I was reading the OWASP Forgot Password Cheat Sheet when I stumbled upon the recommendation to use security questions.
There is even a dedicated page about what information to gather.
Whenever I see such a "feature" on a web site it strikes me as unbelievably insecure for most users, because most users will choose a question an answer that is probably very easy to find out by anyone who knows the person a bit. So I was very surprised to see such a recommendation on OWASP.
Is it really a good idea to implement security questions?