How to Do Password Resets Right

Ben Rothke on four overlooked security risks in the password reset process (and how to address them).

» View Article

READER FEEDBACK
Preview
ron
Thu, 2008-12-04 23:14

Did you really look at that list of "good" questions?

What street did you live on x grade?
Childhood phone number?
Street number you grew up in?

Aren't the the first 3 info that could be aggregated easily enough. In my case, they haven't changed in x (too many to admit) years. If they do any research to learn where I grew up, all they need to do is look up my parents in the phone book.

And there are bunch of question in that list about siblings, isn't that also info that can be aggregated.

Why is "What was the last name of your third grade teacher?" Good,
What is the name of your favorite childhood teacher? Fair and
What was the last name of your favorite teacher? Poor

Granted, there are several questions on the list that sound good, I just wonder what criteria they used to create the not good lists (the good criteria are listed on another page at that site).

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.