A Review of Real World Security Questions & Answers

Passwords13 Las Vegas

Presented by: Bruce K. Marshall (PwdRsch)
Date: Tuesday July 30, 2013
Time: 14:00 - 14:20
Location: Main Room
Track: Passwords13

Security questions and answers (aka Knowledge-Based Authentication) are a popular secondary means of authentication for online sites. This talk analyzes the security of actual user choices included in data dumps from three different organizations.

Security questions and answers have become a popular secondary authenticator for online sites. While security professionals have generally dismissed them as a good choice, they don't seem to be disappearing. In this talk, I will share my analysis of actual user security question and answer choices that were leaked through three different database dumps in the past year. I use this real world data to demonstrate where security questions seem to have their greatest weaknesses, and discusses how to steer implementations towards providing better security. For comparison, we will also look at how the statistics from these environments compare to previous academic studies of security questions.

Bruce K. Marshall

Bruce K. Marshall, aka PwdRsch, is a security consultant and founder of PasswordResearch.com. He aims to introduce more IT personnel to existing and new authentication research so they can better justify secure system design and policy choices. He spend his weekends hunting witches in dark forests.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats