Agreed on the security Q&A stuff. It's a poor way to add password recovery. If the question is answered truthfully, it's often easy to guess or find out for a dedicated attacker. In addition, if the computer is compromised when the account is registered, a keylogger can easily capture the security answer.
Security questions are a horrible horrible and stupid practice that should be outlawed.
+1 googolplex to THIS!!!
I think I almost died of anger the day that I had to bloat my Apple account with 4 (!) bogus (in)security Q+As, because my "algorithm" for generating answers (regardless of the question, actually) wasn't prepared to give 4 different ones, so I had to suffix them. Also, since the answer isn't related to the question at all using my "survival workaround" to forced security questions, I can't know the order for sure.
Twice already I had to answer these "security questions" over the phone and I loved it because they always contain/derive the words "stupid insecure" + something*. The worst is that you can't even leave it blank to avoid compromising your security.
I think our kids in 3 generations are going to laugh at how stupid their elders were with data security... and we are just a bit ahead of time.
* well not really, otherwise I'd compromise my security even further by publishing this, but you get the tone...