Comment Re:So its only ... (Score 1) 48
They could ask:
What happened to your first girlfriend:
Mine's in jail now
or:
What caused your last divorce:
Infidelity (Not mine).
That may be harder to look up, depending on how those answers changed.
Maybe:
What sex does your favorite pet have:
Male/Female, Neutered, Other
Or:
What car did you take your driver's test in.
What color did you paint your shack's bedroom in
Or:
What was the first video game you beat
Or:
How many seconds was the longest belch you've ripped off:
Or:
How many friends did you have in highschool.
Almost none of these are easily verifiable, and technically are harder to source online. Plus some do change, so it means it may make info out of date.
Ideally, you want recovery questions which:
Require updating of 2 that do change
Require 4 that don't.
at least 3 that don't change, one that does that requires updating, and thirdly, a very specific one, to recover, should include some legal ID that has an expiration on upload of no more than 12 hours, with some kind of encryption with script that wipes it, and requires a password that changes to access (Key unlock) with no ability to do a snipping of any kind, that or live verification (Biometric) against a picture of your face with some barometric device. many phones have cameras, and can be compared. either that, or use that alongside the others with some human-based verification of just the picture (live mode in app or browser) for 3 sides of your face (Not to be kept) vs. a registered picture.
This should all be used with financial or some such protected data. Not the average website. and it would be good enough to allow security on those sites, followed by MFA for regular login.