What is with perpetuating this idea that people have some duty to be responsible for companies' broken security practices? You're unable to prevent their fuckups - so you can only take steps to make sure you don't end up on the hook or otherwise severely impacted due to their negligence. It's not my job to avoid repeating public information like mother's maiden name, historical addresses, etc. Nor is it my job to wor…
I don't really see "responsibility" as a useful lens. If you give away information that can be used to reset your passwords, you make it more likely that someone can reset your passwords. Assigning blame is something people do to make themselves feel better after bad things happen. Making it less likely for bad things to happen in the first place may or may not be worth the time and effort, but whether or not you're…
Eh, not really. Assigning responsibility is how we align incentives to prevent things from happening in the first place. You are responsible for not disclosing your bank password. You are not responsible for repeating public information that a bank foolishly decided to consider an authentication token.
Personally fretting about whatever broken actions a bank decides to take uses up a disproportionate amount of your time, as you're unable to actually change them. And any success just encourages the bank to continue, as they suffer less from their own idiocy.