Post
Topic
Board Meta
Re: How to reset/disable secret security answer?
by
madmax6688
on 18/01/2015, 09:53:49 UTC
-snip-
You are right, you really should not be using a security question

If used correctly it can work as a second password. A security question which has an answer that can easily obtained by social engineering and/or research online is certainly worthless. Examples would be:
What is your mothers maiden name? -> answer: *mothers maiden name*
What is the name of your first pet? -> answer: *name of first pet*
etc.
A good use of the system would be to phrase a meaningless question and put another password as the answer, e.g.:
Want some coffee? -> answer: *WtQjXeWGHSYmJuFEDvzBa2V*

If you store the answer in a secure location you have a fallback login should you ever forget your usual password.

Instead just use an email, security questions aren't really needed if you use a strong email.