<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;What is the risk of this?&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/What-is-the-risk-of-this-27772612</link>
<description></description>
<language>en</language>
<pubDate>Sat, 18 May 2013 19:53:34 EDT</pubDate>
<lastBuildDate>Sat, 18 May 2013 19:53:34 EDT</lastBuildDate>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783714</link>
<description><![CDATA[Snowy posted : <div class="bquote"><said>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</said><p><div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p> It wasn't until there was movement in Congress to assert the privacy of SSNs that such practices faded away. But until Congress moved, no amount of rhetoric could persuade the organization or the state to change their practices.<br> </p></div>it sorta happened overnight, except for the example I cited which happened about 3 years ago.<br> </p></div>I can make a calculated guess @ what you were eating that day.<br>I'd even say how many slices you had but with much less certainty. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783714</guid>
<pubDate>Mon, 03 Dec 2012 13:53:38 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783614</link>
<description><![CDATA[EGeezer posted : <div class="bquote"><said>said by anon user :</said><p>I can't change the password to my account on a site with out clicking on <b>Forgot user name and password</b>, and then answering the security questions - even while I know the correct user name and password.<br><br>What is the security risk of that?<br><br></p></div>It's less risk than being able to change the password without having to provide the answers. <br><br><div class="bquote"><said>said by <a href="/profile/795407" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=795407');">Snowy</a>:</said><p>What would you hear if you asked The Teenage Mutant Ninja Turtles what is their favorite food?<br></p></div>Turtle soup. <br><br><small>--<br>Buckle Up. It makes it harder for the aliens to suck you out of your car.<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783614</guid>
<pubDate>Mon, 03 Dec 2012 13:29:55 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783517</link>
<description><![CDATA[AVD posted : <div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p> It wasn't until there was movement in Congress to assert the privacy of SSNs that such practices faded away. But until Congress moved, no amount of rhetoric could persuade the organization or the state to change their practices.<br> </p></div>it sorta happened overnight, except for the example I cited which happened about 3 years ago.<br><small>--<br>* seek help if having trouble coping<br>--Standard disclaimers apply.--</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783517</guid>
<pubDate>Mon, 03 Dec 2012 13:07:34 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783453</link>
<description><![CDATA[dave posted : <div class="bquote"><said>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</said><p>and you miss my point. The trick is to answer those questions in an non obvious way. <br> </p></div>That's ok if you often use the same unobvious way.  But I find if I get too creative, it's harder to remember my lies than it is to remember the actual password, thus rendering it pointless.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783453</guid>
<pubDate>Mon, 03 Dec 2012 12:51:56 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783316</link>
<description><![CDATA[Blackbird posted : <div class="bquote"><said>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</said><p><div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p><div class="bquote"><said>said by anon user :</said><p>...That is what they do, but they only ask for: Social Security Number, Birth Date as MMDD and Last Name Including Suffix (Example Smith Jr)<br>So, how safe/risky is it - what they are doing?<br></p></div>Are you an employee of the organization? That is, is this an access portal into the company network?<br> </p></div>My company used the full 9 digit SSN to validate initial signups to an internet based benefits portal. I think saner heads prevailed.<br> </p></div>An organization I once was part of used SSNs for their employee ID numbers... and then put those numbers on the face of the badges. Ditto for this state using the SSN for your driver's license ID number. It wasn't until there was movement in Congress to assert the privacy of SSNs that such practices faded away. But until Congress moved, no amount of rhetoric could persuade the organization or the state to change their practices. Using a SSN for ID over the Internet is just plain wrong.<br><small>--<br>&#147;The American Republic will endure until the day Congress discovers that it can bribe the public with the public's money.&#148; A. de Tocqueville</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783316</guid>
<pubDate>Mon, 03 Dec 2012 12:12:33 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783249</link>
<description><![CDATA[AVD posted : <div class="bquote"><said>said by <a href="/profile/724762" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=724762');">Kilroy</a>:</said><p><div class="bquote"><said>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</said><p>pizza<br>pizza<br>pizza<br>bronx, ny<br> </p></div>All fine until you get to the sites that require six characters in your answers and won't allow any two to be the same.<br><br>Back to the OP, the security risk is that someone who knows you well may know the answers to your security questions.  This is the issue I have with this method of password resets.  What is stopping your soon to be ex from hijacking your accounts and making your life a little more miserable?  Forget the fact that most of these questions can be answered by using someone's Facebook page.<br> </p></div>and you miss my point. The trick is to answer those questions in an non obvious way. <br><small>--<br>* seek help if having trouble coping<br>--Standard disclaimers apply.--</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783249</guid>
<pubDate>Mon, 03 Dec 2012 11:55:10 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783207</link>
<description><![CDATA[Kilroy posted : <div class="bquote"><said>said by <a href="/profile/766601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=766601');">AVD</a>:</said><p>pizza<br>pizza<br>pizza<br>bronx, ny<br> </p></div>All fine until you get to the sites that require six characters in your answers and won't allow any two to be the same.<br><br>Back to the OP, the security risk is that someone who knows you well may know the answers to your security questions.  This is the issue I have with this method of password resets.  What is stopping your soon to be ex from hijacking your accounts and making your life a little more miserable?  Forget the fact that most of these questions can be answered by using someone's Facebook page.<br><small>--<br>“Progress isn't made by early risers. It's made by lazy men trying to find easier ways to do something.” ¯ Robert A. Heinlein</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783207</guid>
<pubDate>Mon, 03 Dec 2012 11:46:34 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783096</link>
<description><![CDATA[AVD posted : <div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p><div class="bquote"><said>said by anon user :</said><p>...That is what they do, but they only ask for: Social Security Number, Birth Date as MMDD and Last Name Including Suffix (Example Smith Jr)<br>So, how safe/risky is it - what they are doing?<br></p></div>Are you an employee of the organization? That is, is this an access portal into the company network?<br> </p></div>My company used the full 9 digit SSN to validate initial signups to an internet based benefits portal. I think saner heads prevailed.<br><small>--<br>* seek help if having trouble coping<br>--Standard disclaimers apply.--</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783096</guid>
<pubDate>Mon, 03 Dec 2012 11:22:04 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783089</link>
<description><![CDATA[Blackbird posted : <div class="bquote"><said>said by anon user :</said><p>...That is what they do, but they only ask for: Social Security Number, Birth Date as MMDD and Last Name Including Suffix (Example Smith Jr)<br>So, how safe/risky is it - what they are doing?<br></p></div>Are you an employee of the organization? That is, is this an access portal into the company network?<br><small>--<br>“The American Republic will endure until the day Congress discovers that it can bribe the public with the public's money.” A. de Tocqueville</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27783089</guid>
<pubDate>Mon, 03 Dec 2012 11:21:00 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27782483</link>
<description><![CDATA[AVD posted : <div class="bquote"><said>said by <a href="/profile/156437" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=156437');">dave</a>:</said><p>Your mother's maiden name was 'pizza' ?<br>You went to school at pizza high?<br>Your first pet was pizza?<br> </p></div>that's the whole point isn't it? <br><small>--<br>* seek help if having trouble coping<br>--Standard disclaimers apply.--</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27782483</guid>
<pubDate>Mon, 03 Dec 2012 07:38:15 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27777324</link>
<description><![CDATA[anon posted : My apologies for doubting you.<br>As  dave <A HREF="/useremail/u/156437"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> mentioned earlier if the challenge question answers consist of data the site already has then it's not the huge issue it would normally be seen as.<br><br>However, exchanging a password for only the challenge question answers is not too sharp, actually it's piss poor security, IMO.<br><br><small>Snowy-not-logged-in</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27777324</guid>
<pubDate>Fri, 30 Nov 2012 22:28:37 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776826</link>
<description><![CDATA[anon posted : <div class="bquote"><said>said by <a href="/profile/795407" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=795407');">Snowy</a>:</said><p><div class="bquote"><said>said by <a href="/profile/156437" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=156437');">dave</a>:</said><p>I now suspect this might be a troll.<br> </p></div>The OP could post the site address to prove otherwise but I'm doubting the site exists.<br> </p></div>It is at &raquo;<A HREF="https://ws1.aholdusa.com/jgpromos/homeaccess/index.html" >ws1.aholdusa.com/jgpromos/homeac&middot;&middot;&middot;dex.html</A><br><br>I can not for security reasons tell you the answers to the security questions OR give to you my account info so that you can verify, once logged in you can not change the password.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776826</guid>
<pubDate>Fri, 30 Nov 2012 20:28:38 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776783</link>
<description><![CDATA[Snowy posted : <div class="bquote"><said>said by <a href="/profile/156437" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=156437');">dave</a>:</said><p>I now suspect this might be a troll. <br> </p></div>The OP could post the site address to prove otherwise but I'm doubting the site exists.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776783</guid>
<pubDate>Fri, 30 Nov 2012 18:45:02 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776753</link>
<description><![CDATA[dave posted : They want your social security number - what could possibly go wrong with that?<br><br>I now suspect this might be a troll.  Apologies if I'm accusing you unjustly - but really, do you have to ask about using your social security number as identification?  (Unless, perhaps, this is some financial web site where they have that data anyway; but you're not giving a lot of detail, which helps me suspect trolling).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776753</guid>
<pubDate>Fri, 30 Nov 2012 18:35:31 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776726</link>
<description><![CDATA[anon posted : <div class="bquote"><said>said by <a href="/profile/156437" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=156437');">dave</a>:</said><p>The lesser risk depends on how the forgot-my-password mechanism is arranged. If they give you a new password right there in exchange for questions of the mothers-maiden-name variety, it's not particularly secure: such data can be found out.   </p></div>That is what they do, but they only ask for:<br>Social Security Number, Birth Date as MMDD and Last Name Including Suffix (Example Smith Jr)<br><br>So, how safe/risky is it - what they are doing?<br><br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27776726</guid>
<pubDate>Fri, 30 Nov 2012 18:27:24 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27774262</link>
<description><![CDATA[Laura_cyber posted : The main risk includes is that, your account can be hacked easily with little efforts.<br>Try to switch on other secured options available on the web, it would be more convenient for you then.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27774262</guid>
<pubDate>Fri, 30 Nov 2012 04:02:32 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773805</link>
<description><![CDATA[Snowy posted : What would you hear if you asked The Teenage Mutant Ninja Turtles what is their favorite food?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773805</guid>
<pubDate>Thu, 29 Nov 2012 22:10:53 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773705</link>
<description><![CDATA[dave posted : Your mother's maiden name was 'pizza' ?<br>You went to school at pizza high?<br>Your first pet was pizza?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773705</guid>
<pubDate>Thu, 29 Nov 2012 21:43:55 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773132</link>
<description><![CDATA[Snowy posted : <div class="bquote"><said>said by anon user :</said><p>What is the security risk of that?<br> </p></div>On the other side of that...<br>It adds a layer of authentication, as in a 2 factor challenge if it's in addition to just using a registered email address to send a password token.<br><br>Using a hijacked email account to get access to different password protected sites is a daily occurrence.<br>This policy would eliminate or at least slow down an account hijacking depending on the strength of the security challenge Q & A's.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27773132</guid>
<pubDate>Thu, 29 Nov 2012 18:34:06 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27772708</link>
<description><![CDATA[AVD posted : pizza<br>pizza<br>pizza<br>bronx, ny]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27772708</guid>
<pubDate>Thu, 29 Nov 2012 16:46:58 EDT</pubDate>
</item>

<item>
<title>Re: What is the risk of this?</title>
<link>http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27772641</link>
<description><![CDATA[dave posted : The main risk is that a site that fails to provide a way to change your password directly is incompetent, and probably has other problems too.<br><br>The lesser risk depends on how the forgot-my-password mechanism is arranged. If they give you a new password right there in exchange for questions of the mothers-maiden-name variety, it's not particularly secure: such data can be found out.  If they mail you a link to reset the password, it's a little better: someone needs to intercept your mail as well. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-What-is-the-risk-of-this-27772641</guid>
<pubDate>Thu, 29 Nov 2012 16:30:45 EDT</pubDate>
</item>

<item>
<title>What is the risk of this?</title>
<link>http://www.dslreports.com/forum/What-is-the-risk-of-this-27772612</link>
<description><![CDATA[anon posted : I can't change the password to my account on a site with out clicking on <b>Forgot user name and password</b>, and then answering the security questions - even while I know the correct user name and password.<br><br>What is the security risk of that?<br><br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/What-is-the-risk-of-this-27772612</guid>
<pubDate>Thu, 29 Nov 2012 16:24:32 EDT</pubDate>
</item>

</channel>
</rss>
