Insecurity questions
December 12th, 2007 by Benjamin KuoI have recently been filling out “secondary security” questions from various online financial providers, and have been quite disturbed to find that lots (if not all) of the questions I’ve been asked have been the exact same information I’ve been asked to post to social networking sites like Facebook. For example: What high school did you go to? What city were you born in? What’s your birthday? What are the names of your pet? What’s your favorite color? What’s your favorite book?

December 12th, 2007 at 4:16 pm
Good point. I have been concerned that the services which use these 2 factor authentication techniques will ultimately all share the same information, and so the security that the 2nd factor adds will diminish over time. My preferred method are the RSA tokens. They are much more costly than a pure software/information based method, so banks shy away from them.