Quote:
Originally Posted by qasdfdsaq
I don't think you're paranoid but this is how a lot of legitimate business work as well. The whole reason they don't ask for your whole password is to prevent identity theft. That's specifically taught as good practice among security conscious companies such as banks.
|
If they ask for different letters over multiple phone calls, they could eventually harvest an entire password.
I hate it when service providers call me and ask for my date of birth to prove my identity - that's one of the key pieces of personally identifying details and nobody should be cold calling and asking for it. Like the queen, I have two birthdays ... The real one I give to service providers when it is legally required, and the ceremonial one I give out to anyone who insists on having it in order to sign me up, even though they don't have any need for it.