Hacker News new | ask | show | jobs
by cycomanic 1367 days ago
> At one point I had to click a link in the recovery email and enter the month when the account was created.

Seriously?! Who comes up with these security questions? This is such a useless question, on the one hand it's insecure because it is a 1/12 chance of guessing right, but also who remembers what month they created an email account? I would venture a guess most people here couldn't even get the year right (I certainly couldn't). Seems the question is only useful to lock out the legitimate owner.

1 comments

>on the one hand it's insecure because it is a 1/12 chance of guessing right, but also who remembers what month they created an email account?

IIRC, they require both month and year, so there'd be a bit more guesswork involved. I added the exact creation date for all my Google accounts to my password manager when I learned about this verification method.

Ouch... I just checked mine, and I was right about the month but off by 3 years.