Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Social Engineering is a thing to watch out for. I've learnt to never answer honestly when they're asking stuff like "Where were you born?" "What's your first pet" etc.

Instead I've made up some answers that I'll never tell anyone else.

However that doesn't really make those details secure. 2FA is where it's at.



Yeah you can just scroll through someone's Facebook account for 'secret' answers. They're bound to have answered one of those "Your porn star is your first pet's name followed by the street you grew up on" things


I store them as a "note" in my password manager, all generated passwords that have no basis in reality.


> Instead I've made up some answers that I'll never tell anyone else.

You should make up some answers like ighe9Chik9oorooy. That's what I do.


Yes. My first girlfriend is ntnOFT(#9TNSONROe.

I'll never forget you, ntnOFT(#9TNSONROe. We had such good times together.


A (random) English word is a better answer. Otherwise you can be phished by someone communicating with a phone rep.

"For security what's your pet's name?"

"I don't have a pet, I just put a bunch of random characters."

--

Due to implementation these questions are actually sometimes hard to answer truthfully sometimes. My fav teacher has a . in her name but "special characters" are not allowed in answers. My pet's name is 4 characters, too short. How did I answer my first car? Year, make, model? Make? Year and model? Just model? Who can remember?


Only, how is the phisher supposed to know that I used a randomized password?


1) Guess

2) The HN post I replied to.


Yeah, I use lastpass for my passwords, and another application for 2FA... I get REALLY suspicious when a site isn't in my lastpass.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: