Bitcoin Forum
March 01, 2026, 07:38:36 PM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Security question and answer.  (Read 118 times)
akwala (OP)
Newbie
*
Offline Offline

Activity: 5
Merit: 0



View Profile
February 27, 2026, 08:56:59 PM
 #1

In order to change my security question and answer, I did the following in the Account Related Settings form under Modify Profile:
  • entered a security question and answer;
  • entered my password and OTP (next to the "Change profile" button);
  • clicked the "Change profile" button.

This resulted in the form getting re-rendered without any error, but with the following message in red, next to the security answer field:
Quote
You have a secret question set. This is not recommended.

The security question I had entered appeared in its field.

How can I change my security question and answer?
retaur
Member
**
Offline Offline

Activity: 126
Merit: 16


View Profile
February 27, 2026, 09:01:33 PM
Merited by vapourminer (1)
 #2

The old security question or the new one you tried to set?

Security questions aren't recommended because the common ones are either guessable or searchable (especially if you've multiple accounts with the same email, password and security question or someone that sends you a "questionnaire" that asks for information that could be the answer to your security question).
Xal0lex
Staff
Legendary
*
Offline Offline

Activity: 3108
Merit: 2979


View Profile WWW
February 27, 2026, 09:48:24 PM
Merited by hosemary (1), JeromeTash (1), Mia Chloe (1)
 #3

PSA: ACCOUNTS WILL BE LOCKED IF THE SECRET QUESTION IS USED TO RECOVER IT
JeromeTash
Legendary
*
Offline Offline

Activity: 2800
Merit: 1461


Heisenberg


View Profile
February 27, 2026, 09:57:08 PM
Merited by Mia Chloe (1)
 #4

Why would you opt for a security question when there is a much better option to secure your account via OTP.
"Security question" was an old account recovery method which is no longer in use. After the introduction of OTP a few years back, it's better you set it up to increase your account security

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
SeriouslyGiveaway
Full Member
***
Offline Offline

Activity: 644
Merit: 207


Bitz.io Best Bitcoin and Crypto Casino


View Profile
February 28, 2026, 03:22:46 AM
 #5

In order to change my security question and answer, I did the following in the Account Related Settings form under Modify Profile:
  • entered my password and OTP (next to the "Change profile" button);
Something you must know about OTP for your account security.
2FA added by theymos from a SMF patch programmed by PowerGlove.
A concise 2FA/TOTP implementation (SMF patch)

There is a note from theymos on 2FA.
If you use the forgotten-password function, then there's an option to remove the 2FA. So 2FA does not provide any protection in case of a compromised email. Make sure that your email address is secure. If you don't want to set an email address, use something like yourUserName@invalid.bitcointalk.org; don't use a random nonsense email like y@x.com, since somebody might create that domain/email.

KingsDen
Legendary
*
Online Online

Activity: 1750
Merit: 1286


Goodnight, o_e_l_e_o & 1miau 🌹


View Profile WWW
February 28, 2026, 03:30:27 AM
 #6

Why would you opt for a security question when there is a much better option to secure your account via OTP.
"Security question" was an old account recovery method which is no longer in use. After the introduction of OTP a few years back, it's better you set it up to increase your account security
I think theymos should remove the option of security question now that there is 2fa verification. I see that the only function security question is solving now is; if you want to self-destroy your account.
When I was new, I set it but then when I saw that it wasn't recommended, I removed it. I fear that it shouldn't trigger one day and become a problem to me.

Op, as advised by others, consider leaving the secret question alone if you don't want plenty drama with the admin concerning account recovery in the future.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
[/quote]
Code:
[center][table][tr][td][url=h
Cricktor
Legendary
*
Offline Offline

Activity: 1414
Merit: 3694



View Profile
February 28, 2026, 06:19:44 PM
 #7

I would not use and remove a previously set security question and answer in your profile, unless you didn't use a valid email address for your account OR you don't have control over the used email account.

Anyone who still uses the security question and answer should carefully read and understand the Public Service Announcement that Xal0lex has provided the link to! See post #3 above...

If your email account used for registration in this forum is properly secured, it's very recommended to activate and use 2FA for your forum's account.

In case shit happens with your forum account and you need to regain access via recovery, stake a Bitcoin address and/or a GPG public key in the appropriate mega-threads before you run into a need for account recovery.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
hd49728
Legendary
*
Offline Offline

Activity: 2744
Merit: 1292


View Profile
Today at 01:50:17 AM
 #8

The change of secret question to be usable for account recovery to account lock comes from the forum hack in 2015.
Bitcointalk history of hacks and vandalism.
About the recent server compromise.

On May 22 at 00:56 UTC, an attacker gained root access to the forum's server. He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server. In the intervening time, it seems that he was able to collect some or all of the "members" table. You should assume that the following information about your account was leaked:
- Email address
- Password hash (see below)
- Last-used IP address and registration IP address
- Secret question and a basic (not brute-force-resistant) hash of your secret answer
- Various settings

As such, you should change your password here and anywhere else you used that same password. You should disable your secret question and assume that the attacker now knows your answer to your secret question. You should prepare to receive phishing emails at your forum email address.

Accounts will be locked like busminer but there is an account recovery process that takes time, but no guarantee that you will succeed.
Busminer account locked, please help to unlock.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!