Mon, 27 Mar 2006

secret question

I'm creating yet another user account at yet another site. The site is asking me for the usual yadda yadda secrets, like mother's maiden name, to use for a password reset.

The question in my mind is if these are secret enough to use for a password reset, why should I tell you? Sharing a secret makes it not a secret any more, and having a common secret like your mother's maiden name ensures that it is shared. Any time you give a good secret to a site like this you destroy its effectiveness.

permalink