FlyerTalk Forums - View Single Post - UA initiates Account Security Update (Security Q&A authentication added 2016)
Old Aug 29, 2016, 9:00 am
  #498  
1StRanger
 
Join Date: Oct 2013
Posts: 87
I always feel uncomfortable when the security questions/answers are multiplexed between different accounts, especially when there are different levels of (1) security and (2) what's at stake (e.g. bank account vs. a social forum, or even the FF account).
If one of those accounts is compromised (via a general break-in into the website or via social engineering aimed at a specific account), then you've got a good chance of other accounts compromised too.

Now, when a security question chosen for on-line password recovery is also used for a phone support interaction, that increases chances for social engineering hacking being successful. (The same concern applies to those websites that are happy to send you your actual password via e-mail [instead of the one-time password or link to reset your password].)
1StRanger is offline