Google Study Shows Security Questions Aren't All That Secure
What is your favorite food? What was your first teacher's name? What's the name of your first pet? Do those questions sound familiar to you? If they do, it's probably because you either have really boring …
Context & Ripple Effects
This 2015 Google study lands at a pivot point: it dismantles knowledge-based authentication just as the industry starts shipping its replacements. Days later, Facebook began testing a Security Checkup pop-up offering password hardening and login review — the same week's coverage shows platforms quietly retiring trust in what users 'know.'
The study also sets up Google's own later moves: the Advanced Protection Program built on two $20 physical keys, and an internal mandate under which none of Google's 85,000+ employees have been successfully phished since early 2017. The through-line is consistent — answers to favorite-food questions are guessable because personal facts are publicly observable, so security migrates from memory to possession.
First-order effects
- Sites still relying on security questions for password resets face immediate exposure: anyone who can research a target's first pet or first teacher can hijack the account without touching the password itself.
Second-order effects
- Platform vendors respond by building replacement flows — Facebook's Security Checkup shows competitors packaging account-recovery hardening into consumer products rather than waiting on standards.
Third-order effects
- If the pattern holds, knowledge-based factors get demoted to fallback-only while physical keys become the high-assurance default, as Google's own phishing-free record demonstrates; but the Pew survey showing few US adults understand 2FA marks the adoption gap that decides how fast that shift reaches ordinary users.
The trend: Authentication is migrating from what users know — guessable from public data — to what they possess, with platform-built checkups and hardware keys replacing security questions.