25 Years of Programming Community Forum
Blog  Sitemap  Services
September 10, 2010, 05:56:55 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you want email notification when someone replies to a topic, click the topic's Notify button.
 
   Home   Help Search Login Register  
This is a link to the Chat Room (for Firefox+ChatZilla) when you are logged in.
View help topic about using Live Chat
Pages: 1   Go Down
  Print  
Author Topic: Why you should leave Secret Question blank in your forum Profile  (Read 1815 times)
0 Members and 1 Guest are viewing this topic.
SteveW
Administrator
Full Member
*****
Offline Offline

Posts: 191


WWW
« on: March 27, 2008, 08:29:38 AM »

In this and other forums, it is best to leave blank the Secret Question and Secret Answer in your user profile. The Secret Question feature is provided to "help retrieve a lost password".

However, if you lose your password, you can always obtain a new one by requesting that an email be sent to you. This method requires that you have access to the email account that you registered with, which presumably you do have access to.

If you get your password by answering the Secret Question (instead of by email), it bypasses the email requirement, which means that it could potentially be guessed by someone who does not have access to your email account.

Assuming you are using a strong password that is unguessable (hint, hint!), it would be very difficult for anyone to guess it. However, your Secret Question and Secret Answer are both going to consist of English words and phrases. The questions and answers are relatively predictable, and even if you choose unusual ones, they are vulnerable to a "dictionary attack" where someone (or a robot) runs through the dictionary guessing every possible word and phrase. That sounds very difficult, too, but it's millions of times easier than guessing a good random password.

So in other words, if you use a Secret Question, it makes your password only as strong as your Secret Question and Answer, which are much less strong than a good password. In a way, it almost makes your good password irrelevant.

If you leave the Secret Question blank, it's not presented as an option for getting a lost password, so it's much more difficult for someone to try to log in as you.

I'm not really clear why the SMF forum provides it as an option. Maybe it's a leftover feature from earlier days. At least it is blank by default, which is good.
« Last Edit: March 27, 2008, 08:36:53 AM by SteveW » Report to moderator   Logged
Pages: 1   Go Up
  Print  
 
Jump to:  


Yahoo! Search
Search the web Search this site
 
Mazeguy Smilies Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS! View content labeling at ICRA.