Election Security
It's over. The voting went smoothly. As of the time of writing, there are no serious fraud allegations, nor credible evidence that anyone tampered with voting rolls or voting machines. And most important, the results are not in doubt.
While we may breathe a collective sigh of relief about that, we can't ignore the issue until the next election. The risks remain.
As computer security experts have been saying for years, our newly computerized voting systems are vulnerable to attack by both individual hackers and government-sponsored cyberwarriors. It is only a matter of time before such an attack happens.
Electronic voting machines can be hacked, and those machines that do not include a paper ballot that can verify each voter's choice can be hacked undetectably. Voting rolls are also vulnerable; they are all computerized databases whose entries can be deleted or changed to sow chaos on Election Day.
The largely ad hoc system in states for collecting and tabulating individual voting results is vulnerable as well. While the difference between theoretical if demonstrable vulnerabilities and an actual attack on Election Day is considerable, we got lucky this year. Not just presidential elections are at risk, but state and local elections, too.
To be very clear, this is not about voter fraud. The risks of ineligible people voting, or people voting twice, have been repeatedly shown to be virtually nonexistent, and "solutions" to this problem are largely voter-suppression measures. Election fraud, however, is both far more feasible and much more worrisome.
Here's my worry. On the day after an election, someone claims that a result was hacked. Maybe one of the candidates points to a wide discrepancy between the most recent polls and the actual results. Maybe an anonymous person announces that he hacked a particular brand of voting machine, describing in detail how. Or maybe it's a system failure during Election Day: voting machines recording significantly fewer votes than there were voters, or zero votes for one candidate or another. (These are not theoretical occurrences; they have both happened in the United States before, though because of error, not malice.)
We have no procedures for how to proceed if any of these things happen. There's no manual, no national panel of experts, no regulatory body to steer us through this crisis. How do we figure out if someone hacked the vote? Can we recover the true votes, or are they lost? What do we do then?
First, we need to do more to secure our elections system. We should declare our voting systems to be critical national infrastructure. This is largely symbolic, but it demonstrates a commitment to secure elections and makes funding and other resources available to states.
We need national security standards for voting machines, and funding for states to procure machines that comply with those standards. Voting-security experts can deal with the technical details, but such machines must include a paper ballot that provides a record verifiable by voters. The simplest and most reliable way to do that is already practiced in 37 states: optical-scan paper ballots, marked by the voters, counted by computer but recountable by hand. And we need a system of pre-election and postelection security audits to increase confidence in the system.
Second, election tampering, either by a foreign power or by a domestic actor, is inevitable, so we need detailed procedures to follow -- both technical procedures to figure out what happened, and legal procedures to figure out what to do -- that will efficiently get us to a fair and equitable election resolution. There should be a board of independent computer-security experts to unravel what happened, and a board of independent election officials, either at the Federal Election Commission or elsewhere, empowered to determine and put in place an appropriate response.
In the absence of such impartial measures, people rush to defend their candidate and their party. Florida in 2000 was a perfect example. What could have been a purely technical issue of determining the intent of every voter became a battle for who would win the presidency. The debates about hanging chads and spoiled ballots and how broad the recount should be were contested by people angling for a particular outcome. In the same way, after a hacked election, partisan politics will place tremendous pressure on officials to make decisions that override fairness and accuracy.
That is why we need to agree on policies to deal with future election fraud. We need procedures to evaluate claims of voting-machine hacking. We need a fair and robust vote-auditing process. And we need all of this in place before an election is hacked and battle lines are drawn.
In response to Florida, the Help America Vote Act of 2002 required each state to publish its own guidelines on what constitutes a vote. Some states -- Indiana, in particular -- set up a "war room" of public and private cybersecurity experts ready to help if anything did occur. While the Department of Homeland Security is assisting some states with election security, and the F.B.I. and the Justice Department made some preparations this year, the approach is too piecemeal.
Elections serve two purposes. First, and most obvious, they are how we choose a winner. But second, and equally important, they convince the loser -- and all the supporters -- that he or she lost. To achieve the first purpose, the voting system must be fair and accurate. To achieve the second one, it must be *shown* to be fair and accurate.
We need to have these conversations before something happens, when everyone can be calm and rational about the issues. The integrity of our elections is at stake, which means our democracy is at stake.
Tuesday, November 15, 2016
Secure the vote
Saturday, March 02, 2013
Fwd: Security Weekly: Watching for Watchers
Watching for Watchers
By Scott Stewart | June 17, 2010In last week's Security Weekly we discussed how situational awareness is a mindset that can — and should — be practiced by everyone. We also described the different levels of situational awareness and discussed which level is appropriate for different sorts of situations. And we noted how all criminals and terrorists follow a process when planning their acts and that this process is visible at certain times to people who are watching for such behavior.
When one considers these facts, it inevitably leads to the question: "What in the world am I looking for?" The brief answer is: "warning signs of criminal or terrorist behavior." Since this brief answer is very vague, it becomes necessary to describe the behavior in more detail. Read more »
Friday, November 02, 2012
How to Crack a Wi-Fi Password
Cracking Wi-Fi passwords isn't a trivial process, but it isn't difficult. Learn how it works so you can learn how to protect yourself. More »
Wednesday, October 31, 2012
RJS Security – Hoaxicane Sandy
FotoForensics and TinEye used to analyze a hoax
Thursday, February 11, 2010
Man-in-the-Middle Attack Against Chip and PIN
Man-in-the-Middle Attack Against Chip and PIN
Nice attack against the EMV -- Eurocard Mastercard Visa -- the "chip and PIN" credit card payment system. The attack allows a criminal to use a stolen card without knowing the PIN.
The flaw is that when you put a card into a terminal, a negotiation takes place about how the cardholder should be authenticated: using a PIN, using a signature or not at all. This particular subprotocol is not authenticated, so you can trick the card into thinking it's doing a chip-and-signature transaction while the terminal thinks it's chip-and-PIN. The upshot is that you can buy stuff using a stolen card and a PIN of 0000 (or anything you want). We did so, on camera, using various journalists' cards. The transactions went through fine and the receipts say "Verified by PIN".
[...]
So what went wrong? In essence, there is a gaping hole in the specifications which together create the "Chip and PIN" system. These specs consist of the EMV protocol framework, the card scheme individual rules (Visa, MasterCard standards), the national payment association rules (UK Payments Association aka APACS, in the UK), and documents produced by each individual issuer describing their own customisations of the scheme. Each spec defines security criteria, tweaks options and sets rules -- but none take responsibility for listing what back-end checks are needed. As a result, hundreds of issuers independently get it wrong, and gain false assurance that all bases are covered from the common specifications. The EMV specification stack is broken, and needs fixing.
Read Ross Anderson's entire blog post for both details and context. Here's the paper, the press release, and a FAQ. And one news article.
This is big. There are about a gazillion of these in circulation.
Sunday, January 31, 2010
Tracking your Browser Without Cookies
Bruce Schneier brings this to our attention at his blog.
My results:
"Your browser fingerprint appears to be unique among the 430,332 tested so far.
Currently, we estimate that your browser has a fingerprint that conveys at least 18.72 bits of identifying information."
Tracking your Browser Without Cookies
How unique is your browser? Can you be tracked simply by its characteristics? The EFF is trying to find out. Their site Panopticlick will measure the characteristics of your browser setup and tell you how unique it is.
I just ran the test on myself, and my browser is unique amongst the 120,000 browsers tested so far. It's my browser plugin details; no one else has the exact configuration I do. My list of system fonts is almost unique; only one other person has the exact configuration I do. (This seems odd to me, I have a week old Sony laptop running Windows 7, and I haven't done anything with the fonts.)
EFF has some suggestions for self-defense, none of them very satisfactory. And here's a news story.
EDITED TO ADD (1/29): There's a lot in the comments leading me to question the accuracy of this test. I'll post more when I know more.
Friday, January 22, 2010
German TV on the Failure of Full-Body Scanners
Before we sign up for expensive and intrusive security measures, we should at least verify that they work.
German TV on the Failure of Full-Body Scanners
The video is worth watching, even if you don't speak German. The scanner caught a subject's cell phone and Swiss Army knife -- and the microphone he was wearing -- but missed all the components to make a bomb that he hid on his body. Admittedly, he only faced the scanner from the front and not from the side. But he also didn't hide anything in a body cavity other than his mouth -- I didn't think about that one -- he didn't use low density or thinly sliced PETN, and he didn't hide anything in his carry-on luggage.
Full-body scanners: they're not just a dumb idea, they don't actually work.
Monday, January 18, 2010
Securing your laptop from Customs
Bruce Schneier has some suggestions for people who are very nervous about being forced to give their laptop password to Customs: Laptop Security while Crossing Borders.
Last year, I wrote about the increasing propensity for governments, including the U.S. and Great Britain, to search the contents of people's laptops at customs. What we know is still based on anecdote, as no country has clarified the rules about what their customs officers are and are not allowed to do, and what rights people have.
Companies and individuals have dealt with this problem in several ways, from keeping sensitive data off laptops traveling internationally, to storing the data -- encrypted, of course -- on websites and then downloading it at the destination. I have never liked either solution. I do a lot of work on the road, and need to carry all sorts of data with me all the time. It's a lot of data, and downloading it can take a long time. Also, I like to work on long international flights.
There's another solution, one that works with whole-disk encryption products like PGP Disk (I'm on PGP's advisory board), TrueCrypt, and BitLocker: Encrypt the data to a key you don't know.
....
tep One: Before you board your plane, add another key to your whole-disk encryption (it'll probably mean adding another "user") -- and make it random. By "random," I mean really random: Pound the keyboard for a while, like a monkey trying to write Shakespeare. Don't make it memorable. Don't even try to memorize it.
Step Two: Send that new random key to someone you trust. Make sure the trusted recipient has it, and make sure it works. You won't be able to recover your hard drive without it.
Step Three: Burn, shred, delete or otherwise destroy all copies of that new random key. Forget it. If it was sufficiently random and non-memorable, this should be easy.
Step Four: Board your plane normally and use your computer for the whole flight.
Step Five: Before you land, delete the key you normally use.
At this point, you will not be able to boot your computer. The only key remaining is the one you forgot in Step Three. There's no need to lie to the customs official, which in itself is often a crime; you can even show him a copy of this article if he doesn't believe you.
Step Six: When you're safely through customs, get that random key back from your confidant, boot your computer and re-add the key you normally use to access your hard drive.
And that's it.
....
This is by no means a magic get-through-customs-easily card. Your computer might be impounded, and you might be taken to court and compelled to reveal who has the random key.
But the purpose of this protocol isn't to prevent all that; it's just to deny any possible access to your computer to customs. You might be delayed. You might have your computer seized. (This will cost you any work you did on the flight, but -- honestly -- at that point that's the least of your troubles.) You might be turned back or sent home. But when you're back home, you have access to your corporate management, your personal attorneys, your wits after a good night's sleep, and all the rights you normally have in whatever country you're now in.
Tuesday, January 12, 2010
Why Whole Body Scanners Won't Work
The TSA already subjects your carry-on bags to X-ray scanning that penetrates the “skin” to show what’s beneath. Yet screeners routinely fail to discern the guns, knives, and other contraband their monitors show. Sometimes undercover federal investigators are smuggling those weapons to test screeners; other times, passengers who’ve forgotten the pistol or ammunition in their knapsack turn themselves in when they reach their gate. Expecting screeners who overlook the hunting knife beside a paperback novel to find the explosives taped near a woman’s… Well, let’s just say the distractions of whole-body imaging are considerably greater than anything in the average carry-on.
There’s a far simpler, constitutional, and less offensive way to protect aviation than photographing two million passengers in their birthday suits each day: Free the airlines from the federal government’s stranglehold on security. Let each company determine what works best for its routes, customers, and specific risks. Does anyone seriously believe that politicians and bureaucrats know more about securing planes than pilots and executives who’ve spent their lives in the industry? Even baggage handlers could give Congress a lesson in preventing terrorists from hiding bombs in checked luggage – yet the Feds dictate to them instead.
Monday, January 11, 2010
Full Body Scanners
There's an obvious question whenever you bathe a body in radiation -- what are the health effects, if any?
From the "Big Government" blog:
Are Total Body Scanners Safe? The Jury Is Still Out
....
The TSA website represents the full body scanner as a safe method of screening. However, not only are we giving up our privacy, we are also playing Russian roulette with our safety. It is important to note:
1. No long term safety tests have been conducted on these scanners
2. The energy produced by T-rays gives off heat and lies close to the laser range.
Because of this, there is a question about how safe these machines would be in the hands of individuals who may not be as well trained as a radiology technician. (Theoretically there may be damage associated with prolonged thermal exposure.)3. Alexandrov et al. at Los Alamos National Laboratory theorized that the thermal energy given off by T-rays can damage DNA by unwinding or unzipping the double helix strands of DNA. This could possibly lead to mutations as the DNA attempts to repair itself.
It is clear that the rush to deploy these machines may put the public at unacceptable risk. The questions about safety for pregnant women, children, and the possibility of increased cancer risk need to be answered before these machines are put into place. It simply is not clear whether the risks are outweighed by the stated benefits.
Infrared lasers are much safer than visible light lasers for a couple of reasons. Being invisible, the eye is less likely to try and focus on them, so much less chance of burning the retina. Also, the infrared wavelengths don't penetrate the eye quite as well as visible light does.
When I was in college, the going theory was that microwaves did their damage by heating tissue. As long as the power level was low enough that you didn't cause too much heating, microwaves did no long-term damage. But then again, there were Russian scientists who claimed microwaves could cause behavioral problems at levels a tenth of a percent of what US science considered safe. We seem to have quit arguing over microwaves, possibly because shielding has improved, but other forms of radiation, including cell phone transmissions, are hotly contested.
In any event, once people start speculating about the health effects of millimeter wave radiation -- um excuse me, make that *RAY-DEE-AAAAYYYY-SHUN* -- I suspect we won't have to worry about invasions of privacy. They won't get FDA approval.
Monday, December 28, 2009
Flailing Panic in the Air
Peter Hitchens has a few suggestions for TSA while they're making a big show of doing something.
Flailing Panic in the Air
by ANM Blog on 12/28/09Here we go again, another series of unreasonable panic responses to a terror incident in the air. As far as I am concerned, if Mr Abdulmutallab is convicted of the crime alleged against him he may go to jail forever. I hate such acts and believe in severe punishment for the people who plan or attempt them.
But is our reaction logical? First, from a reasonably careful reading of the reports of this event, I learn that the official global airline security system, and the parallel system of intrusive identity checks, to which all air travellers are subjected all the time, don't seem to have worked according to their own procedures. Is Lagos airport secure? If not, what exactly are the provisions, at Amsterdam or elsewhere, for dealing with passengers arriving from Lagos and intending to travel onward to other destinations? If there is any doubt about Lagos, anything short of a rigorous and unavoidable check on all such passengers would mean that the European and American airline security system was as strong as the security check at Lagos. Are we happy with that? Yet I haven't myself seen any clear answer to this question.
It appears to me that at some important point, Mr Abdulmutallab may well not have been properly searched. It also seems to me that this person, whose own father had astonishingly reported him to the US Embassy for suspicious and erratic behaviour, and was on an official watchlist, ought to have attracted special attention long before he boarded the Detroit flight. I mean, if someone's father (and in this case a powerful, wealthy and respected citizen) goes to these lengths, shouldn't every alarm bell shrill? What else are all these security systems for, if not to pass on such warnings to the people who can act on them?
Those responsible for these omissions should be located and disciplined, and the gaps plugged. But I fail to see why airline passengers should be punished, as planned, for the failings of the authorities. A ban on more than one piece of hand luggage seems to me to be wholly unrelated to this event, and mere opportunism. I am not quite sure why security is being stepped up at British airports, which were not even involved in this incident (unless it is security for passengers arriving from Lagos, in which case we need to ask why this needs to be stepped up). A ban on in-flight maps (and in some cases in-flight movies) seems to me to be verging on the insane. Are we also to be stripped of our watches, so we can't work out roughly where we are anyway? I take it that matey flight-deck announcements about speed and weather will also be banned, so as not to give terrorists help in working out the plane's position. Why not black the windows out, in case we recognise a lake, a river, a coastline or a mountain range?
And then there's the plan to strap bursting passengers, bloated with the water they've drunk to try to stop dehydration, and unsettled by pressurisation, into their seats for a whole hour before landing, with the lavatories locked. Pursue this unhinged logic a little further, and all passengers should be issued with giant nappies, blindfolded, shackled and tranquillised, Guantanamo-style - and not told where the plane is going, either. This is presumably the securocrats' dream, a wholly safe world where only officials can travel.
Airline security seems to me to have reached a point where it resembles collective punishment, and punishment of the wrong people. It wasn't the flying public that caused this mess. On the contrary, it was a passenger (as did those aboard United 93) who bravely tackled Mr Abdulmutallab. And I'm still anxious to know if this bomb was a real threat. The culprit, as I've said, presumably thought it was and so deserves everything he gets, if found guilty.
But are we making a huge bogeyman and a tight-knit organisation out of pathetic amateurs? Does anyone know, in a demonstrable and certain way a) if Richard Reid's shoe-bomb would actually have worked, in the unlikely event of him not being spotted setting fire to his footwear? b) if the liquid bomb could actually have been assembled in a useable form aboard a plane (we know a version of it would have gone off. We were shown that .We don't know, at least I don't in any reliable way, how hard it was to assemble, or whether that assembly was possible in flight.
I am not asking these questions rhetorically. I genuinely wish to know and would be grateful for any hard facts. It amazes me that these prosecutions take place and this vital detail seems to be skipped over, or assumed. I know it's irrelevant to the guilt or innocence of the perpetrators. But it's not irrelevant to us, or to the way we are governed. Let's hope it will be made clear in this case.
Sunday, December 27, 2009
What kind of idiot is Janet Napolitano?
What kind of idiot is Janet Napolitano?
Homeland Security Secretary Janet Napolitano said Sunday that the thwarting of the attempt to blow up an Amsterdam-Detroit airline flight Christmas Day demonstrated that "the system worked."Asked by CNN's Candy Crowley on "State of the Union" how that could be possible when the young Nigerian who has been charged with trying to set off the bomb was able to smuggle explosive liquid onto the jet, Napolitano responded: "We're asking the same questions."
She then went on to say that there's no suggestion the terrorist was improperly screened.
Sheez. We're led by incompetents. Napolitano should be fired post haste for this sort of idiocy.
Jonah Goldberg speaks for me:
Napolitano has a habit of arguing that DHS is a first responder outfit. Its mission is to deal with "man-caused-disasters" afer they occur. It appears she really believes it. If the White House wants to assure people that it takes the war on terror seriously (a term Robert Gibbs used this morning by the way), they could start by firing this patenly unqualified hack.
And then in 2012, we'll fire the unqualified hack responsible for appointing all the others found in this administration.
Monday, September 28, 2009
Schneier on Security: Ass Bomber
For years, I have made the joke about Richard Reid: "Just be glad that he wasn't the underwear bomber." Now, sadly, we have an example of one.
Lewis Page, an "improvised-device disposal operator tasked in support of the UK mainland police from 2001-2004," pointed out that this isn't much of a threat for three reasons: 1) you can't stuff a lot of explosives into a body cavity, 2) detonation is, um, problematic, and 3) the human body can stifle an explosion pretty effectively (think of someone throwing himself on a grenade to save his friends).
But who ever accused the TSA of being rational?
Friday, September 25, 2009
Wednesday, August 05, 2009
Counterproductive Security
The numerous incidents of defeating security measures prompts my cynical slogan: The more secure you make something, the less secure it becomes. Why? Because when security gets in the way, sensible, well-meaning, dedicated people develop hacks and workarounds that defeat the security.......We are being sent a mixed message: on the one hand, we are continually forced to use arbitrary security procedures. On the other hand, even the professionals ignore many of them. How is the ordinary person to know which ones matter and which don't? The confusion has unexpected negative side-effects. I once discovered a computer system that was missing essential security patches. When I queried the computer's user, I discovered that the continual warning against clicking on links or agreeing to requests from pop-up windows had been too effective. This user was so frightened of unwittingly agreeing to install all those nasty things from "out there" that all requests were denied, even the ones for essential security patches. On reflection, this is sensible behavior: It is very difficult to distinguish the legitimate from the illegitimate. Even experts slip up, as the confessions reported occasionally in various computer digests I attest.
Saturday, May 16, 2009
Stupid Security Strikes again
The mad dictatorship of the 'security' industry reached new depths of lunacy when a Japan-bound traveller was stopped at Heathrow for carrying a paperback thriller with a picture of a gun on the cover.
When Carolyn Burgess placed her Robert B. Parker novel, A Triple Shot Of Spenser, on the security tray she had it snatched away because it 'might upset passengers' on the plane. It had the image of a handgun on the front.
Eventually, after three officials had consulted each other on this serious matter, Mrs Burgess, a 58-year-old bank worker, was told she could take the book on the plane – provided she kept it in her bag and didn't read it.
A spokesman for BAA attempted to explain this loopy behaviour by saying: 'In certain circumstances, a passenger carrying an item which features an image or slogan that could be perceived as aggressive may be asked to cover it up or remove it. Security officers are advised to use common sense when making these requests.'
At least the book wasn't blown up in a controlled explosion.
Tuesday, October 14, 2008
Clever antiterrorism plan
Used against the IRA:
One of the most interesting operations was the laundry mat [sic]. Having lost many troops and civilians to bombings, the Brits decided they needed to determine who was making the bombs and where they were being manufactured. One bright fellow recommended they operate a laundry and when asked "what the hell he was talking about," he explained the plan and it was incorporated -- to much success.The plan was simple: Build a laundry and staff it with locals and a few of their own. The laundry would then send out "color coded" special discount tickets, to the effect of "get two loads for the price of one," etc. The color coding was matched to specific streets and thus when someone brought in their laundry, it was easy to determine the general location from which a city map was coded.
While the laundry was indeed being washed, pressed and dry cleaned, it had one additional cycle -- every garment, sheet, glove, pair of pants, was first sent through an analyzer, located in the basement, that checked for bomb-making residue. The analyzer was disguised as just another piece of the laundry equipment; good OPSEC [operational security]. Within a few weeks, multiple positives had shown up, indicating the ingredients of bomb residue, and intelligence had determined which areas of the city were involved. To narrow their target list, [the laundry] simply sent out more specific coupons [numbered] to all houses in the area, and before long they had good addresses. After confirming addresses, authorities with the SAS teams swooped down on the multiple homes and arrested multiple personnel and confiscated numerous assembled bombs, weapons and ingredients. During the entire operation, no one was injured or killed.
Tuesday, October 07, 2008
Sneaky
Turns out you can add anyone's number -- or remove anyone's number -- to/from the Canadian do-not-call list. You can also add (but not remove) numbers to the U.S. do-not-call list, though only up to three at a time, and you have to provide a valid e-mail address to confirm the addition.
Here's my idea. If you're a company, add every one of your customers to the list. That way, none of your competitors will be able to cold call them.
No charge.
Thursday, October 02, 2008
Rent a decoy
Now this is clever:
"I came across the ad that was for a prevailing wage job for $28.50 an hour," said Mike, who saw a Craigslist ad last week looking for workers for a road maintenance project in Monroe.He said he inquired and was e-mailed back with instructions to meet near the Bank of America in Monroe at 11 a.m. Tuesday. He also was told to wear certain work clothing.
"Yellow vest, safety goggles, a respirator mask...and, if possible, a blue shirt," he said.
Mike showed up along with about a dozen other men dressed like him, but there was no contractor and no road work to be done. He thought they had been stood up until he heard about the bank robbery and the suspect who wore the same attire.
Thursday, September 18, 2008
How they did it
The AP reports the hacker impersonated Palin, using the "forgot your password?" feature to gain access. He simply gave Palin's birthdate and zipcode, and then answered the secret question, "Where did you meet your spouse?" The answer, of course, was "Wasilla High." He showed up on a forum yesterday to brag about his feat under the name, "Rubico."
I have a few accouts with similar features. Most of them e-mail the password (or reset the password and e-mail a temporary password) to your registered e-mail address. But your e-mail service may not have that option. Instead, a challenge-and-response system is used. The user is asked to supply information other people won't have access to.
Unfortunately, that sort of information is very hard to find in the average life. Birthdates get recorded by social networking sites, unless users take care not to provide them. They're probably also on any number of public documents -- if not in one place, then certainly scattered around several. And if you know a famous person's address, you can get the zip code from Mapquest or smilar services.
Other "secret questions" are not that hard to guess. If you're known to have grown up in a particular city, the name of the high school is usually a fairly small set of possibilities. The make of your first car, also a fairly restricted set. (The name of your first car is a bit harder. My ex suggested the car we were using at the time be named "Imelda" because it kept needing new brake shoes.)
A secure password is a good way of restricting access to authorized users. You have a large target space, and a very small target to hit by random guessing. (Even a four-digit PIN is secure, because someone standing at an ATM punching in numbers for half an hour is bound to draw attention.) (But I'd still like the option to have a longer PIN.)
Every pathway that allows access to someone who's forgotten his password is another target to aim at, and one where, as I've mentioned, the number of false targets may not be as large as it is for a password. And if a site is anything like some I've gotten accounts for, there may be as many as half a dozen "secret questions" that might come up. Each one of those is an access way of unknown size.
Hopefully, you're already picking your passwords with care. Pick your secret questions and answers with equal care. (Maybe, any question about cars, you could decide you'll always give the correct answer about pets? But you need to be consistent enough that you'll remember it when you need it.)