Identity questions

Overview#

Identity questions are often used for Identification or Password Recovery (Password Reset) purposes.

The Identity questions feature is a security anti-pattern.

Identity questions typically includes, but is not limited to:

Security Considerations#

Identity questions Example#

Sarah Palin's Yahoo! email account got hacked during a previous presidential campaign because the answer to her security question was... "Wasilla High School"!

Even with user-specified questions, it is highly likely that most users will choose either:

In conclusion, security questions are inherently insecure in virtually all their forms and variations, and SHOULD NOT be employed in an authentication scheme for any reason.

The true reason why security questions even exist in the wild is that they conveniently save the cost of a few support calls from users who can't access their email to get to a reactivation code. This at the expense of security and Sarah Palin's reputation. Worth it? Probably not.

More Information#

There might be more information for this subject on one of the following: