TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Why do sites still ask me to do security questions?

9 点作者 irunmyownemail7 个月前
It's 2024, there are still today, sites asking for security questions when registering as a new user?

5 条评论

pwg7 个月前
Because their &quot;security checklist&quot; had an item inserted 18.5 years ago that says: &quot;must have security questions&quot; and so to pass their security audit (i.e., check the boxes on the checklist) they have to request security questions.<p>The best way to answer &quot;security questions&quot; is below:<p>sort --random-sort --random-source=&#x2F;dev&#x2F;urandom &#x2F;usr&#x2F;dict&#x2F;words | head -5 | tr $&#x27;\n&#x27; &quot; &quot; ; echo<p>Adjust the head -5 to adjust how many words are output. Then your answer to &quot;what was the name of the first street you lived on&quot; could be:<p>crunched shirt wins ambushed titter<p>You gain an answer that has no relation to the question, as well as an answer that is easy to recite over the phone to a person (should the need arise).
评论 #42084927 未加载
solardev7 个月前
Why do we still have dumb password requirements? Why do we have SMS based 2FA? Why aren&#x27;t we all using passkeys?<p>Security changes take forever. Old school sys admin and IT security types don&#x27;t really like to keep up with web changes. And users don&#x27;t know any better. And grandma is probably less likely to mess up a security question than figure out what to do when she upgrades her phone and loses all her 2FA.
评论 #42092439 未加载
评论 #42088698 未加载
syndicatedjelly7 个月前
The bad guys get better faster than the good guys do
评论 #42084175 未加载
评论 #42084975 未加载
cpach7 个月前
Haven’t seen that for years.
评论 #42092444 未加载
meiraleal7 个月前
Bots signing up is a solved issue and I didn&#x27;t get the memo?
评论 #42092449 未加载