710 karma · joined February 14, 2013
The dangerous ones such as this allow someone to use the security questions in place of your password. These are less secure than if you were to use your place of birth and address as your password.
Their thought process probably goes something like "we can't have users giving us their password over the phone, anyone could overhear that and they would think it is insecure. Lets have them give us something less confidential instead".
Services like this that require verbal authentication via the telephone should generate a passphrase and email it to their uses upon signup.
Having to build an additional "let me type it in" option seems like it increases the complexity and confusion. One of the banks I use asks for the zip first and then populates the city and state text fields on the lines below. This also has the benefit of working if Javascript is disabled.
Perhaps a "send to a friend" link in the email would help?
How are people viewing this news in Venezuela?
On the other hand, I enjoyed my entire time in college, and I feel that I received a great deal of valuable experience, but I also did a great deal of coding outside of school. I think in my case I would have been fine without getting a degree, but it helped to hone some of the areas that I was not very strong in.
I agree that neither approach is ideal, but it would prevent users from receiving third party links in their emails.
1. User clicks http://links.example.com/?redirect=example.com/reset_passwor...
2. The server running on links.example.com makes a request to the third party web server
3. The server redirects the user to http://example.com/reset_password