Security Questions
Dec
18
2014
I’m not sure what to think about security questions. You know, the things they make you answer when you forget your password.
There are some times when I wonder “why not do away with the password?” If answering a couple security questions is good enough to get a new password, then mabe it’s good enough to replace a password.
And some times I get asked a security question I don’t remember setting up, and there are multiple possible answers. In that case, what’s the fallback if I can’t get the answer right?
After seeing a few too many security questions to which I answered (in my head) “How am I supposed to know that?”, I was inspired to come up with a list of bad security questions.
For those developing login sequences, here are questions that will annoy your users:
- Who sat next to you in 3rd grade?
- What was your favorite baby food?
- How old were you when you got your first tooth?
- What country were your great-grandparents born in?
- What was your favorite color in 5th grade?
- How many second cousins do you have?
- How old were you when you lost your first tooth?
- What is your favorite noble metal?
- How long was your bus ride in middle school?
All of those are things which are ambiguous or I don’t know or they don’t have an answer.
Any other examples of bad security questions?
And when they had taken security of Jason, and of the other, they let them go.
Acts 17:9

This is Alpha, the first-born, when he was 2YO.
This is Beta, the second-born, when he was about 2YO.
This is Gamma, the third-born, when he was about 18MO.
