City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#!
It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
As such most helpdesk employees will accept the answer "Oh I forgot, I do remember I put some random characters in there"... and your random password end up not helping you after all.
Nah, "well, it kinda looks like random characters" is information a support rep will give you.
Welcome to social engineering and info escalation.
The random character thing isn't great for this use, it seems, as a result.
There are ~35,000 cities and towns in the U.S., but if you start weighting those by populating (and birthing hospitals and centres), you're going to reduce that count considerably.
https://www.reference.com/geography/many-cities-united-state...
There are a lot of lovely and easy to remember names in other countries ;)
There are about 300 in the U.S. of over 100k population (corollary: the other 34,700 locations have fewer than 100k people each, or are at most 10% of the population). A 1/300 chance of cracking a security question on any given transaction is pretty good odds. Particularly if the crack is then reusable.
Another 10% of the U.S. population (roughly) lives in the 10 largest cities alone. That's a 1% likely success rate based on just ten values.
The point being that "legitimate sounding but fabricated" may still not be a particularly good option.
You don't have to answer the challenge with a 100% truthful, legitimate, accurate response, because the point is to NOT provide an answer that could be guessed by framing the response in truth, or even reality. So long as you've picked one that matches with what you've preseeded, use a random word/phrase as your response.
q: What is the name of your favorite teacher? a: bumble bees in the desert
Still, if that helps in one case per thousand, it's still better than none.
> Do NOT give ANY hints; only accept an EXACT answer; I will NEVER say I "forgot" this answer. 2DXSDGREDV@#!
Maybe add an "I test you occasionally." :D
If there's a length limit, trim and remove parts of that as you see fit. For example:
> NO hints! EXACT answer! NO exceptions! 2DXSDGREDV@#!
I'm going to do this at a few places, then call to test them :D.