This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.
For the record, I don't have a great answer to this either -- genuinely curious.
Or “what instrument do you play”, when multiple instruments I play are in the multiple choice list but only one can be correct. And what the fuck is the point of multiple choice security questions when anyone has a 1/10 chance of correctly guessing on any login attempt.
United Airlines is by far the worst major company I have ever seen in all of these and deserves to be shamed.
"42_red_banana_&"
"Mother's maiden name? Cruz-Valdez"
"First Concert? Lil' Mermaid"
"City you were born in? Ubuntu"
CSR: What's your mother's maiden name? Oh wait, looks like an issue on our side.
Me: No issue. My mother's maiden name is Q5D6Erty#76cjWE1H. She's Dutch.
Me: "ok, but it's some random text: Q 5 --"
CSR: "--yeah, ok, that's fine"
Since then I just make up a random, fake but real-sounding answer so the humans don't get confused.
CSR: "What is your mother's maiden name?"
Me: "do you really want me to say it?"
CSR: chuckling. "Yes, I need you to say it"
Me: "Diarrhea"
I get a little thrill every time.
The "password" here is only used over the phone in place of an account number or similar where a customer can't recall other information.
The reddit user here would have had to provide this password over the phone before to another agent. It's the only way for it to get there.
Source: I posted that on reddit.
Security questions in general are terrible so don't take this as if it's in defense of them.
My favorite are the presumptive ones that assume something like "Where did you meet your spouse?"
Someone should just go over the top: "Who was the editor of your first successful novel?" "What investment did you make your first billion with?"
Other than two about your birth location and mother's maiden name, both easily found answers for someone
"Your superhero name is the name of your pet + favorite teachers name"
You'd click on the comments and there's tens of thousands of people volunteering answers. Some are of part of the hustle to till the honeypot, but I'd see people I know comment on them with real information. It's wild
It is very hard to come up with universally good security questions.
You add let's say, up to 3 peoples names and mobile numbers for recovery and then they are contacted requesting to reach out to you to authenticate.
Something like
"You've been added to X's web of trust for account recovery at example.com. If X needs to recover their account, we may ask you to confirm with them that it's genuine."
Then something like
"X is trying to recover their account for example.com. Please contact them within the next Y days to confirm it's genuine and if it is, respond with the the 4 digit recovery code X gives you"
Then from x's side:
"Your web of trust has been contacted. Feel free to contact them now and give them the pin YYYY so they can confirm this is genuine"
This approach pretty elegantly addresses a number of security question limitations and existing 2FA infrastructures shouldn't be that hard to modify in order to implement it.
Probably my favorite feature of this approach is it requires the various security code social manipulation scams to be successful against 2 people instead of 1 which is rather statistically unfavorable for the scammer.
Also there's a 100+ year old workaround for that which used to be used in the postal service so people didn't have boxes on their doorstep with giant labels on it reading things like "Dildos Direct": Either leave the company name off or use some alias.
Including the company name is really just a user interface flourish to dealienate the feature