If you access web-based services such as social networking websites, message forums, or online banking applications, you've probably had to register for a user account. This sometimes drawn-out process required you to enter a login name as well as a password (or get one assigned to you), providing some sense of security when accessing the service.
Since good passwords (not the words 'computer' nor 'secret') can be almost impossible to remember (such as a ten character combination of letters, numbers, and punctuation), many services now use a "security question" you can answer in case you forget your username and/or password and need to retrieve or reset them. By offering a security question, these services can help ensure it is really you when a request is made for your login information.
Some websites may even require answering this security question as well as your password every time you use their services, offering a supposed second level of account security.
Security questions are normally facts that supposedly only you can recall, information that should not change. Several common examples are listed below:
* First School Attended
* Mother's Maiden Name
* Name of First Pet
* Where a Spouse was First Met
Some websites force you into answering a predefined question, a popular one being your mother's maiden name. Others offer a list of questions from which you may choose, but some may allow you to type your own questions and answers. This allows you to enter private information such as the name of your favorite musical group, the name you gave a pet rock, or the celebrity poster you placed on your wall as a kid.
Unfortunately, the answers to some security questions are well-known, easy guessed, can be obtained online, or can be found via public records or a private investigator (and if someone truly wants access to your account they may go through a lot of trouble). Thus, these questions, while provided to either offer a second level of security or remove the need for customer service representatives to otherwise verify identity when you request a new password, can cause all sorts of trouble.
Especially if only a security question is required to obtain or reset a password, or even a combination of a security question and other pieces of personal information, if someone can guess or obtain the answers to your questions, it is open season on your account!
This type of secret question and answer hacking can and has affected many individuals, including famous people. As an example, according to reports, 2008 Republican Vice-Presidential candidate Sarah Palin had her e-mail account breached when someone allegedly answered a few questions during a password reset request. The questions were her birthday, zip code, and where she met her spouse (Wasilla High), information available on the web or easily guessed.
Now that you know how easy it may be for others to access your account via a security question, what can you do to help protect yourself?
* If offered the choice, pick the most obscure security question offered or type your own question and answer if this feature is available. Pick something you and only you may know - something you are positive is not available in public records, your Facebook page, or elsewhere online. Never use your mother's maiden name, social security number, or birthplace, as these can either be found or cause other security and privacy problems if someone does hack the account and read the answers to your security questions.
* Use different security questions for each and every service. No matter how secure you make your account, it can get hacked due to lackluster security procedures of the web service provider or even due to an inside job. Someone could read the answers to your security questions and use these to gain access to your accounts on other websites!
* Consider treating your security question's answer as a second password. You can either encrypt the answer by replacing the letter 'O' with a number 0, the letter 'l' with a number 1, the letter 'a' with the @ symbol, etc., though as dictionary attacks become more advanced this may become less effective. Or "go crazy" and create nonsensical answers just like your passwords as a combination of letters, numbers, and punctuation symbols.
The downside to this method is that your answer may be impossible to remember so you'll have to store it somewhere. And if you do forget your security question answer or cannot find it, you may never be able to reset your password! As a best case scenario you might be able to call customer service or send a copy of your ID to prove your identity. These processes could take a long time, problematic if, for example, you need to use an online banking service to pay your utilities bill today. And remember that some sites may require you to answer your security question every time you login, not just if you forget your password.
While website user account security used to revolve around just a login ID and a password, security questions have become very commonplace, especially as user verification when retrieving a lost password. If you are forced to answer such a question, try to pick the most obscure information possible so it is not easily guessed or found. Use different security questions on each and every website in case your account does get hacked and your answers read. Finally, consider treating your security question as a second password, making it cryptic thus difficult to hack. Security questions have become a modern fact of life on the Internet, so learn how to use them to your advantage.
Copyright 2009 Andrew Malek.
- Related Videos
- Related Articles
- Ask / Related Q&A
- Avoiding Identity Theft: Critical Steps Every Individual Must Take
- Avoiding Identity Theft: Critical Steps to Take
- Online Security and Identity Theft 101
- A Better Way To Stop Identity Theft
- Winning The Fight Against Identity Theft With Fraud Alert
- Learn About Identity Theft - 6 Tips To Safeguard Your Interests
- Identity Theft is Gonna Getcha
- Protecting yourself against Identity Theft




How To Make Fast Money Online Legally
By: Annette Lode | 07/01/2010Especially with the economy the way it currently is, and the unemployment rate being 10%; more and more people are turning to the World Wide Web to try and earn their dream income. While it is true that there are a lot of ways to make fast money online legally on the net, like all things it will take some amount of work.
Give Value With Your Online Content to Create Internet Business Relationships
By: Phyllis Zimbler Miller | 07/01/2010I read Internet marketing and Internet business material continually, and one of the most frequent phrases I see can be summed up as: "Give value to your prospective customers." What does this mean?
How Keyword Ranking Can Make You Money
By: Riley West | 06/01/2010People search for all kinds of things on Google and the search terms (keywords-keyword phrases) are what they use to search for information and things. What you want is to know what that searcher is looking for and give it to them! How do you do that? It's not nearly as hard as you think, and it's the way all the masters get their pages to the top for their selected keywords.
Google Adsense Affiliate Program
By: Pasi Kaarakainen | 06/01/2010Having an internet home business of your own means you get to work online whenever you want and do it somewhere in your home. There are many ways to go about this, but one way many internet business owners make money is to promote the Google Adsense affiliate program.
Success In Affiliate Marketing for Newbies Depends On Good Research
By: Suzanne E Morrison | 06/01/2010These are just a few things to consider for affiliate marketing for newbies. If you conduct proper research in advance and put together a good plan you can have great success in affiliate marketing.
McAfee's Cybercrime Predictions
By: Rex Camposagrado | 06/01/2010In McAfee's 2010 report, the cyber security major stated that, it expects cybercriminals to target social networking sites and third-party applications and use more complex Trojans and botnets to build and execute attacks, and take advantage of HTML 5 to create emerging threats. The company is of the opinion that 2010 will be a good year for law enforcement’s fight against cybercrime.
New Black Box Internet Marketing System For 2010
By: Neville Easley | 06/01/2010The New Black Box Internet Marketing System For 2010 from Carbon Copy Pro will revolutionize how marketing is proceeded online. For any Internet Marketer who is currently searching for additional ways to expand their Business. This professional marketing manual will enable you to overcome any obstacle related to internet marketing.
How You Can Get More Traffic to Your Website
By: Samuel Dillehay | 06/01/2010This article focuses on using article writing to get more traffic to your website.
5 Things to Do as Soon as You Purchase a New Computer
By: Andrew Malek | 13/03/2009 | ComputersHave you just purchased a new desktop or laptop computer? Congratulations, and hopefully you will get plenty of use out of your new machine, whether it is for business, finance, research, multimedia, or purely entertainment (or a little of all the above). But wait - don't open the boxes, plug in...
7 Reasons People Tell You Not to Switch Web Browsers
By: Andrew Malek | 13/03/2009 | InternetWhen you purchased your computer or installed a new operating system, more than likely it came bundled with a web browser such as Internet Explorer or Apple Safari. While this browser seems to offer all the features you need when surfing the Internet, other alternatives exist such as Mozilla Firefox,...
Why Should You Buy a Desktop PC?
By: Andrew Malek | 10/03/2009 | ComputersPeople are always "on the go" these days, and the convenience of a laptop computer fits with our busy schedules. Thus it makes sense that depending on several analyst reports, more people worldwide choose to purchase laptops instead of desktops. With today's popularity of netbooks, tablet PCs, and digital media...
7 Reasons Why Computers Run Slower As They Get Older
By: Andrew Malek | 10/03/2009 | ComputersIt never fails - awhile back, perhaps it was a few years, perhaps it was only a few months, you bought a new super-fast, top-of-the-line desktop or laptop computer. At first it ran fantastic - there were few software crashes, browser pages visually popped onscreen, and games ran smoothly at...
Why Security Questions Can Be Bad News
By: Andrew Malek | 09/03/2009 | InternetIf you access web-based services such as social networking websites, message forums, or online banking applications, you've probably had to register for a user account. This sometimes drawn-out process required you to enter a login name as well as a password (or get one assigned to you), providing some sense...
Pros and Cons of Using Free Web-Based Email Providers
By: Andrew Malek | 08/03/2009 | InternetNowadays, more Internet users are turning away from software-based e-mail programs run on their own computers such as Outlook and Windows Mail and towards web-based e-mail services like Yahoo! Mail, Google's Gmail, and Microsoft's Hotmail. Some sign onto free e-mail services just for their personal accounts and access software-based e-mail...
7 Ways to Get the Most From Your Older Digital Camera
By: Andrew Malek | 08/03/2009 | ComputersNewer digital cameras may allow for faster exposures, larger printouts by taking photos with more megapixels, and increased photographic opportunities with enhanced zoom capabilities. While new digital cameras seem to be released every month, with today's worrisome economy it may not be possible to take advantage of these technological advancements. Though...