DEV Community

Discussion on: Why don't websites allow users to create their own security questions?

Collapse
 
niorad profile image
Antonio Radovcic

Because security questions are an additional attack vector and should not be used at all. The dev-time is better invested in enforcement and encouragement of long & secure passwords and 2FA.

Collapse
 
garvinc profile image
Garvin

What would be your workflow for password reset? That is the typical use case for security questions.

Collapse
 
niorad profile image
Antonio Radovcic

Enter E-Mail -> Receive Reset-Link