Educause Security Discussion mailing list archives

Re: Challenge/response questions?


From: Charles Buchholtz <chip+educause () SEAS UPENN EDU>
Date: Tue, 14 Apr 2009 18:16:00 -0400

On Tue, Apr 14, 2009 at 04:42:09PM -0400, Gary Flynn wrote:
Bob Bayn wrote:

Responses must be an exact match, and our users seem to have a lot of
trouble with that, especially after 6 months or so.

We have that problem too. In a new system we proposed, the answers
would be case insensitive and would have white space removed.

Some "favorites" change over time so challenges that ask about a favorite
are hard to answer after 6 months.

Agreed. Especially when you're 19. :)

Consider this approach:

"In 2006, you told us your favorite musical performer was:
   [ ] Panic! At the Disco
   [ ] Black Eyed Peas
   [ ] Chamillionaire
   [ ] Beyonce
   [ ] None of the Above"

It eliminates the problem when the person enters "Springsteen" and you
want "Bruce Springsteen".  And it reduces the problem when you want
"Beyonce" and the person can't quite remember whether she said
"Beyonce" or "Pink" or "Red Hot Chili Peppers".

You could gather the wrong choices from other people's answers.

To reduce the effectiveness of guessing, there would have to be enough
questions and choices, and you'd have to lock out the account after a
small number of failures (maybe only 1).

--- Chip

Charles H. Buchholtz                    Director of Systems Programming
chip () seas upenn edu            School of Engineering and Applied Science
http://www.seas.upenn.edu/~chip           University of Pennsylvania

Current thread: