Security questions on websites for password recovery
Are so dumb and annoying.
“Have you forgotten your password? Well, all you need to do to get it back is remember which of these questions you selected when you signed up for this website (and not any other website, which probably has a very similar list of questions) and which answer you gave for it at the time.”
Aggggghhhhhh, fuck off!!
Firstly, sorry, but I can’t remember question which I chose when signing up for this website, so I guess I’ll have to try each in turn.
Secondly, lots of these I could have given multiple possible answers to. ’Place of Birth’? I could have put ‘Madeley’ or ‘Telford’ or ‘Shropshire’ or ‘England’ or ‘Home’ or ‘26 Canonbie Lea’. ’Favourite Animal’, I don’t know, if I’d seen a squirrel that morning I’d probably have said that, ‘Cat’ perhaps?, narwhals and nudibranchs are both very cool, and I may have put that if I’d seen them on TV recently. ‘Favourite Food’? God, I don’t know, ‘Bacon’?, or, ummmm, well, errrr, … yeah, probably ‘Bacon’ for that actually.
Thirdly, lots are questions that lots of people would know the answer to, or could easily find out, so aren’t that secure at all, like mother’s maiden name, so I either pick a question with a less obvious answer (which takes us back to the second problem), or I lie, and then forget what my lie was.
The only real solution to the first and second problems are to always chose the same question (if possible) and always give the same answer, but that doesn’t seem all that secure.
Just give me my password back!!!
(thank god 1Password usually protects me from this hassle)