3 ms·
Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same
by miah_ 11y ago
Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names.
What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.
- mjevans 11y agoI did that to my payroll account to try and prevent this very issue. Little did I know that it's one of those services you need the password (I had written that down at the time as it was temporary) AND these questions that are usually used for password resets. I don't think that will ever get fixed until I change jobs again.
- 8_hours_ago 11y agoUntil someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".
- ludamad 11y agoWhile avoidable with training, that brings up its own issue: What if what's being asked of the people taking these calls is outside their pay range?
- deleted 11y ago[deleted]
- aquadrop 11y agoI think all account credentials related things should be handled by special support people, who were trained to understand the situation. Shouldn't be that big percentage of all requests when people need to change/remember password and can't use regular ways.
- voltagex_ 11y agoThen the company's decisions on how much to pay their call centre staff has just opened up a possible vector for attack. Simple as that.