ruza on Nostr: "The password reset functionality did ask for answers to two security questions, but ...
"The password reset functionality did ask for answers to two security questions, but they found that those answers were checked with code that ran locally in a user's browser, not on Subaru's server"
https://www.wired.com/story/subaru-location-tracking-vulnerabilities/
https://www.wired.com/story/subaru-location-tracking-vulnerabilities/