Back to resources

Why Security Questions Are Weaker Than You Think

A bunch of websites ask you to set up securityquestions when you create an account. Some security questions could be like what was your first pet's name? Or, something like what street did you grow up on? Or maybe what was your mother's maiden name? These questions seem like a good, helpful thing, but most of the time they're one of the biggest weakest parts of your account security. Below, learn about security questions, why they matter, and how to deal with them.

The problem with security questions

Security questions were made to make sure that you are actually you.The idea behind security questions was that only you would know the answers to the security questions. But, the idea behind security questions has a big problem with it: most of the questions are really easy for other people to find the answers to .

Think about the security questions that appear a lot. Something like your first pet's name might be on your old social mediaposts.Something like the street you grew up on could be in public records or something.Something like your mother's maiden name could be found through family history sites. Hackers can research and look for these answers. And, sometimes the information behind these has already been leaked from a different hack.

Basically, the secret answers that only you are supposed to know, are actually not really that secret.

Why this matters

Security questions are usually the things that protect people from changing your password and resetting your password.If a hacker can answer your security questions, they might be able to reset your password or change your password and hack into your account, even without knowing your real password.

That makes security questions really weak. You might have a strong password, but if the security questions stopping hackers from resetting your password are really easy to guess or look for,even if you have a strong password it probably won't matter. The hacker can actually simply just ignore it .

The safer way to answer security questions

Here's a simple trick that turns weak security questions into a strong thing protecting your password: don't answer security questions honestly. You should actually think of each answer like a different password. Make each answer long, random and absolutely unrelated to the actually real answer.

For example, if the question is “What was your first pet’s name?”, your answer does not have to be a pet’s name at all. It can be a random string like “violet-anchor-92-storm”.

For example if the security question was “What was your first pet's name?”, your answer doesn't have to be your pet’s name at all. Your answer could be like a random string of words like “violet – anchor – 92 – storm” .Nobody can research that, because it has nothing to do with your real life. It's never going to be foundanywhere because it's not related to you at all.

The only problem with this is remembering these fake answers, and that's exactly where a password manager can help.

How a password manager solves this

A password manager can store more than just passwords. A password manager can store secure notes and stuff like the answers to your security questions.So, you can generate random, meaningless answers for every security question and save them safely in your vault, so you don't even have to remember them.

This gives you the best of both worlds. Your security questions become impossible for attackers to research, because the answers are random. And you never have to remember them, because your manager stores them for you. You have effectively upgraded a weak security feature into a strong one.

Password managers give you the best of both worlds. Your security questions become literally impossible for hackers to research and look for answers because the answers are literally just random. And you also never have to remember the answers to your security questions, because your password manager stored them for you. You've just changed a really weak security feature into a really strong security feature.

With HatePassword, you can keep these details in your encrypted vault with your passwords, protected by the same zero-knowledge encryption. Only you can see your passwords and data.

A quick guide

To handle security questions safely:

  • Never use honest answers that hackers could find or guess.
  • Treat each answer like a password: long, random, and unique.
  • Store the fake answers in your password manager so you do not lose them.
  • Prefer stronger options when a site offers them, like two-factor authentication, which is way better than security questions.

Security questions were made a leally long time ago, and if you answer them normally, then security questions are really, really weak. But with a really easy change in how you answer the security questions, and a password manager to remember your answers, you can protect your account really easily with almost no work.