  
e.g.  
What is your Mother’s maiden name?  
A: Q1aSU4KasZkPEm5qW1ojmVxPMPyUK9

---

<div class="post-metadata">

**Author:** ![digs](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/digs/32/14889_2.png) [@digs](https://boards.straightdope.com/u/digs)\
**Post date:** [February 17, 2012, 8:37pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/18 "2012-02-17T20:37:36Z")

</div>

> [@Kimballkid](#):
>
> Yeah, **Mangetout** I see your point. But, for instance, you could always put in different names on the maiden name question on different sites. How are they going to know? I think web sites use the same ones to retain a level of consistency for the users who aren’t tech savvy or don’t want to spend a lot of time making up a question.

Hmmm, wonder if they’d notice that my mom’s name used to be “Sally VanVisa” on my cc site, and “Sally VanDope”, “Sally VanHoldem” and “Sally VanDigimonPron” on others…

---

<div class="post-metadata">

**Author:** ![DocCathode](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doccathode/32/18773_2.png) [@DocCathode](https://boards.straightdope.com/u/DocCathode)\
**Post date:** [February 17, 2012, 8:43pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/19 "2012-02-17T20:43:55Z")

</div>

Anybody who knows how my mind works could answer all my online security questions\*. Knowing actual data on me (city I was born, high school I graduated from) would be useless.

What was my first car? Batmobile.

Favorite teacher? Doctor Strangelove.

Childhood pet? Krypto.  
OTTOMH, I can’t think of any place online that requires a security question of me that actually matters. I don’t bank online. I don’t belong to a data back up site. I think Yahoo mail, Facebook and the rest don’t qualify as important.

---

<div class="post-metadata">

**Author:** ![ComeToTheDarkSideWeHaveCookies](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@ComeToTheDarkSideWeHaveCookies](https://boards.straightdope.com/u/ComeToTheDarkSideWeHaveCookies)\
**Post date:** [February 17, 2012, 8:46pm UTC](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153/20 "2012-02-17T20:46:44Z")

</div>

The fraudsters trying to steal your personal information certainly give you the ‘roll your own’ option in their phishing pages. Another example of how the web app pipeline of the underbelly is often better than at many legit companies…

[Next page](https://boards.straightdope.com/t/website-security-questions-with-no-add-your-own-question-option/613153.md?page=2)
