I mean, I just feed security questions as a randomly generated string- password managers will even save that string so you donβt have to remember it.
Comic Strips
Comic Strips is a community for those who love comic stories.
Rules
-
π Be Nice!
- Treat others with respect and dignity. Friendly banter is okay, as long as it is mutual; keyword: friendly.
-
ποΈ Community Standards
- Comics should be a full story, from start to finish, in one post.
- Posts should be safe and enjoyable by the majority of community members, both here on lemmy.world and other instances.
- Any comic that would qualify as raunchy, lewd, or otherwise draw unwanted attention by nosy coworkers, spouses, or family members should be tagged as NSFW.
- Moderators have final say on what and what does not qualify as appropriate. Use common sense, and if need be, err on the side of caution.
-
𧬠Keep it Real
- Comics should be made and posted by real human beans, not by automated means like bots or AI. This is not the community for that sort of thing.
-
π½οΈ Credit Where Credit is Due
- Comics should include the original attribution to the artist(s) involved, and be unmodified. Bonus points if you include a link back to their website. When in doubt, use a reverse image search to try to find the original version. Repeat offenders will have their posts removed, be temporarily banned from posting, or if all else fails, be permanently banned from posting.
- Attributions include, but are not limited to, watermarks, links, or other text or imagery that artists add to their comics to use for identification purposes. If you find a comic without any such markings, it would be a good idea to see if you can find an original version. If one cannot be found, say so and ask the community for help!
-
π Post Formatting
- Post an image, gallery, or link to a specific comic hosted on another site; e.g., the author's website.
- Meta posts about the community should be tagged with [Meta] either at the beginning or the end of the post title.
- When linking to a comic hosted on another site, ensure the link is to the comic itself and not just to the website; e.g.,
β Correct: https://xkcd.com/386/
β Incorrect: https://xkcd.com/
-
π¬ Post Frequency/SPAM
- Each user (regardless of instance) may post up to five (5 π) comics a day. This can be any combination of personal comics you have written yourself, or other author's comics. Any comics exceeding five (5 π) will be removed.
-
π΄ββ οΈ Internationalization (i18n)
- Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
SΓ, por favor [Spanish/EspaΓ±ol]
- Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
-
πΏ Moderation
- We are human, just like most everybody else on Lemmy. If you feel a moderation decision was made in error, you are welcome to reach out to anybody on the moderation team for clarification. Keep in mind that moderation decisions may be final.
- When reporting posts and/or comments, quote which rule is being broken, and why you feel it broke the rules.
Web Accessibility
Note: This is not a rule, but a helpful suggestion.
When posting images, you should strive to add alt-text for screen readers to use to describe the image you're posting:
Another helpful thing to do is to provide a transcription of the text in your images, as well as brief descriptions of what's going on. (example)
Web of Links
- !linuxmemes@lemmy.world: "I use Arch btw"
- !memes@lemmy.world: memes (you don't say!)
Yeah, it's a little silly if you end up on the phone having to say it to a service rep, but it's better than what's otherwise basically security theater.
The name of my high school crush was "SnorkleBrewersExploringAsphaltBrowniePie" why do you ask?
"Little Snorkly Pie, we called them."
I said my name is Apostrophe Semi-colon DROP USERS.
I enjoy singing "oh ricky you're so fine, you're so fine you blow my mind hey ricky [clap clap] hey ricky [clap clap]" at the service rep and i told them that if i don't sing it or clap that i have failed the security challenge.
it's the answer to what was the color of my first car.
I once spent about five minutes explaining my email over the phone β which email has just a handful of letters, but in a weird sequence. Can't imagine having to dictate a random password.
Reminds me of the time when our office got corporate debit cards for everyone, and one dude had his security phrase be eight letters βQβ (or more specifically, a sorta connective letter that can only be at the end of syllables in our language).
I feel like maybe someone could convince people over the phone to give them access if they explained correctly that the fields have random strings and roughly how they are formatted, but claim to have forgotten what they are
You could convince a cs rep to open it with a sob story and a fake sniffle.
Fortunately, most places have gone away from giving CS repels that kind of access.
Childhood friend: Z67!1pQ6fk9
I started this too lmao.
Huh?
Instead of answering security questions honestly, you can treat them as just like another password field.
Funny thing is when a bank employee asks you for the answer on the phone. I was like 5 characters in dictating the random 32 characters when she just stopped me and let me do what I called to do.
That doesn't sound like a good system security-wise TBH. I'd prefer if the employee had to enter the answer successfully on their end for the system to grant them the necessary access, otherwise it feels like a big opportunity both for internal snooping and for social engineering.
Yeah, I guess they are seeing the answer on their side because they need to be able to judge that when you say your first car model name differently than when you typed it in, it's the same thing.
Because you are not trying to recall the answer, you are answering the question, and can word the answer differently than before.
Which I don't like.
you need to never use the "security questions" ever...
The security questions are often forced.
The trick is to make up answers. Have some go-tos or a pattern that only you know and no one else could guess with information from your life.
Why yes, I did grow up on AmazonFakeStreet. Oh, my spouse? MicrosoftSpouseName of course.
You can also store these in a password manager like KeePass...
if you use password manager, you should never need to use recovery questions.
Well, I'd rather write down anything I enter, in case I do ever need it. But yeah, generally speaking you shouldn't need the answers.
it probably doesn't hurt to save it, but at the same time, for a keepass user, if you lost the primary password, it probably means you don't have the wallet for whatever reason.
Well, there might be other reasons to need them. For example, I once got locked out of an account, because I had lost the 2FA credentials (which I did not have in KeePass, incidentally). The webpage let me back in with a recovery question.
Well, technically, it was a recovery code which was just random symbols I had been provided upon account creation, but kind of the same thing in the end.
unless youβre using a password manager capable of tracking those for you.
Doesn't every password manager have a "notes" field these days?
You replied to the wrong guy, but I think they rather meant it as "unless you're using a password manager (...because password managers are generally capable of storing extra data)". π
I mean, even if it can't store extra data in one entry, you could still create multiple entries for a single account and just name the entries similarly.
And to give an example of a password manager intentionally kept so simple that, well, there is a solution, but it is somewhat choose-your-own-adventure: https://www.passwordstore.org/#organization
(You can get GUIs for it, which may have a premade solution after all, for example: https://f-droid.org/packages/app.passwordstore.agrahn )
so the funniest thing, we were sitting around at a family reunion. someone asked, so do we all use the same answers for our security questions? and uh, turns out we all do. same made up answers (everyone had the same favorite cat. whose favorite person was me awww yisss), but the same answers. and that moment we decided to update our security procedures.
You get security questions asking you who your "favorite person" is?
the trick is q'wdsjfaosdijgoasfgnsdk;jfavfghoiaerjhpguewrhjtiwuerth
never ever put any non-random information there.
i had a 70 year old guy getting divorced, because his wife of similar age "hacked" his email by entering name of their parrot and found out he is emailing with another 70 yo lady.
Ideally you still want it to be something you'll remember, unless you're using a password manager capable of tracking those for you.
The mistake that guy made is that he still chose a name he had some attachment to. You want to make sure you choose something you have no attachment to whatsoever.
And then never reuse the same answer between different services, just in case one of them is storing them as plaintext.
You can't even install Windows (local account) these days without answering 3 of these. If you ever click on one of the recovery options, you'll be asked for one of them.
My solution is usually to just randomly smash the keyboard for a while.
My solution is usually to just randomly smash the keyboard for a while.
i do the same.
install Windows
Well... there's your problem. ;}
No, cause it's at work and not my choice. It's also just one example of many. I don't run Windows on any of my own PCs any more.
I use fingerprint technology.
It is so secure, I can't get in, 95% of the time!
Don;t worry the it will work for the feds when they knock you unconscious and put your finger in the scanner.
That's why I never tell anyone that my first pet was named Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch.
Finnish?
Itβs a village in Wales.
Welsh cat! Bapahdahbabapadahdah.
My voice is my passport. Verify Me.
i am wearing a wire.
You can also lie to security questions with joke answers only you understand.
