In context of GDPR and data minimisation requirements... is it even legal to have knowledge based authentication / security questions in use? Any service, except maybe a genealogy service, asking user their mother's maiden name should not exist.
#privacy #gdpr #knowledgebasedauthentication #securityquestions