[Archive] The format of security question

:classical_building: Archived Content from Web3Auth Community

This topic was originally posted by echo.chan on 4/14/2023.
This content has been migrated from our previous community forum to preserve valuable discussions.


Is it considered insecure that we let users to set an answer 4 to 8 characters string?
I am thinking whether hacker would be able to brute force the answer by trial and errors.
Are there any rate limit in attempts to enter a backup share?
Thank you!