Identity protection

None of this is expert advice. It's what people worked out for themselves, usually the hard way — what actually helped, and what they'd tell someone standing where you are. Take what fits and leave the rest.

How this was put together

If you only read a few

  1. Avoid security questions asking for 'favorite' items, as these preferences can change over time and are difficult to recall accurately years later.

    Favorites may change as you age, and people often fail to provide the correct answer from the past.

    • Answers derived from closed sets (like favorite color) are also discouraged.

    4 people, independently

  2. Answer online security prompts with made-up, nonsensical, or unrelated details rather than your actual personal facts.

    Genuine answers are frequently searchable online or known by acquaintances, which can make it easier for others to access your accounts.

    14 people, independently

    • Create a consistent fictional persona using details from a celebrity or character to answer security questions.5
  3. Avoid posting biographical details like pet names, favorite foods, first cars, or teachers on social media.

    Hackers can use old pictures and posts to find answers to common security questions.

    • Only applies if you post content on social media.

    one person who lived it

  4. Recognize that social engineering is a primary method of compromise because it works well.

    It works so well.

    one person who lived it

  1. If forced to use security questions, create custom questions with absurd or nonsensical answers if the platform allows it.

    Custom questions with inside jokes or nonsense answers are difficult for others to guess.

    2 people, independently

  2. Choose subjective or obscure security questions rather than factual ones like schools or maiden names.

    Factual details like streets and maiden names can be easily searched.

    one person who lived it

  3. Do not reuse the same fake security answer across high-value accounts like banks and schools.

    Security answers are often stored in plain text without encryption or hashing, allowing attackers to access multiple accounts if one site is compromised.

    one person who lived it

    • Avoid using security questions for account recovery if they rely on non-private data.1
  4. Recognize that viral posts asking for personal info may be bots collecting data to sell or to verify active accounts.

    Such posts are often used to gather information to sell or check account activity.

    one person who lived it

12 more on this
  1. Leave immediately if an employer demands your private passwords.

    The company is likely unethical.

    one person who lived it

  2. Construct security question answers with the same complexity as passwords, using mixed case, numbers, and punctuation.

    Simple proper names can be guessed via dictionary attacks.

    2 people, independently

  3. Avoid sharing personal information in response to mass 'share this' posts.

    Sharing such information openly can be dangerous.

    one person who lived it

  4. Use two-factor authentication instead of relying on security questions.

    It is a much better and more effective option; sites using only security questions should be avoided.

    2 people, independently

  5. Create fictional answers for security questions using elements from books, games, or songs that have personal meaning to aid memory.

    Nonsense with personal meaning is easier to remember.

    2 people, independently

  6. Monitor children's online activity to ensure they are not inadvertently sharing sensitive personal information like birth hospital or time.

    Children may unknowingly provide this information to sites (e.g., astrology sites), giving strangers a start on stealing their identity.

    one person who lived it

  7. Assume attackers can gather information from multiple sources to build a detailed profile of you.

    Social engineering involves combining disparate data points (like hobbies, profession, location, and family status) to compromise accounts.

    one person who lived it

  8. Recognize that data brokers buy and sell user-generated content, which can link supposedly anonymous accounts together.

    Anything said anywhere can be matched elsewhere to reveal all associated accounts.

    one person who lived it

  9. Apply a consistent modification rule to your security answers, such as always using lowercase for proper names or intentionally misspelling words.

    Consistency ensures you can remember how you altered the answer.

    one person who lived it

  10. Keep a copy of your usernames and passwords in a separate location that does not rely on internet connections or electricity.

    Keyloggers exist even with authenticators or encryption.

    one person who lived it

  11. Be prepared for customer care representatives to ask for security answers verbally.

    Representatives may ask questions like 'who is the sandwich?' during calls.

    one person who lived it

  12. Treat security questions as a flawed security measure.

    Security experts consider them a disaster that should be eliminated.

    one person who lived it

Close