Mother's maiden name. First pet. The city you were born in. These were built as shared secrets between you and a system, a quiet handshake that confirmed your identity. They stopped being secret a long time ago.
Those answers now sit in old breach dumps, data-broker profiles, and the public timeline of your own social accounts. An attacker doesn't guess them. They look them up. NIST retired knowledge-based verification from its identity guidelines for exactly this reason: a fact that can be researched is not proof of anything.
The reset path has become the softest way into an otherwise well-defended account. The login might demand a passkey and a hardware token. The recovery flow behind it often asks for trivia an attacker finished collecting weeks ago.
Static answers can be looked up. The way a person works cannot.
Verify the Person, Not the Trivia
A stronger question draws on what the real person actually did this week: who they met with, which systems they touched, the rhythm of a normal day. Harder trivia won't close the gap. That knowledge lives in behavior, changes constantly, and appears in no profile anyone can buy.
Abnormal already builds this understanding of how each person operates. Applied to identity recovery, it turns verification from a static secret an attacker can purchase into a live signal only the legitimate user can produce.
The inbox has had behavioral scrutiny for years. The account recovery flow is overdue for the same.
See the latest from Abnormal's product and engineering teams.

