83°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Am I really the only one who knows what street I grew up on?

    May 12, 2009

    The top trending topic on Twitter the other day was #twitterpornname. This seemingly innocent meme prompts you to find your Twitter porn name by combining the name of your first pet with the street you grew up on, or some variation. Thousands of people began shouting out this information on their Twitter profiles.

    At this point, little red flags may be going off in your head if you realize that another place you may have seen these questions is... the security questions for your online bank account! "The name of your first pet" and "the street you grew up on" are common security questions asked by many websites, and probably you've signed up on a few websites that have asked you these.

    This meme quickly caused people to seriously think about online security. On one hand, you have people freely giving out the answers to their security questions for their online banking accounts, their student email accounts, etc.

    On the other hand, you have businesses treating this information as if you are the only one who could possibly know it. The whole point of a password is that nobody knows it except you. If I log in to a website and provide my password, the website can be reasonably sure that it is really me logging in. When security questions can be used to reset a password, you'd better be sure that nobody else knows the answers to the security questions.

    Why, then, do businesses assume that you are the only one who knows the answers to "what street did you grow up on" or "what is your mother's maiden name"? Surely you can think of a few other people in your life who know the answers, because they grew up with you, or they are related to you.

    So while it's generally a bad idea to give out the answers to your security questions on Twitter, there is really a bigger issue here.

    Note: You may have arrived at this post because you saw my tweet which included my SSN and credit card number. Be assured: this was not my actual SSN or CC#. I was making fun of the fact that people give up personal information so easily.

    Tue, May 12, 2009 6:46pm -07:00 #privacy #twitter
Posted in /articles

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv