Click here to Skip to main content
15,890,579 members

Welcome to the Lounge

   

For discussing anything related to a software developer's life but is not for programming questions. Got a programming question?

The Lounge is rated Safe For Work. If you're about to post something inappropriate for a shared office environment, then don't post it. No ads, no abuse, and no programming questions. Trolling, (political, climate, religious or whatever) will result in your account being removed.

 
GeneralRe: Absurd "Security Questions" Pin
Stephen Gonzalez14-Jun-16 10:14
Stephen Gonzalez14-Jun-16 10:14 
GeneralRe: Absurd "Security Questions" Pin
Worried Brown Eyes14-Jun-16 11:29
Worried Brown Eyes14-Jun-16 11:29 
GeneralRe: Absurd "Security Questions" Pin
TheGreatAndPowerfulOz14-Jun-16 10:37
TheGreatAndPowerfulOz14-Jun-16 10:37 
GeneralRe: Absurd "Security Questions" Pin
kdmote14-Jun-16 11:52
kdmote14-Jun-16 11:52 
GeneralRe: Absurd "Security Questions" Pin
Kirk 1038982115-Jun-16 3:49
Kirk 1038982115-Jun-16 3:49 
GeneralRe: Absurd "Security Questions" Pin
agolddog15-Jun-16 3:53
agolddog15-Jun-16 3:53 
GeneralRe: Absurd "Security Questions" Pin
scmtim15-Jun-16 4:29
scmtim15-Jun-16 4:29 
GeneralRe: Absurd "Security Questions" Pin
joequincy15-Jun-16 4:55
joequincy15-Jun-16 4:55 
Specifically responding to your update:

I wish it was that easy. I work at the customer service level of a financial business that recently implemented "build your own" style security questions. The form is as self-explanatory as can be...
Password Reset Security Question {input element}
Password Reset Answer {input element}

This just confuses the hell out of users. I have to walk an average of one person per day through the process, and thoroughly explain that "here you can type out your own question, which will be shown to you when you request a password reset. Below, you put in the answer to that question." This is a basic concept to those of us who have experience in site development and high-level security concepts... but to the average user, it's mind boggling. In some cases, I even end up recommending that the user leaves those fields blank (in that case, they simply cannot self-initiate a password reset, and must call or come in to one of our offices. It's more work for us, but doesn't add a security risk). There are plenty of people who are far too impatient to even attempt to figure it out, and for them, I'm glad our situation has a workaround for the concept.

This isn't to say that the concept needs reworking. Security questions as they are typically implemented are appallingly insecure, and depend on essentially public data. This is bad, and needs to be addressed by the industry at large. On that, we are completely agreed.
GeneralRe: Absurd "Security Questions" Pin
kdmote15-Jun-16 7:16
kdmote15-Jun-16 7:16 
GeneralRe: Absurd "Security Questions" Pin
Walt Borovkoff15-Jun-16 7:47
Walt Borovkoff15-Jun-16 7:47 
GeneralRe: Absurd "Security Questions" Pin
kdmote15-Jun-16 8:25
kdmote15-Jun-16 8:25 
GeneralRe: Absurd "Security Questions" Pin
maze315-Jun-16 5:19
professionalmaze315-Jun-16 5:19 
GeneralRe: Absurd "Security Questions" Pin
PIEBALDconsult15-Jun-16 11:02
mvePIEBALDconsult15-Jun-16 11:02 
GeneralRe: Absurd "Security Questions" Pin
thewazz15-Jun-16 12:36
professionalthewazz15-Jun-16 12:36 
GeneralRe: Absurd "Security Questions" Pin
kdmote15-Jun-16 15:16
kdmote15-Jun-16 15:16 
GeneralMSIn Pin
ridoy14-Jun-16 5:17
professionalridoy14-Jun-16 5:17 
GeneralRe: MSIn Pin
jeron114-Jun-16 5:20
jeron114-Jun-16 5:20 
GeneralRe: MSIn Pin
OriginalGriff14-Jun-16 5:40
mveOriginalGriff14-Jun-16 5:40 
GeneralRe: MSIn Pin
Kornfeld Eliyahu Peter14-Jun-16 6:00
professionalKornfeld Eliyahu Peter14-Jun-16 6:00 
GeneralRe: MSIn Pin
OriginalGriff14-Jun-16 6:08
mveOriginalGriff14-Jun-16 6:08 
GeneralRe: MSIn Pin
Kornfeld Eliyahu Peter14-Jun-16 6:17
professionalKornfeld Eliyahu Peter14-Jun-16 6:17 
GeneralRe: MSIn Pin
ridoy14-Jun-16 10:15
professionalridoy14-Jun-16 10:15 
GeneralRe: MSIn Pin
ridoy14-Jun-16 10:14
professionalridoy14-Jun-16 10:14 
GeneralRe: MSIn Pin
Mark_Wallace14-Jun-16 6:52
Mark_Wallace14-Jun-16 6:52 
GeneralRe: MSIn Pin
ridoy14-Jun-16 10:17
professionalridoy14-Jun-16 10:17 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.