The answer is yes, and the TL;DR is not to use them, use 2FA, and not share personal details online (which is hopefully all obvious advice)

cross-posted from:

  • no they are not, just another stupid article from proton. nothing stops you from saying that bwE0FpHb5iPzMZiismyeiTIWhoB*#V8SaD0F3R*SeH was your first pets name.

    And how many regular people do that? Or does security apply only to advanced users?

    •  flatbield   ( ) 
      8 months ago

      Security is always porous. The article really had no suggestions. They say 2FA but account recovery is often a combination of access to your email account or questions. None of this stuff is particularly secure.

      So yes security is an advanced feature usually not provided and normal users do not even try at being secure nor do most systems insist on it.

      Edit: Some sites are doing away with passwords and just sending and email with a link to login. Totally not secure but account recovery has long used the same method so it may not be actually reducing security much since there never was much security.