Post
Topic
Board Meta
Re: Secret Question issue: theymos, consider hassle to recover locked account
by
actmyname
on 27/04/2018, 11:45:03 UTC
-snip-
The secret question is usually the last thing that people will resort to when they have lost their password. With an email, you can retrieve the password through a simple reset. When a user doesn't have an email/loses their email wouldn't it make sense to lock an account for verification if they reset using the secret question?

Especially considering the fact that the answer is usually far less secure than passwords.