5 ms·
Security questions are usually just used to decide whether to send you an email with a password reset link (or more annoyingly, a new password), aren't they? I
by FaceKicker 14y ago
Security questions are usually just used to decide whether to send you an email with a password reset link (or more annoyingly, a new password), aren't they? I've never seen a system where being able to answer the security question(s) is equivalent to knowing your password. Anyone who knows my mother's maiden name probably also knows my email address and could more easily spam me directly than using a website to send me password reset links.
- pbreit 14y agoYou are mostly correct and thus it is generally safe to use accurate answers. But, sadly, I have seen some systems skip the email step.
- nnnnnnnn 14y agoYes, but if you compromise email then they become easily guessable password equivalents.
- experiment0 14y agoAppleID's can be reset by knowing your email address, date of birth and normally 2 security questions.
- skymt 14y agoIn 2008 Sarah Palin's Yahoo! Mail account was broken into simply by looking up the answers to the security questions.
- donpdonp 14y agoPaypal's two-factor authentication, a hardware token in my case, has a screen to enter the security code but a link that says 'i dont have my token with me'. Clicking on that link prompts for the answers to two 'security questions'. Answer them correctly and you're in!
- jgeralnik 14y agoGmail, at least as of two years ago, let you choose a new password after correctly answering the security question. I once tried to answer the security questions to all of my close friends' accounts. I then sent the ones the I succeeded on (and was presented with a choose your new password screen which I then closed) and email suggesting that they change their security questions to something more secure.