« Google's product design can be scary good | Main | Negotiating the Option Pool »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341df5ce53ef00d834b4579553ef

Listed below are links to weblogs that reference For security purposes, what is your favorite color?:

Comments

dnl2ba

I'm no security expert, but I don't see why this is a problem. Obviously, if they let you in just based on your "security question" answer, then the security is bad because I'm likely to have named my first pet something an attacker might have in a dictionary (or a personal acquaintance could know it or look it up on the Internet, or whatever). But if they just email you a login link, what's the harm in that? Unless your attacker has access to the chain between their mail server and yours, how do they get access to the mailed new password or login link?

Dorrian

Thanks for mentioning. I think I've known that the original intention was only to send email, but I bet many sites down the line have lost sight of that and just do it for password recovery. I still find my experience with my bank shocking because they are using it for identity purposes.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment