On TV.com: Latest DEXTER Renewed My Faith
BNET Business Network:
BNET
TechRepublic
ZDNet

May 19th, 2009

Study: password resetting 'security questions' easily guessed

Posted by Dancho Danchev @ 5:41 am

Categories: Browsers, Hackers, Passwords, Phishing, Social Networking Applications, Web 2.0

Tags: Password, Security Question, Security, Dancho Danchev

How secret are in fact the ’secret questions’ used for resetting forgotten passwords? Not so secret after all, according to a just published study entitled “It’s no secret: Measuring the security and reliability of authentication via ’secret’ questions” according to which 17% of the study’s participants were not only able to answer the ’secret questions’ of strangers, but also, that the most popular questions were in fact the easiest ones to answer.

Here’s an abstract from the study presented at this year’s IEEE Symposium on Security and Privacy, by Stuart Schechter, A. J. Bernheim Brush, and Serge Egelman :

“We ran a user study to measure the reliability and security of the questions used by all four webmail providers. We asked participants to answer these questions and then asked their acquaintances to guess their answers. Acquaintances with whom participants reported being unwilling to share their webmail passwords were able to guess 17% of their answers. Participants forgot 20% of their own answers within six months. What’s more, 13% of answers could be guessed within five attempts by guessing the most popular answers of other participants, though this weakness is partially attributable to the geographic homogeneity of our participant pool.”

Moreover, upon assessing the memorability of the ’secret questions’, the user study involving 130 participants (64 male and 66 female) also found out that the harder ones to guess were also the hardest ones to remember.

Two similar recently conducted studies confirm these findings. For instance, in “Choosing Better Challenge QuestionsMike Just and David Aspinall found out that users also tend to stick to low entropy answers which are potentially vulnerable to brute forcing attacks. The researchers came to the same conclusion in their second study “Challenging Challenge Questions” pointing out that given the average answer length of less than 8 characters, the authentication system relying upon only a single security question is highly vulnerable to brute force attack.

And whereas brute forcing attempts against the security questions is a feasible attack tactic, malicious attacks tend to be a little bit more pragmatic than that, especially in a Web 2.0 world where the majority of their potential victims have already unconsciously/consciously published the answers to their security questions on the Web.

Case in point - the applicability of their findings can be confirmed through real-life incidents. For instance, the Sarah Palin hacker managed to reset her password by Googling for the answer to her ’secret question’, followed by two similar password resetting attacks aimed at Twitter employees throughout the past one year. Moreover, a huge percentage of the commercial ‘password recovery services‘ or email hacking for hire propositions rely on password resetting attacks next to the plain simple malware infection, and attempt to exploit a XSS flaw within a particular web based email service provider.

All of these findings, combined with the misalignment of the end user’s perception of security offered by security questions and the extend to which the answers have already been made public, can be summarized with a single security tip - make sure that you don’t tweet about how much fun you had on your honeymoon in Paris a couple of years ago, when your security question is “Where did you spend your honeymoon?“, which you would have presumably answered correctly.

What do you think, are security questions a viable form of authentication? Talkback.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 19 Talkback(s)
Simple question CAN be hard to guess
Take, for example, your car registration number, perhaps followed by a special character & then a short passphrase. Even better, your first car's registration number, or your last car's registration n... (Read the rest)
Posted by: d.s.williams Posted on: 10/09/09 You are currently: a Guest | | Terms of Use
Always been questionable.  CobraA1 | 05/19/09
RE: Study: password resetting 'security questions' easily guessed  Oorang | 05/19/09
RE: Study: password resetting 'security questions' easily guessed  DWN1956 | 05/19/09
RE: Study: password resetting 'security questions' easily guessed  u0107@... | 05/20/09
RE: Study: password resetting 'security questions' easily guessed  thirdteam | 05/20/09
Addendum to initial comment  thirdteam | 05/20/09
Pass on Security Questions  rontiara | 05/20/09
The state of society  thirdteam | 05/20/09
RE: Study: password resetting 'security questions' easily guessed  CTHarris@... | 05/20/09
Response to question of remembering  thirdteam | 05/20/09
What do you think, are security questions a viable form of authentication?  S60_alan | 05/20/09
institutions avoid upgrade costs at our expense  Sticksandstones | 05/20/09
RE: Study: password resetting 'security questions' easily guessed  canoeak@... | 05/20/09
Sheesh, we've got fingerprint scanners in 8m HP consumer laptops next year  SecurityThroughObscurity | 05/20/09
Fingerprint scanners?  LiLac22281 | 05/21/09
RE: Study: password resetting 'security questions' easily guessed  twaynesdomain | 05/21/09
RE: Study: password resetting 'security questions' easily guessed  tu3k | 05/30/09
RE: Study: password resetting 'security questions' easily guessed  tgupta80@... | 06/01/09
Simple question CAN be hard to guess  d.s.williams | 10/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More