June 30th, 2008

usability: Verification of Challenge Question and Challenge Answer

A website I use regularly requires me to verify my contact information annually. Today, I noticed that the last question on the verification page is for my “Challenge Question” — the question/answer combo that I would need to use if ever lost my password.

Here’s a small screenshot showing this question (click it to see a larger screenshot with more context):
What was the name of your first pet? xxxxxxxxxxxxxxxxxx

As you can see, it shows the question that I chose to use, but for the answer it shows “xxxxxxxxxxxxxxxxxx”, and says “Your challenge answer has been hidden for security reasons.” Then, it asks me to check a box saying “Yes, the information above is correct.” How can I confirm that my challenge answer is correct, if I can’t see it? The number of x’s does not even correspond to the number of characters in my first pet’s name.

While I appreciate that they do not display this relatively-sensitive information (since it’s almost like a password), I feel like it’s silly to ask me to verify something that I can’t see. I refused to accept that the answer was correct, and went ahead and selected/entered a new Challenge Question/Challenge Answer combination.