Google research found that website security issues are not actually safe
For enhanced security, multiple websites often have security issues beyond the password. However, Google's in-depth research shows that the last line of defense after the password is lost is weaker than expected.
Google found that the security intensity of security problems is weak because many people lie when answering security questions, especially some (37%) who intentionally provide false answers to security questions to make it harder to guess. However, the side effects of such behavior are that many people cannot immediately think of the answer to the security question, especially when the question is very special. According to Google statistics, about 40% of people cannot recall the answer. In contrast, the success rate of password reset by SMS is much higher, reaching 80%. Google compared the intensity and ease of memory of the problem, and found that security issues both security and ease of memory are almost not stored. For example, the study found that "What is your frequent flyer number" is one of the safest problems, but only 9% of the people who choose this problem remember their own number.
The study also found that attacks against security issues are especially dangerous because many users have the same answer. For example, what kind of food do hackers like? (English problem) "the success rate of a single cracking of this problem has reached 19.7%. For South Korean users, the success rate of 10 attempts to crack the "City of birth" problem reaches 39%. (The first problem indicates that Westerners have a single taste, and the second problem indicates that the Korean region is small :)).
The third problem that Google found was that some security questions were too narrow in scope and limited the number of answers from the very beginning. For example, the question "Who is your superhero" makes it easier for users to ignore security issues.
This document references multiple sources: static.googleusercontent.com and bgr.com.