Hacker News new | ask | show | jobs
by dhimes 2209 days ago
But you should never give the correct answer for password recovery.

What is a belief you had as a child that you no longer have?

Purple Ocean.

And that can be your answer for all the questions: first pet name, elementary school, and so on.

2 comments

> But you should never give the correct answer for password recovery.

Exactly. You're supposed to use your password manager to generate a second password and use that as your answer. I know this sounds stupid but it is the only way to stay safe.

The only problem with this is if you have to read it to someone live. Otherwise, yes!
i've heard stories of call centers accepting "oh, i don't remember, i just typed a bunch of random letters and numbers" as confirmation over the phone.
Very good idea!
Good idea!