Hacker News new | ask | show | jobs
by quantumfoam 2993 days ago
I usually just do a random hash. Also, really, really hate the sites that do not allow you free form text the question itself and rather populate a bunch of commonly known ones. FFS, if you're a web developer working on security questions, let the user make up the question. Agreed though, we should just do away with this as an authentication factor.
1 comments

Let the user make up a question and remind them that they might need to answer it over the phone so they don’t choose something embarrassingly personal.