
You probably have come upon password security questions before. They are often used when a user forgets the password to an account to identify the user. The major problem with those security questions is the fact that they often only display general questions that the user can chose from during configuration. This includes the mother’s maiden name, the first school, the favorite sports team or the birthplace.
Asking those questions is problematic because of two things. First, they are not that secure if the attacker has access to information about you. Your mother for instance would surely know most of the answers to those questions, as would a close friend and even most work colleagues or class mates might. The second problem with these type of questions is that they can also be easily guessed. The number of possibilities is a lot smaller than the number of possible passwords for an account meaning an attacker could simply try the most popular answers to see if they would be a hit.