Keith Brown states that password “ security questions are considered dangerous ” in the context of web applications, in particular as it relates to the new Membership Provider functionality in ASP.NET 2.0, because “there’s nothing stopping the user from asking a question that...