Disinfo: 'Forget Your Password?' May Be The Weakest Link

MSNBC points out that the ubiquity of sites like Facebook and Myspace have rendered password resets based on personal questions dangerously insecure:

As an experiment, Herbert Thompson, chief security strategist of People Security, recently asked a few friends for permission to hack into their bank accounts. Using only information gathered from Web sites, Thompson found his way in within minutes. How?

After clicking on the familiar "Forgot your password?" link, one can access online accounts by entering your pet's name, identifying a high school mascot, or answering some other seemingly obscure questions. But there's a problem: A criminal can do that, too. With the help of social networking sites like Facebook and MySpace, personal trivia is getting less obscure all the time. You'd be surprised how easily someone can uncover Fido's name or your alma mater with a little creative searching.


Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <i> <b> <strong> <br> <hr> <h2> <h3> <h4> <embed> <object> <param>
  • Lines and paragraphs break automatically.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options