<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: What is my favorite movie?!!</title>
	<link>http://www.tssci-security.com/archives/2007/04/04/what-is-my-favorite-movie/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Sat, 11 Oct 2008 12:38:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Scott Roberts</title>
		<link>http://www.tssci-security.com/archives/2007/04/04/what-is-my-favorite-movie/#comment-304</link>
		<dc:creator>Scott Roberts</dc:creator>
		<pubDate>Thu, 05 Apr 2007 01:15:11 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/04/04/what-is-my-favorite-movie/#comment-304</guid>
		<description>I say we all move to epic pass poems. Much harder to fake. What attacker memorized all of the Illiad just to steal $20 from my bank account?</description>
		<content:encoded><![CDATA[<p>I say we all move to epic pass poems. Much harder to fake. What attacker memorized all of the Illiad just to steal $20 from my bank account?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://www.tssci-security.com/archives/2007/04/04/what-is-my-favorite-movie/#comment-302</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Wed, 04 Apr 2007 16:25:09 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/04/04/what-is-my-favorite-movie/#comment-302</guid>
		<description>Yeah, I'm not sure why people think asking security questions is a good idea. Maybe for very small instances, it sounds ok, but it scales even worse than passwords and usernames and PINs.

Bank of America asks a set of 5 questions. Bank of Canada asks another set of 5 questions. If you pick the same one for each, you've done nearly nothing to combat the fraud that still occurs more than people admit: perpetrated by friends/family that know those answers or can get them.

I also hate those, "Who was your favorite teacher?" questions. That depends on my mood when you ask me...or what I've been thinking about recently. And when you've been to 12 years of schooling in some good classes and 5 years of college...you get a LOT of choices to muck through!

Sadly, the question I typically pick has to do with my pet's name or my first dog's name. I don't have a pet other than fish and have never, myself, owned a dog. I use my parent's dog's name because at least in my mind, that won't even change. (Mother's maiden name doesn't often change either, but I used to get confused because my mom has remarried since I was born, so do I use the original or the second...?)

:) But yes, I universally hate challenge questions unless they can give me the same question every time (or let me write my own). But that's just not useful.</description>
		<content:encoded><![CDATA[<p>Yeah, I&#8217;m not sure why people think asking security questions is a good idea. Maybe for very small instances, it sounds ok, but it scales even worse than passwords and usernames and PINs.</p>
<p>Bank of America asks a set of 5 questions. Bank of Canada asks another set of 5 questions. If you pick the same one for each, you&#8217;ve done nearly nothing to combat the fraud that still occurs more than people admit: perpetrated by friends/family that know those answers or can get them.</p>
<p>I also hate those, &#8220;Who was your favorite teacher?&#8221; questions. That depends on my mood when you ask me&#8230;or what I&#8217;ve been thinking about recently. And when you&#8217;ve been to 12 years of schooling in some good classes and 5 years of college&#8230;you get a LOT of choices to muck through!</p>
<p>Sadly, the question I typically pick has to do with my pet&#8217;s name or my first dog&#8217;s name. I don&#8217;t have a pet other than fish and have never, myself, owned a dog. I use my parent&#8217;s dog&#8217;s name because at least in my mind, that won&#8217;t even change. (Mother&#8217;s maiden name doesn&#8217;t often change either, but I used to get confused because my mom has remarried since I was born, so do I use the original or the second&#8230;?)</p>
<p>:) But yes, I universally hate challenge questions unless they can give me the same question every time (or let me write my own). But that&#8217;s just not useful.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.160 seconds -->
