Of course, the same apps with security questions are probably the ones not hashing your actual password in the first place.
Think about last names, as well... there's huge variety in length, spelling, etc. -- it's poor customer service to force the customer to spell it out letter by letter -- so it's necessarily just displayed there on their screen.
The problem is that most sites won't let you set your own question. More about my idea on security questions: http://lucb1e.com/!65
One of the worst sites I saw demanded that I select my security question from a list. Sweet gosh, I have absolutely no idea which of your brain-addled security choices I selected.
"...but the account is being used for malicious purposes." - me
"Sorry, sir but until you tell me what you named your first dog I cannot stop it." - AOL
Do you mind if I quote you (with link) on my blog?
Google, too. I suggest you run through the recovery process yourself (on a dummy account, or your own) to see the kinds of questions asked. Questions like "when did you last access the account?" are easily answered; as is "name 5 regular contacts"; and so on. I could (but would not) perform the recovery process (and gain access to) acquaintances accounts, given how simple the questions are.
The key is just knowing "enough" in aggregate to pass their bar.