2008/7/1 Rich Teer <[EMAIL PROTECTED]>:
> On Tue, 1 Jul 2008, Alan Burlison wrote:
>
>> The new OpenSolaris.org membership application will start using security
>> questions for self-service password resets.  People will be able to
>> pre-register a number of questions and answers, if they request a
>> password reset they will need to supply the answers to the questions
>> they previously set up.
>>
>
> [...]
>
>> Comments and additions are gratefully accepted.
>
> Why don't you just let people write their own questions?  Then you won't
> have to worry about missing some important question.

The best reason is to prevent them from providing information they
shouldn't or guiding them to use questions which are "safer" for this
sort of thing.

-- 
Shawn Walker
_______________________________________________
website-discuss mailing list
[email protected]

Reply via email to