3 ms·
It's pretty clear that our 'personal' information just isn't so personal anymore, so I think that it's a good idea for companies that use verification questions
by ydavid 18y ago
It's pretty clear that our 'personal' information just isn't so personal anymore, so I think that it's a good idea for companies that use verification questions to be very careful to determine that the verification questions that they use for password reset or identification purposes contain truly 'private' information. It's scary when I call up a bank and I can get full access to my account by just giving my account number and my mother's maiden name. Isn't that information in a database somewhere? If I'm on facebook and my mom is on facebook, how hard is it to figure that out? Genealogy websites would probably also be a great help to dig up this info.
My other favorite verification questions are "Where were you born?" and "What's your birthday?". Hm... these are also Facebook profile questions, and they're also not so hard to dig up.
I thought that my social security number was private at least, but last week (no joke) I got a letter in the mail from UPenn saying that a university researcher's laptop containing my social security number had gone missing. fun fun.
My recommendation for web developers would be to rely on users having control of their email accounts and to not allow for "security questions." And if there is a problem with someone's email account being hacked, speak with the customer and use your common sense to resolve the situation. You can always just suspend the account pending the outcome of your 'investigation'. But please please don't outsource this 'investigation' task to people who lack communication skills and/or common sense. (e.g. PayPal, eTrade, Citibank & Dell)