
“What is your mother’s maiden name?” “What was your first pet?” Security questions feel old-fashioned, and there is a real problem with them: the honest answers are often things a stranger can find or guess. The fix is simple once you see it. Our GetMyPassword team explains why security questions are weak and how to answer them in a way that actually protects you.

Why security questions are weak
Security questions were meant to verify it is really you, but they often do the opposite. Real answers — your hometown, your first school, your pet’s name — are frequently public on social media or easy to guess. Worse, they never change, so once an answer leaks in a breach, it is compromised forever. In effect, they can be a weaker backdoor around your strong password.
Treat answers like passwords
Here is the key shift: a security question does not need a true answer, just a consistent one. So give it a random, fake answer — treat it like a second password. Your “first pet” can be 7ygT-violet-anchor. It cannot be researched or guessed, because it has nothing to do with your real life.
- Use a unique random answer for each security question.
- Store it in your password manager alongside the account login.
- Never use real, findable facts about yourself.
- Keep answers different across sites, just like passwords.
A security question is just another password with a hint attached. Answer it with the truth and you hand attackers the hint for free; answer it with nonsense only your password manager knows, and it becomes a real lock.
Generate and store your answers
The easiest way to do this is to generate each answer like a password. Use our password generator to create a short random string for every security question, then save it in your password manager’s notes for that account. You never have to remember them, and you turn a notorious weak spot into one more thing an attacker simply cannot beat.
Frequently asked questions
Should I answer security questions truthfully?
No. True answers are often public or guessable. Use a random, fake answer for each question and store it in your password manager, so the answer cannot be researched or guessed by an attacker.
Why are security questions considered insecure?
Because honest answers are frequently findable on social media or easy to guess, and they never change, so a leaked answer stays compromised. That can make them a weaker backdoor around an otherwise strong password.
How do I remember fake security answers?
You don’t have to. Store each random answer in your password manager alongside the account, the same way you store passwords. You only need to look it up if a site ever asks the question.



