TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Why do sites still ask me to do security questions?

9 pointsby irunmyownemail7 months ago
It's 2024, there are still today, sites asking for security questions when registering as a new user?

5 comments

pwg7 months ago
Because their &quot;security checklist&quot; had an item inserted 18.5 years ago that says: &quot;must have security questions&quot; and so to pass their security audit (i.e., check the boxes on the checklist) they have to request security questions.<p>The best way to answer &quot;security questions&quot; is below:<p>sort --random-sort --random-source=&#x2F;dev&#x2F;urandom &#x2F;usr&#x2F;dict&#x2F;words | head -5 | tr $&#x27;\n&#x27; &quot; &quot; ; echo<p>Adjust the head -5 to adjust how many words are output. Then your answer to &quot;what was the name of the first street you lived on&quot; could be:<p>crunched shirt wins ambushed titter<p>You gain an answer that has no relation to the question, as well as an answer that is easy to recite over the phone to a person (should the need arise).
评论 #42084927 未加载
solardev7 months ago
Why do we still have dumb password requirements? Why do we have SMS based 2FA? Why aren&#x27;t we all using passkeys?<p>Security changes take forever. Old school sys admin and IT security types don&#x27;t really like to keep up with web changes. And users don&#x27;t know any better. And grandma is probably less likely to mess up a security question than figure out what to do when she upgrades her phone and loses all her 2FA.
评论 #42092439 未加载
评论 #42088698 未加载
syndicatedjelly7 months ago
The bad guys get better faster than the good guys do
评论 #42084175 未加载
评论 #42084975 未加载
cpach7 months ago
Haven’t seen that for years.
评论 #42092444 未加载
meiraleal7 months ago
Bots signing up is a solved issue and I didn&#x27;t get the memo?
评论 #42092449 未加载