Hacker News new | past | comments | ask | show | jobs | submit login

Are you referring to 'security questions' where the user must choose from a predetermined list? A predetermined list which is often questions whose answers may be know to close attackers (first school), not applicable to everyone (name of first pet), or anglocentrically blind to worldwide cultural diversity (mother's maiden name). I hate that so much.

Providing a list is fine as long as they let the user type their own question if they want to. I cannot trust the security of a single one of their crap questions if I were to answer them honestly. However, if they let me type my own question, I can absolutely guarantee it.




Yeah those. I choose them in order, no matter the subject, and put a password manager passphrase in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: