Twitter Porn Names Scam
pcworld.com
pcworld.com
Those are both very easy to find pieces of information. Let me select the question myself too. By forcing me to give you answer here you're potentially making my account _less secure_.
Right now I have standard fake answers to those questions, let's hope they never cross reference those with anything else. I'm not sure how I'd convince someone my mothers maiden name is "<insert comedy name here>"
Also depends what sort of site it is and if it has a concept of "support staff".
Personally, I don't think businesses should implement half-baked security features -- and password request forms are as half-baked as it gets.
The best solution would be for important sites (my bank, my stockbroker, ...) to make me come into their office with documentation if I forget my password.
The problem, unfortunately, gets more difficult for "unimportant" sites... frankly, short of relying on a centralized ID provider that can ensure identity in person, there isn't a good answer.
I hear there's this thing called "OpenID".
Currently, we use email/password for authentication, but if our user forgets their password, they can answer their security questions to reset it. To design our list of questions, we worked off of http://www.goodsecurityquestions.com/examples.htm and tried to find questions which were relatively obscure, but not so obscure that users couldn't come up with answers. I suppose we can make "write your own question" an option, but we do think that most users given that option will write too easy a question, like mother's maiden name.
Our app contains a lot of sensitive data, including medical data, and privacy of this data is incredibly important to our business. We have to be attentive to regulation and industry standards -- and you're right that industry standards probably give us some cover -- but we have both the desire and the flexibility to do the right thing.
A more secure, but frustrating for the dis-organized, approach is to email out a small set (3-5) of one-time credential-recovery passphrases (often called a scratch-list) with the initial account approval message.
Another slightly more usable forced-in-channel alternative includes image file recognition where the user selects from a predefined set of pictures to use as their "shared secret" when the account is created. Typically, a salted hash of the image file is stored as the actual password value so multiple versions (slightly bit skewed) of the same visual representation can be leveraged for password expiration.
Alas, all of these more secure alternatives limit the user's ability to "personalize" their shared secret and require additional bookkeeping.
They'll get an earfull when they ask me for it though, futile or not :)
Whenever i need to open an important account (say, with the power utility) I make up answers and record them on paper. Simple. Effective.
Combustible.