Brokerage login now requiring I answer these questions. Not a single one of these has a single answer I’d actually remember. They all have problems regarding what would actually count or multiple possible answers to choose from, or these are not things people would remember or they just don’t apply to most people.

  • Piatro@programming.dev
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    1
    ·
    1 day ago

    So-called “security questions” like these are prohibited under various standards (there’s a NIST one that I can’t remember exactly, and OWASP ASVS) because they’ve always been really terrible at verifying it’s actually you answering them, and not just someone who happens to know the answer. Mother’s maiden name being the notorious example.