Hacker News new | ask | show | jobs
by Loocid 631 days ago
If you're storing it next to the password, then you've killed the point of the recovery questions anyway. May as well not store them at all.
2 comments

If that's an option it's usually what I do but often they're mandatory.
That assumes that there's no other way to get your password than by accessing the contents of your password manager. The service itself could have its passwords/hashes leaked, and people unfortunately do reuse passwords across services even with a password manager, so it's very plausible for someone to get your password but not the answers to your questions.