3 ms·
The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"
by floatboth 8y ago
The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"
- palunon 8y agoYou have no obligation to answer the secure questions truthfully, or not to write a long random string of text... Starting with "Do not accept the answer if I can't spell this exactly" in case a human gets involved...
- Terr_ 8y agoIt frustrates me how almost every company's "secure question" system is utterly retarded and recklessly dangerous. 1. They draw from fixed unimaginative pools of often-overlapping questions, so that a breach in one company compromises you on multiple others. 2. Unlike a password, the actual secret question is often plaintext If I had to design a replacement... The user would always be allowed to define custom questions, all questions could be assigned multiple synonymous correct answers (e.g. "Dr. Smith", "Doctor Smith"), and they all go through a one-way hash with salt.