Authentication Designers: Don’t do security questions

PSA: Dear Authentication Service Designers, don’t do security questions, especially if support can read them.
No one wants to give away private information that can potentially be used to “hack” other accounts that also have security questions (and answers).
The name of my 1st pet? How often have I answered that? The NSA knows the answer to that question for sure 😉

So every time I give away one piece of “information only I should know” I weaken my own security, and you, authentication designers weaken the security of your users.
But maybe that’s what you want anyway.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.