Safer Storage and Handling of User Answers to Security Questions

Safer Storage and Handling of User Answers to Security Questions

Like it or not, security question password reset isn’t going away. Most organizations find it to be a cost effective approach that seems to work in practice. While there are many problems with this approach, one has received little attention: how to safely store the answers. I show that common methods used for storing password validation information are not suitable for security questions, and propose better alternatives.

Presented by