Hacker News new | ask | show | jobs
by LinuxBender 2727 days ago
What are you protecting? Financial data? If so, have them go to a branch office and prove their identity to a person.

Which is more important, retaining the person, or protecting their data? If retaining the person, then give them some simple and less secure method like a recovery email address. If protecting the data, I would leave them locked out of their account. Unpopular opinion, but I do that a lot it seems.