• FuglyDuck@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    14 hours ago

    … that’s an excellent question.

    Frankly, even if you don’t… what’s the point? if you can crack the password, you can probably crack the secret question. or questions.

    if you can social engineer a password, same with secret questions.

    They’re basically just a second passwords. possibly one of many passwords with a prompt.

    • zaphod@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      ·
      14 hours ago

      I’m not even sure how I would store the answers to these questions in a database. Would you hash them like passwords or just store them in plain text (maybe encrypt them, but if someone has access to your servers they can probably access the encryption key too)?

      • FuglyDuck@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        13 hours ago

        many passwords allow you to store pass keys (like with crypto wallets) as hashes attached to any login credentials. I would suggest storing them that way. at worst, I used to create secondary credentials.