Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

Hosting Discussion > Web Hosting Forums > Web Hosting Discussion > Best security questions to ask
forgot password?


Reply


Old
  Post #1 (permalink)   06-29-2009, 05:37 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
Hey there folks,

We just updated our billing system over the weekend to the new WHMCS 4.0.x branch and along with the new version came security questions that we can ask customers. In the past we asked any number of things such as "mothers maiden name" and "last 4 digits of SSN numbers" and various other questions.

What are your top questions that you ask when people forget login information etc?

I found a pretty informative site listing a number of the top questions and their comparisons as to whether they're Safe, Memorable and Stable etc. Asking the question, "What's your favorite color" doesn't hold much weight given that there are limited colors and people's minds change over time. So what kinds of questions are you guys asking customers or do you even bother with this extra security check?

Here's a link to that site I was reading: http://www.goodsecurityquestions.com/compare.htm
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #2 (permalink)   06-29-2009, 06:46 PM
HD Guru
 
HostLeet's Avatar
 
Join Date: May 2009
Location: Florida, USA
Posts: 625

Status: HostLeet is online now
I think "What's your pet's name?" is a good one.
__________________
HostLeet.Com LLC - Fully Managed WebSite Hosting Services & Domain Names!
cPanel - LiteSpeed - CloudLinux - Softaculous Auto-Installer - 24/7/365 Support
60-Day RISK FREE Money Back Guarantee - 99.9% Uptime Guarantee - Daily Backups
Register Domain Names - Secure Payment Options - Read Our Most F.A.Q's HERE!
 
 
 


Old
  Post #3 (permalink)   06-29-2009, 09:11 PM
HD Wizard
 
romes's Avatar
 
Join Date: Feb 2007
Location: IL
Posts: 1,444
Send a message via MSN to romes

Status: romes is offline
I think any question relating to personal information is no good. Your mothers maiden name, pets name, etc. are really bad questions. Hackers use these types of questions to their advantage all the time.


Asking the person for a secret phrase, or what ever is a better question as the hacker will never know this unless the person leaks the information out himself.


Also, thanks for the link conor.
__________________
RomesBlog.net | Xbox 360 Gaming Articles, Add-ons, New Releases and Much More!
Gaming Directory | Directory on the blog | Great source of traffic! | Reciprocal Link for PR2+ Sites | Advertise for FREE!
 
 
 


Old
  Post #4 (permalink)   06-30-2009, 08:55 AM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
Yeah, there's SO much information available on FaceBook and MySpace which is freely available to many people it got me thinking about security questions.

People often post pictures of their kids (along with names), pictures of pets (and names) and with some minor looking around you can find out what highschool they went to, and best friends in school/college etc.

The phrase option is nice, but how often are you presented with that when you just put in something, then quickly forget it?

Email addresses change, and stuff that would be "constant" is easily searchable on the web (especially those little survey things people make up on Facebook.

Who remembers their Maternal Grandmother's Maiden name? Email addresses change often for people too - so just trying to think of what can be used
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #5 (permalink)   06-30-2009, 09:28 AM
HD Wizard
 
SenseiSteve's Avatar
 
Join Date: Mar 2009
Location: Saint Louis
Posts: 3,778
Send a message via MSN to SenseiSteve

Status: SenseiSteve is online now
Quote:
What is the first name of the boy or girl that you first kissed?
I think this is pretty memorable - very personal - not widely known or disseminated. I've seen some very strange security questions lately - which is a good thing.
__________________
Hands-On Web Hosting
cPanel Web Hosting, Domain Registration, Managed VPS Servers
Infusing Markets LLC - A Digital Interactive Marketing Firm
 
 
 


Old
  Post #6 (permalink)   06-30-2009, 03:34 PM
HD Wizard
 
romes's Avatar
 
Join Date: Feb 2007
Location: IL
Posts: 1,444
Send a message via MSN to romes

Status: romes is offline
Well, some people have a phrase only they use or know so that is something they can use. Also, it is just common sense if you use something that you just made up on the spot to save in a .txt and store on your computer or external drive.
__________________
RomesBlog.net | Xbox 360 Gaming Articles, Add-ons, New Releases and Much More!
Gaming Directory | Directory on the blog | Great source of traffic! | Reciprocal Link for PR2+ Sites | Advertise for FREE!
 
 
 


Old
  Post #7 (permalink)   06-30-2009, 04:44 PM
CSN-UK | Charlie
 
csn-uk's Avatar
 
Join Date: Mar 2009
Location: Swindon (UK)
Posts: 470
Send a message via MSN to csn-uk

Status: csn-uk is offline
one that iv seen used and favor towards is the good old "what are the x and y characters of your pasword" replaceing x and y with a number so for example:

Password: HostingDiscussion
Quesion "what is the 2nd and 6th letter of your password"
Answer "o and n"

It isent particually usefull if they cannot remember their password however the number can be changed dependant on the users password however 2 random letter chocies should be used where possible.

Works well on live support and via phone, both Norton, Orange, and O2 utalise the same quesion if not a variation of it.
__________________
CSN-UK | Shared Hosting | Dedicated | VPS | Custom Packages Avalible On Request | Quality SSL Certificates from COMODO CA
CSN-UK.net | Server Status | Client Area | Live Support
 
 
 


Old
  Post #8 (permalink)   06-30-2009, 11:55 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
Yeah, the "last 4 digits/letters of the password" we often use in live help etc... or if it's technical support they're already logged into our billing/support system already and that does the verification for us.

The main thing that we were seeing is the password reminders or "i forgot my password" type scenarios.

The "kissing" security question I've seen that a few times, along with "first crush" and "first employer".

I just can't get over how FREE people are with their information some times. The security questions at the banks are worse than pathetic - "what city were you born in" or "mothers maiden name" and my favorite "what is your phone number" - yes, that REALLY was a question at a Credit Union I belonged to. They've since removed it, but it was SO awful!

Security is always at the forefront of my mind - good and bad. Hopefully someone's brain is kicking into gear with how they address these sorts of issues in their own organization.
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #9 (permalink)   07-01-2009, 10:26 PM
HD Newbie
 
Join Date: Jun 2009
Posts: 12

Status: neo666 is offline
i write my own questions..<..>
 
 
 


Old
  Post #10 (permalink)   07-02-2009, 08:29 AM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
Care to share any of them?
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: