About three years ago, the startup I was working for was bidding on a US Government contract, and that required us to register with what at the time was called Central Contractor Registration (CCR). The “security” questions were notable enough that I kept a record of them at the time, which I ran across recently.
The old registration required that I supply the answers to five security questions. This is more than I have seen anywhere else:
Fortunately, although the prompts were the same for each of the questions, there was a long list of prompts from which to choose:
The list was long enough that I had to scroll down to see the whole thing:
While having a longer list of questions is helpful (and probably essential, if five questions are involved), there isn’t really anything new here, and some questions have little entropy, even for those for which you can’t get the answers from social networking sites.
I also captured some of the password requirements:
CCR has been incorporated into GSA’s System for Award Management (SAM) [sound like someone’s uncle?]. The process is somewhat different, and more conventional now, with three “security” questions. I suppose the answer to a “Security Question” is a “Security Answer”:
Note the “one or more”. Your account could be taken over by someone knowing only one of these answers. Scary.
The username/password rules are interesting too.
Update 29 August 2015: I ran across a podcast talking about “the worst government websites on the internet” that cited SAM as their poster child of bad government websites. Their issues apparently aren’t limited to their use of security questions.