I guess it’s fair to say that passwords is sort of a pet topic of mine. Well, here’s a sobering look at one possible dark side of our online lives.
The piece by MSNBC’s Bob Sullivan, on The Red Tape Chronicles blog, looks at how identity thieves can use a common security feature against you. It’s the “Forgot your password” link found on just about any site where you have an account.
The problem is that the answers to so many of the common security questions are becoming increasingly easy to find in this era of social networking and online databases. Mother’s maiden name. High School mascot. Favorite pet’s name. City of birth. These aren’t all that tough.
There are no known cases in which hackers have widely exploited “forgot your password” links, but there are indications that both researchers and criminals are training their eyes in this direction. Markus Jakobsson, principal scientist at the famed Palo Alto Research Center in California, said answers to password reset questions have become so valuable that a black market has developed for personal information like dog’s names. Criminals buy buckets of personal information, obviously with an eye towards foiling security systems, for about $15 per set, he said.
