The mechanisms for password recovery are flawed," John added. "The traditional method of password recovery is asking questions that only you, the real owner, should know. Unfortunately, answers to these questions often can be deduced based on information that can easily be found online -- especially given people's proclivity for "over-sharing" on social media sites.