Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Doesn't that make it the perfect question? For someone to answer the question correctly, they have to demonstrate that they don't even need to do so, because they already know the thing you wanted to protect?


Along that reasoning... I'm from your bank. Please give me your account # and PIN.


No, that doesn't work: if you really think that is a good argument, then everyone is also a fool for believing "enter your password here to log in"; remember that you are answering a password reset challenge question at the same site you would normally enter your password.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: