"Security question answers" are akin to auxiliary passwords, which users will not use on a daily basis. Remembering a password that you almost never type is hard. Requiring exact case is likely to make the user fail to answer properly.

On a theoretical point of view, a "security question" is already a huge weakness, which you tolerate because some users will forget their password, and you want to handle that case with as much automation as possible, and not asking any security question would be even worse security-wise. Hence, the added value of security questions is that they allow a not-totally-open password reset process which can nonetheless be conducted automatically, i.e. at minimal cost for the server. Case sensitivity would probably remove much of that value. Actually, I would even recommend normalization by suppressing whitespace, punctuation and accents.

Answer from Thomas Pornin on Stack Exchange
🌐
Quora
quora.com › Are-the-answers-to-security-questions-case-sensitive
Are the answers to security questions case sensitive? - Quora
Answer (1 of 2): Today no. Unless they specifically tell you they are sensitive. If the security questions are single answers then no problem. However, if for example the question was, “What was your first car?” you might want your answer ...
Top answer
1 of 3
19

"Security question answers" are akin to auxiliary passwords, which users will not use on a daily basis. Remembering a password that you almost never type is hard. Requiring exact case is likely to make the user fail to answer properly.

On a theoretical point of view, a "security question" is already a huge weakness, which you tolerate because some users will forget their password, and you want to handle that case with as much automation as possible, and not asking any security question would be even worse security-wise. Hence, the added value of security questions is that they allow a not-totally-open password reset process which can nonetheless be conducted automatically, i.e. at minimal cost for the server. Case sensitivity would probably remove much of that value. Actually, I would even recommend normalization by suppressing whitespace, punctuation and accents.

2 of 3
1

Security questions are basically another password. Ideally it should thus have the same properties as a password i.e. reasonable length (greater than 8 characters) being the most important to defend against guessing and bruteforce.

This research study was posted here in a previous question: https://docs.google.com/viewer?a=v&pid=sites&srcid=ZGVmYXVsdGRvbWFpbnxyZXVzYWJsZXNlY3xneDozNDcwNDhmMmE2MmJiMDkw

Its conclusions are that complexity is not that important against an online entry. Thus if you check for basic dictionary words, username etc, have sufficient length and implement an account lockout or exponential backoff, there is no significant benefit in also requiring complexity.

Of course the best would be to eliminate secret questions and add an out of band password reset method such as SMS one time password or even email one time password / link. Or stop managing passwords altogether and support an OAuth (e.g. Facebook connect) or Open-ID (Google etc) based method of authentication.

🌐
Droidrant
droidrant.com › home › are windows 10 security questions case sensitive?
Are Windows 10 Security Questions Case Sensitive? [Answered 2023]- Droidrant
July 5, 2022 - The answers are case-insensitive, but you must be able to remember them. You can also use the security questions to reset your password if you forget it. The answers to security questions should be at least six characters long and contain upper and lower-case letters, digits (0-9), special ...
🌐
AskVG
askvg.com › home › help and how-to guides › [tip] how to reset forgotten user account password in windows 10
[Tip] How to Reset Forgotten User Account Password in Windows 10 – AskVG
May 21, 2018 - When you install newer versions ... question. In fact you can use same answer for all 3 questions if you want. The answers are not case-sensitive....
🌐
NinjaOne
ninjaone.com › home › blog › it ops › updating security questions for local accounts in windows 10 & 11
Updating security questions for local accounts in Windows 10 & 11 | NinjaOne
1 month ago - Use the command ms-cxh://setsqsalocalonly in the Run dialog to access the security questions interface. Try variations: Security answers are case-sensitive, so try different capitalizations of your answers.
🌐
MMO-Champion
mmo-champion.com › forum › video games › star wars: the old republic
are security questions case sensitive?
Nope, it isn't. I got my account locked the other day actually because I entered it wrong too many times. After calling customer support, I found out I had added an extra letter to my security answer, hence why it wouldn't work, ie. typo. ... Actually when I went through account recovery in ...
🌐
Password Bits
passwordbits.com › security-questions-faq
Security Questions FAQ + Tips - Case Sensitive? Exact? Truthful? - Password Bits
September 12, 2022 - I want to address people’s more common questions about security questions and give you some tips to make better security questions. Most websites don’t use case-sensitive security questions.
Find elsewhere
🌐
Windows10bro
windows10bro.com › change-security-questions.html
Change your security questions in Windows 10
Click on the first dropdown and select one of the six pre-approved questions: Tip: for Windows and other services, you never know if security answers are case-sensitive. (Uppercase and lowercase are considered different letters.) So, stick to always answering in lowercase: you'll never wonder ...
🌐
Reddit
reddit.com › r/windowshelp › forgot windows 11 password and security questions but still have pin and fingerprint access
r/WindowsHelp on Reddit: Forgot Windows 11 password and security questions but still have pin and fingerprint access
December 28, 2022 -

Hello all,

So like the title says I have forgotten the password to my laptop. I believe I changed the password over a year ago and never really used it ( just the pin and fingerprint) and clearly picked something irregular. In turn, the three security questions I cant seem to get the answers right (although I know what they should be), at least one is wrong and im not sure if they are case sensitive but a quick google search suggests no. I can still log in easy enough because I have my fingerprint and pin access but I dont want to wait around for the laptop to require a password log in.

There is a microsoft account attached to the computer but resetting the microsoft account password (which I knew anyway) has no effect on the computer password (I assume it is a local account).

Additional notes:

The laptop used to use windows 10 operating system but I upgraded it to windows 11 recently.

I have seen two possible ways of fixing this issue on the internet so far but they seem kind of dodgy so I have avoided them.

Below is the link to the first one (although the comments suggest if your device has encryption on it it will not work, so I turned off encryption in the settings but BitLocker encryption might still be active, not sure).

www.youtube.com/watch?v=0gOZoroPNuA&ab_channel=Britec09

The second option I have seen is creating a second administrator account and using that to change the password on this account but that seems surprising that that would work.

I do not have a password reset disk.

If I go into settings < accounts < sign-in options < password, i can try passwords over and over again with little fus. I can also go to the sign in screen and try the security questions over and over.

From my searches so far it looks like im kinda bonned though i think but thought id ask.

Edit:

  1. Removed some information.

  2. Solved. I ended up doing the following to change my password. Open cmd as administrator (being already logged in with pin/fingerprint obviously). Type in 'net user'. This identifies all the accounts on your computer: "Administrator, UserName, Guest, etc". Once you identify your account (whatever UserName is) you can type in 'net user UserName *' and will be prompted to type and retype a new password for the user.
    Before I logged out I changed my security questions which in windows 11 can be found by typing "ms-cxh://setsqsalocalonly" into the run command and typing in your new password. I also created a 'physical password reset disk' using a usb.
    Got a bit stressed when my fingerprint and pin number stopped working within windows (checked by trying to look at my passwords in my browser which prompts you to sign-in with one). However, this was because I had changed the password and hadnt logged back in yet. I have now logged in and out several times and checked fingerprint and pin number are working properly to log in as well.

🌐
Onlinecloudsecurity
onlinecloudsecurity.com › home › are security questions case sensitive?
Are Security Questions Case Sensitive? | Online Cloud Security
January 20, 2022 - Quick Answer: Unless the service provider expressly states that they are case sensitive, security questions are typically not case sensitive, however, you must ensure that the space is present if there is a gap between two words.
🌐
JanBask Training
janbasktraining.com › community › cyber-security › are-security-questions-case-sensitive
Are security questions case sensitive? | JanBask Training Community
April 7, 2022 - The answer is - Security questions are basically another password. Ideally it should thus have the same properties as a password i.e. reasonable length (greater than 8 characters) being the most important to defend against guessing and bruteforce.
🌐
Accruent
help.accruent.com › tms › Content › Online_Help › GettingStarted › Security_Questions.htm
Security Questions
Security question answers are not case sensitive. To update your security question selections and/or answers, follow the steps below: ... From this window you can change which security questions you've selected to answer as well as the answers to any of your security questions.
🌐
JCurve Solutions
jcurvesolutions1.zendesk.com › hc › en-us › articles › 203319649-Setting-Up-Security-Questions
Setting Up Security Questions – JCurve Solutions
Tip: Remember, security question answers are not case sensitive, so do not waste an attempt by simply changing some characters to a different case.
🌐
DocuSign Community
community.docusign.com › docusign-maestro-80 › what-to-do-if-security-questions-fail-857
What to do if security questions fail? | Community
March 17, 2022 - If you are trying to reset your ... inputting the answer to your security questions. Please keep in mind that the security question is case-sensitive......
🌐
OS Today
frameboxxindore.com › apple › are-windows-10-security-questions-case-sensitive.html
Are Windows 10 security questions case sensitive?
September 5, 2021 - No, they are not case-sensitive. How to update local account security questions on Windows 10
Call   OS Today
Address   https://frameboxxindore.com