Which involves you speaking a pin over an ordinary insecure phone call.
> ordinary insecure phone call
Is POTS or mobile phone voice calls considered insecure? I am surprised by this.Unfortunately that opens you open to a social engineering attack, 9 times out of 10 if you call the helpdesk for a password reset and they ask you the questions and you answer "some random junk I don't remember" they'll reset it for you..
(I'm sure a determined enough attacker will eventually find an agent willing to accept the former excuse, but if it reaches that point, I think I've already lost this battle.)
I just treat those as another password input that I save in my password manager (e.g. Bitwarden).
I use a password manI till use random security questions though, better than the alternative.
One time I was trying to set up a security question and it kept saying the info doesn't match their records and it seemed they were actually validating against public records. How friggin stupid.
Agent: "I'll need to ask for a few details first. What was your first pet's name?"
Me: "ZD4Fbyed6fzoUcmi"
Agent: "Thank you."
So I suppose my answer would have to be "This one".