Brokerage login now requiring I answer these questions. Not a single one of these has a single answer I’d actually remember. They all have problems regarding what would actually count or multiple possible answers to choose from, or these are not things people would remember or they just don’t apply to most people.

  • Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    84
    ·
    1 day ago

    Just make the answers diceware passwords and store them in your password manager.

    • fulg@lemmy.world
      link
      fedilink
      English
      arrow-up
      46
      arrow-down
      1
      ·
      edit-2
      1 day ago

      This is the right answer. I never answer those, you add new entries in your password manager in the notes for the main site.

      If you answer truthfully to any one of those “security questions”, your account is at risk.

        • fulg@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 hour ago

          TIL about hidden options in Bitwarden, thanks!

          I of course already use the password generator to make up the random string, and often you can’t use special characters there since they expect real words as answers.

        • lurch (he/him)@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          I just make an extra entry in KeePass with a suffix and different icon. I treat the answer just like an additional password and put the question as username or in the notes.

      • IHawkMike@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        ·
        24 hours ago

        It’s unlikely since it uses the field ID and not the text, so it wouldn’t know which question went with which answer.

        It’s so rarely needed to actually use these anyway, that it’s a non-issue IMO. You should never opt to use security questions as they are terrible from a security standpoint. This is just for when they are required by stupid websites.