Greg
My feedback
2 results found
-
103 votesGreg supported this idea ·
An error occurred while saving the comment -
72 votes
At this point, security questions have been shown to not be an effective way to validate a users identity. At this time the recovery email address is our sole means of identifying users ownership of an account.
An error occurred while saving the comment Greg commented"Security questions" weaken the overall security of the account as any research into successful attacks will reveal. Protonmail, please do not mandate the use of these. They really are bad practice.
Frankly, people should be using a password manager and backing up said password manager. If you cannot take responsibility for this, you're probably better off using a more generic email address like gmail or hotmail, which use poor security practices (i.e., being able to "reset" forgotten passwords).
Plain text aids security. For example, it helps protect from malicious links.