Here are REAL examples of some of the options Apple gives you:
- Who was your favourite singer or band in high school
- What was the first album that you purchased
- What was the first film you saw in the theater
- What was the first car you owned
- Which of the cars that you've owned has been your favourite
- Where were you January 1st, 2000.
- What is the first thing you learned to cook
- Where did you go the first time you flew on a plane
- What is the last name of your favourite elementary school teacher
But you don't get all of those. You get a random selection. So two different accounts might have different options.For me I don't have an answer to over 80% of those questions. Either because I don't know, it doesn't exist, or because it is US centric.
Honestly Apple's security questions took me over 20 minutes, were mandatory to use iTunes, and was a fully unpleasant experience. There's very little chance I'll remember them later either.
It is quite funny how lax their security is elsewhere when they can justify this painful nonsense.
[1]: No, not that exact string ;)
Apple created these questions for you to enter real answers. They fully intend for you to put in real answers. That is what the system's purpose is.
That we look at it and say "well that is grossly insecure, so I'm going to put in the SHA512 hash of the question with a fixed secret salt" might assuage our risk, but it does nothing to relieve Apple of the failure of this security system.
A common example: "Name of first car?"
So was that "Neon"? or "Dodge Neon"? or "Blue Neon"? or maybe "neon"? or "1991 Dodge Neon"?
Security questions are basically a secondary password masquerading as something else. But because they are not called a password, the expectations on their character-wise-correctness are not clear to a layman. I find the continued proliferation of security questions baffling, especially when some sites call password + security question "two factor authentication".