« What is your mother’s maiden name ? », « What was the name of your first pet ? », « In which city were you born ? » : these security questions, designed to help you recover an account if you forget your password, seem reassuring. However, they often constitute a WEAK LINK in your security. Why? Because the answers are often guessable, findable on the internet, or already known to your entourage. Properly managing your recovery questions is an overlooked but important aspect of online security. Here’s how to prevent these questions from becoming an entry point for hackers.
Why security questions are a weak link
Security questions (or « secret questions », « recovery questions ») are used to VERIFY your identity to recover an account; but they often pose problems. WHAT THEY ARE FOR: when you forget your password or lose access to an account, the service may ask you to answer a secret question you had set, to confirm it’s really you; it’s a RECOVERY method. WHY THEY ARE WEAK: the problem is that the answers are often too easily DISCOVERABLE. GUESSABLE ANSWERS: many questions are about information that isn’t really secret; the name of your birth city, your favorite dish, your pet’s name can be known by your loved ones or found. ANSWERS ON SOCIAL NETWORKS: in the age of social media, much of this information is PUBLIC or easy to find; the name of your pet, your school, your city may be visible on your profiles; a hacker can collect them. ANSWERS KNOWN TO YOUR ENTOURAGE: your loved ones often know the answers (your mother’s maiden name, your place of birth); it’s not « secret » for them. FEW ANSWERS: for some questions, there are only a few possible answers (a favorite color), easy to guess. THE RISK: an attacker who knows or guesses your answers can RECOVER your account in your place, bypassing your password; security questions can therefore be an ENTRY POINT, a weak link. WHAT YOU NEED TO UNDERSTAND: security questions are NOT a good protection in themselves; they are often less secure than the password they are supposed to « recover »; you must therefore manage them intelligently (see below) or prefer better recovery methods. What does it serve to understand? Not to rely on weak questions; to better MANAGE these questions; and to prefer safer recovery methods. The key idea: security questions (« name of your pet », « birth city ») are often a WEAK LINK: the answers are often guessable, findable on social networks, or known to your entourage; an attacker can therefore use them to recover your account by bypassing your password. The main countermeasure, counterintuitive but effective: do not answer honestly to these questions; treat the answer as a second password (a false and unpredictable answer), and keep it in your password manager. Even better, when possible, prefer more robust recovery methods (two-factor authentication, backup codes) rather than these questions.
Security questions are supposed to help you recover your account, but they’re often weak because the answers are easy to find. Hackers can guess or look up your pet’s name, birth city, or mother’s maiden name. The best way to protect yourself is to lie—give fake answers that only you know, stored in a password manager.
Imagine a hacker tries to recover your email account. They see on your Facebook profile that your first pet was “Max.” If you answered “Max” to the security question, they can bypass your password. But if you had answered “PurpleDragon42,” they’d be stuck.

How to properly manage your recovery questions
Here’s how to prevent these questions from weakening your security. DO NOT answer honestly — this is the key, counterintuitive advice: do NOT give the true answer to a security question; treat the answer as a SECOND PASSWORD: invent a FALSE, long, and unpredictable answer, unrelated to the truth; thus, no one can guess or find it. Treat the answer as a PASSWORD — a good « answer » is like a good password: unique, unpredictable, with no link to public information; for example, to « name of your pet », answer a random string of words rather than the real name. NOTE your false answers in a manager — since your answers are false and unpredictable, you won’t remember them; store them in your password manager (which can often keep notes), to retrieve them if needed (our guides on adopting a password manager). Prefer BETTER recovery methods — when a service offers them, prefer safer methods than questions: two-factor authentication, backup codes, a well-secured email address or recovery number (our guides on keeping a backup access to your accounts). AVOID making your info public — limit what you share on social networks: your city, your school, your pets’ names, your dates; this information is exactly what feeds security question answers (our guides on limiting the data you share online). Beware of « GAMES » on social networks — beware of quizzes and « games » that ask for your first car, your childhood street name, your pet: these are often disguised information collections matching security questions; don’t play along. Check your CURRENT questions — if you had answered honestly to security questions on important accounts, consider changing them with false answers. Secure RECOVERY as a whole — questions are just one element; ensure that ALL your recovery methods are solid (secured recovery address, etc.). Some TIPS:
- Never answer honestly (answer = second password);
- Note your false answers in a manager;
- And prefer two-factor authentication when possible.
In summary: do not answer honestly to security questions (treat the answer as a false and unpredictable password, noted in your manager); prefer better recovery methods (two-factor authentication, backup codes); limit the information you make public; beware of games that collect this info; and secure all your recovery methods. You thus transform a weak link into a solid protection.
The right reflex. Here’s the advice that surprises everyone, but radically changes the security of your accounts: NEVER answer honestly to security questions. Yes, you read it right: to the question « what is the name of your first pet ? », DO NOT put the real name of your pet. Why? Because the true answer is almost always too easy to find: it may be visible on your social networks, known to your loved ones, or guessable; an attacker can then use it to recover your account by bypassing your password. The lifesaving reflex: treat each answer as a SECOND PASSWORD. Invent a FALSE, long, and unpredictable answer, with no relation to the truth; for example, to « name of your pet », answer something like « Cactus-Cloud-Violin-42 » instead of « Rex ». This answer, no one can guess or find on the internet, as it has no link to your real life. You thus transform a weak link into a real protection. Of course, such a fanciful answer is impossible to remember: that’s why you must NOTE it in your password manager (which usually allows storing notes), to retrieve it the day it’s requested. The manager thus becomes the guardian of your true-false answers. Two complementary reflexes. First, when a service offers BETTER recovery methods than these questions — like two-factor authentication or backup codes — PREFER THEM: they are much more solid than secret questions. Then, beware of what you make PUBLIC: limit on social networks the information (city, school, pets, dates) that exactly feeds these questions; and above all, don’t let yourself be trapped by « games » and viral quizzes that innocently ask for your first car, the name of your childhood street or pet — these are often disguised information collections matching security questions. Answering falsely to your secret questions (like a password), noting these answers in your manager, and preferring two-factor authentication: with these reflexes, you close a door that many leave wide open.

Precautions and proper use
A few nuances complete the proper management of recovery questions. Do not FORGET your false answers: the downside of answering falsely is that you must retrieve these answers the day you need them; hence the importance of NOTING them (in a manager); a forgotten false answer could lock you out; manage them like passwords. Recovery, a BALANCE: recovery methods must be secure enough so an attacker can’t exploit them, but accessible enough so YOU can recover your account; it’s a balance; hence the interest in solid methods AND well-managed (two-factor authentication with backup codes kept). Do not NEGLECT the recovery address: often, recovery goes through an email address or number; ensure this backup address is WELL SECURED and always accessible; a hacked recovery address compromises recovery. The TRAP of games and quizzes: let’s recall, these « games » on social networks (« tell us the name of your first school ! ») are often information collections matching security questions; don’t participate. The COHERENCE of your security: recovery questions are just one link; your overall security also depends on strong and unique passwords, two-factor authentication, protection of your email; treat the whole (our guides on what to do if a password is stolen). What the SERVICE offers: some services abandon security questions in favor of more modern methods; it’s a good evolution; use the best options available. Do not REUSE the same answers: like passwords, avoid using the same false answers everywhere; vary them. SECURITY against access by loved ones: honest answers are known to your entourage; false answers also protect you from this risk; to consider according to your situation. In summary: note your false answers (don’t forget them); aim for a secure/accessible balance in recovery; secure your recovery address; beware of games that collect this info; treat your security as a whole; use the best methods offered by services; and don’t reuse the same answers. Well-managed, recovery questions cease to be a weak point.
Warning: answering honestly to a security question is sometimes giving the key to your account to someone who knows you — or to the internet. You must be aware of a paradox: these « secret » questions, supposed to PROTECT your account, can in reality dangerously weaken it if you answer sincerely. The reason is simple: the true answers are generally not secret at all. The name of your pet, your birth city, your mother’s maiden name, your school, your favorite dish: this information is often known by your LOVED ONES (it’s not « secret » for your entourage), and increasingly FINDABLE on the internet — especially on your social networks, where you willingly share your city, your pets, your background, your memories. An attacker who manages to gather this information (by browsing your profiles, or because they’re part of your entourage) can then RECOVER your account by answering your security questions, completely bypassing your password, no matter how strong it is. The secret question thus becomes the flaw through which one enters. That’s why the countermeasure — answering FALSELY to these questions, with unpredictable answers treated as passwords — is so important: it closes this door. A particularly sneaky trap to know: the « GAMES » and viral quizzes on social networks, which cheerfully invite you to reveal « the name of your first car », « your childhood street », « the name of your first pet », « your birth city ». These questions are not innocent: they EXACTLY match classic security questions, and participating in these « games » is like publishing the answers to your own secret questions, for all to see; never fall for it. Two other precautions. First, if you adopt false answers, NOTE them imperatively (in your password manager): a forgotten false answer could lock you out of your own account the day it’s requested; manage them like passwords. Then, do not neglect your RECOVERY address (email or number), often used to recover an account: if it’s poorly secured or hacked, it becomes a flaw too; protect it well. In short, never let honest security questions become the key you hand to someone who knows you or to the internet: answer falsely, note your answers, beware of info-collecting games, and prefer more robust recovery methods. This often weakest link deserves as much attention as your passwords.

Frequently asked questions
Should you really lie to security questions?
Yes, and it’s not « lying » in the problematic sense: it’s a recognized and recommended security strategy by experts. Let’s understand why it’s wise. Security questions pose a fundamental problem: their true answers are generally NOT secret. The name of your pet, your birth city, your school are often known by your loved ones, or findable on your social networks; an attacker can therefore discover them and recover your account in your place. By answering HONESTLY, you thus offer an easy entry point. The solution is to treat the answer as a SECOND PASSWORD, i.e., to give a FALSE, unpredictable answer, with no link to reality. To the question « name of your first pet ? », instead of « Rex » (guessable), you answer for example a random string of words. This answer, no one can guess or find, as it corresponds to no real information about you. You thus transform a weakness into strength. It’s not cheating: it’s simply refusing to use findable information as a « secret key », and replacing it with a true unpredictable key. The only constraint: as this false answer makes no sense, you won’t remember it; you must therefore NOTE it in your password manager (which allows storing notes associated with each account), to retrieve it the day it’s requested. Without this, you risk locking yourself out. A nuance: vary your false answers from one account to another (don’t always reuse the same one), like passwords. In summary, yes, you must « lie » to security questions — in the sense of giving false and unpredictable answers rather than the true ones —, because the true answers are too easy to find; it’s an effective security strategy, provided you note these false answers in a manager so you don’t forget them. Thus, your recovery questions become a protection instead of a flaw.

Why are these social network games asking for your pet’s name dangerous?
These « games » and viral quizzes, seemingly innocent and fun, are dangerous because they collect precisely the information that serves as answers to your account’s security questions. The mechanism is sneaky. You see on social networks a friendly post like: « Let’s get to know each other! Answer in comments: the name of your first pet, your childhood street, your birth city, the model of your first car, the name of your elementary school! ». It looks like a friendly game, and many people answer in good faith, without seeing any harm. The problem: these questions EXACTLY match classic security questions used by online services to recover an account! By publicly answering this « game », you thus publish, for all to see (including potential scammers browsing these posts), the answers to your own secret questions. An attacker only needs to collect this information to attempt to recover your accounts in your name. Whether these posts are malicious collections or simply harmless chains, the result is the same: you expose sensitive information. The right reflex: DO NOT participate in these games that ask for this type of personal information (especially those that look like security questions); don’t share them either. More broadly, this illustrates an important principle: think about what you make public on social networks, because seemingly harmless information (your city, your pet, your background) can be used to bypass your security (our guides on limiting the data you share online). It’s also another reason to answer FALSELY to your security questions: thus, even if these real information circulates, they don’t match any of your answers. In summary, these games are dangerous because they make you publish the answers to your secret questions; don’t participate, beware of what you share, and protect your accounts with false answers and good security practices.

What is the best way to recover a forgotten account?
The best recovery method is generally NOT security questions (often weak), but more robust mechanisms offered by modern services; the ideal is to set them up in advance. Let’s see the options, from the most recommended to the least reliable. TWO-FACTOR AUTHENTIFICATION with backup codes: it’s the best combination; by activating two-factor authentication on your important accounts, you strongly protect them; and services usually provide BACKUP CODES (one-time use codes) to keep safely, which allow you to recover access if you lose your authentication method; keep these codes in a safe place (printed, or in your manager). A WELL-SECURED email address or RECOVERY number: many services allow recovering an account via a backup email address or number; it’s effective, provided this address or number is itself well-protected and always accessible (a hacked recovery address becomes a flaw). A PASSWORD manager: by storing your passwords (and your false answers to questions) in a manager, you reduce the need to « recover » an account, as you directly retrieve your credentials; it’s a precious safety net. SECURITY questions: if you must use them (some services impose them), manage them intelligently — false and unpredictable answers, noted in your manager —, but don’t count on them as main protection, as they are weak. The general idea: anticipate recovery BEFORE needing it. Set up, on your important accounts, two-factor authentication with its backup codes kept, a secured recovery address, and a password manager: thus, if you forget a password or lose access, you have reliable means to regain control, without depending on weak questions. Find the balance between security (an attacker must not be able to easily recover your account) and accessibility (YOU must be able to do it). In summary, the best way to recover an account is to prepare in advance solid methods (two-factor authentication and backup codes, secured recovery address, password manager), relegating security questions to a last-resort solution, managed with false answers. Anticipating recovery is avoiding being locked out when needed.
What to remember
Security questions (« name of your pet », « birth city », « your mother’s maiden name »), supposed to protect your accounts, are in reality often a WEAK LINK: their true answers are generally not secret at all; they are guessable, findable on your social networks, or known to your entourage. An attacker can therefore use them to recover your account by bypassing your password. The main countermeasure, counterintuitive but recommended by experts: NEVER answer honestly to these questions. Treat each answer as a SECOND PASSWORD: give a FALSE, long, and unpredictable answer, with no link to reality (to « name of your pet », answer a random string of words instead of the real name); thus, no one can guess or find it. As these false answers are impossible to remember, NOTE them in your password manager, to retrieve them when needed. Complete with: prefer BETTER recovery methods when services offer them (two-factor authentication with backup codes kept, well-secured recovery address), which are much more solid than questions; limit the information you make PUBLIC on social networks (city, school, pets, dates), as they feed these questions; and above all, beware of « GAMES » and viral quizzes that innocently ask for your first car, your childhood street, or your pet’s name — these are disguised information collections matching security questions, never to feed. Also think about securing your recovery address (often used to regain an account), not forgetting your false answers (hence the importance of noting them), and treating your security as a whole (strong and unique passwords, two-factor authentication, email protection). Anticipate recovery BEFORE needing it, by setting up reliable methods. By intelligently managing these questions — false answers noted in a manager, distrust of info-collecting games, and solid recovery methods —, you transform a neglected weak point into a robust protection, and you close a door that many leave wide open to hackers.



Doubts about your security, a device to check or clean? Our support service guides you step by step.
Leave a Reply
You must be logged in to post a comment.