Massive Twitter breach underscores the problem with "secret questions"
Twitter's Evan Williams certainly isn't the first famous person to have a "secret question" figured out by a hacker, but I'm always surprised when someone in IT circles falls victim to such an elementary attack. It's not news that secret questions are a terribly bad idea for enabling password resets or protecting account information. For a question to work, the answer truly needs to be a secret. ...





