❓ Security Question Answer Generator

Real answers to security questions (mother's maiden name, first pet, etc.) are often findable online or guessable by someone who knows you. Generate a random, unrelated answer instead — and save it in your password manager alongside the question.

What the two styles produce

Both styles draw from the same fixed list of 25 words. Random words joins three of them with hyphens; Word + number appends a three-digit number from 100 to 999:

Random words   25^3     = 15,625 = 13.9 bits
Word + number  25 x 900 = 22,500 = 14.5 bits

Fourteen bits is nothing next to a password and does not need to be: the attack on a security question is a person who read your social media, not a GPU farm. Words are drawn with replacement, so Copper-Copper-Nimbus can come up and is perfectly fine.

Making the answer usable later

The risk runs both ways: an answer you cannot retrieve removes the recovery route you would need when locked out, and a support agent may accept a near miss over the phone, which no generator can control. Nothing here is sent anywhere or stored.

Frequently asked questions

Can I put a fake answer to a security question?

Yes, and you should. Nothing checks whether your first pet was really called Basalt-Trellis-Voltage. Your mother's maiden name and the street you grew up on are matters of public record; a random phrase is not.

Are security questions actually secure?

No, which is why NIST SP 800-63B tells verifiers not to use knowledge-based authentication at all. Real answers are low entropy, often public, and reused at every site that asks. Where you cannot avoid the question, a random answer turns a known fact into a stored secret.

Should the answer be as strong as a password?

It cannot be, and does not need to be. These answers are checked at a rate-limited form or by a human, not against a stolen hash file, so 14 bits of genuine unpredictability beats a real answer that is findable in one search.