As I proved in my last blogpost, it’s actually trivial to compromise a facebook account given a very small amount of personal information. After talking to a number of other geeks on Friday night, two things became quite apparent.
Facebook security is poor, at best, and the ability to change the user’s contact email address is shocking. Security questions and secret answers are easily exposed by social engineering, thus, these questions only work effectively if you have a completely different identity which you only use for secret questions and answers. I don’t approve entirely of having secret questions that aren’t related to you directly.. I mean, if you had a secret question which was “What is your mother’s maiden name?”, and you gave an answer which wasn’t true, you’d have to do two things. a) remember that you lied, and b) always use the same one, or you’d be forever confused.
...