Ask HN: Online Account Security Questions
First - the multiple security questions. Second - the mandatory length and confusion in our passwords
This techniques are ridiculous and only hinders usability and adoption.
How about letting users enter a pin instead of requiring them to answer and set 5 random questions.
Password security, if I want it to be password - so be it. Give me a warning and let me keep moving. That ALONE has been the reasons I opt for not using certain services online.
Why must online security be stricter than real world application such as ATM pin with the added benefit of using all alphanumeric chars?
While taking brute force precaution in the code - why make it harder for users to use/register for your service?