Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It shows how careless the industry is that these security questions persist. Sarah Palin’s Yahoo! account was handed by someone guessing easily accessible security questions. That was 17 years ago.

When backward systems force you to answer these questions, I agree it’s better to generate a random string just for this question and provider. Plus it’s a fun time on the odd occasion these extra questions are required in a phone call.

“To complete security, what was your first pet’s name?”

“I’ll never forget dear PMM&7Qhdcim6WdJ:2XaviMw”



To get an account back, once I got something like:

> Which is your favotite food?

> Please select your old answer:

> 1) banana

> 2) apple

> 3) t5$2eoW

> 4) pear


Are you Elon Musk? :)

But suriosly good advice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: