3 ms·
If you're relying the extra protection of an exact match over a match with a Levenshtein distance of 1, your security question isn't secure to begin with. Prop
by DanielStraight 10y ago
If you're relying the extra protection of an exact match over a match with a Levenshtein distance of 1, your security question isn't secure to begin with.
Proper management of security questions is pretty straightforward: Set them to a long random string and keep track of them as if they were another password.
If you do that, the fuzzy matching shouldn't be a problem at all. If you're using real answers that are easy to obtain from knowing anything about you, exact matching isn't helping.
- jason_slack 10y agoThis is a good idea. I'll try this approach.