Hacker News new | ask | show | jobs
by Freak_NL 3342 days ago
Don't do that unless you don't care about that account. Often the answer to a security question effectively acts as a password. You are not defending against someone guessing your answer, you are defending against someone using an automated dictionary attack. A common word like 'potato' scores quite high in the common password lists.

A safer option is to just generate a random password for those questions as well and store it on your password manager.

1 comments

If you do that then it's super easy to social engineer the company in question. "I don't know what I put for mother's maiden name, I just mashed the keys a lot on that".
Apple does not allow. If u forgot your security questions you cannot add 2FA