WebApp Sec mailing list archives

User verification questions


From: "Derick Anderson" <danderson () vikus com>
Date: Mon, 10 Oct 2005 10:47:37 -0400

What good questions can be used for user verification? I've seen some
password recovery interfaces which have the typical mother's maiden
name, city of birth, etc. and others which let the user define their own
question (a stupid idea in my opinion, but I'm willing to be educated).
I'm thinking beyond a password recovery interface - I'm more concerned
with a general protocol that could be used in situations where email
isn't an option.

Thanks,

Derick Anderson



Current thread: