• Skip to main content
  • Skip to primary sidebar

Ask Liz Weston

Get smart with your money

  • About
  • Liz’s Books
  • Speaking
  • Disclosure
  • Contact

Q&A: The insecurity of bank security questions

October 10, 2016 By Liz Weston

Dear Liz: I recently opened an account at a bank that boasted “multi-factor authentication,” but I looked into the claim and it turns out the bank is using passwords plus answers to security questions, such as the name of your first pet, as the “multi-factor authentication.” I expect you know that the real multi-factors are something you know, like a username and password, something you have, like a code that has been sent to your phone or email, and something uniquely inherent to you, like a fingerprint. Clearly, this bank is misrepresenting its “multi-factor authentication.”

Answer: If there was any doubt about how insecure security questions are, it should have been settled with the hack of the IRS’ Get Transcript service. The criminals gained access to 700,000 taxpayer accounts by correctly answering multiple questions with answers supposedly known only to the affected taxpayers. In reality, the answers to many security questions can be purchased from black market databases or simply found by perusing people’s social media accounts.

If your financial institutions are still using security questions to identify you, you should demand to know why. If the institution doesn’t offer at least two-factor authentication (a password plus a code), you should consider putting your money somewhere else.

Related Posts

  • Q&A: Freezing Your Social Security Number

    Dear Liz: Recently you answered a question about whether Social Security files could be “frozen”…

  • Q&A: Parental identity theft

    Dear Liz: I have been dating my boyfriend for about eight months and he recently…

  • Your Social Security questions answered

    My column about getting your parents a bigger Social Security check, "More Social Security for…

  • 8 steps to financial security

    Financial security isn't a number or a threshold. It has to do with what you…

Filed Under: Identity Theft, Q&A Tagged With: banking security, Identity Theft, multi-factor authentication, q&a

Primary Sidebar

Search

Copyright © 2025 · Ask Liz Weston 2.0 On Genesis Framework · WordPress · Log in