Live data from Hacker News

Social Login Buttons Aren’t Worth It

blog.mailchimp.com

81–90 of 114 posts

Re: Social Login Buttons Aren’t Worth It

#81

Earlier quoted context omitted.

What is Charmin going to put in their Facebook feed that has recurring value? New research on the best way to wipe your ass? I'll continue to get that from charmin.com, rather than risk a charmin app that posts to my wall that tells people I just learned how to wipe my ass.

Coupons and offers which are built into Facebook now. "calbear81 just claimed an offer for $10 off 24 pack of Ultra Soft Charmin toilet paper".

This thread is hilarious - awesome work.

Re: Social Login Buttons Aren’t Worth It

#82

Earlier quoted context omitted.

Yes, both of these UI features would reveal the fact that this username or email already exists. But isn't it impossible not to reveal it on the signup page anyway? You want users to have unique usernames (or emails acting as usernames), therefore the signup form has to tell them if it has been already taken. My suggestion would be to tell users if the username or email is unknown right away - and perhaps add a captc…

You can use the same strategy there too: in the signup page, it can just say "a confirmation email has been sent to your email". In the event that the email is already known, the email will say "someone else has tried to sign up with your email -- if this was you click here to change your password". This way, the attacker will never know if the email genuinely resulted in a new account or not.

Interesting. So we have a clear-cut case of having to choose between (a) more security; or (b) a simpler sign-up process which means more revenue.

It seems to me that choice (a) will not always be the right one - it depends on how much security would improve and how much revenue will be lost. If you find the previous HN article on this topic that you mentioned I'd be curious to read it.

Re: Social Login Buttons Aren’t Worth It

#83
post #78

So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook inves…

1. True, but irrelevant.

2. It is very easy. SQL injection etc. isn't something you magically get rid of because you use a facebook login...

The reason so many get this wrong is because they don't even try. And if you don't even try you won't get any other aspect of security right and outsourcing your logins isn't going to solve any of that. If you have to outsource this to facebook, the moment you get big you will, guaranteed, have issues with DoS, rate-limiting, SQL injection etc. for everything but the login. Which honestly isn't much of an advantage (sure, leaking your password database is bad press - but if you have the slightest bit of salting it might even turn out to be somewhat good - after all, your little startup apparently had way better security than sony and 99% of everyone elses leaked databases). If salted passwords is the only thing valuable in your database you are in serious trouble anyway.

3. Since building your own login is so easy and hardly even a fraction of anything worth doing with your startup, outsourcing it completely is just ludicrous.

If you can't even salt your passwords right maybe this web-thing isn't your thing after all, or maybe you should outsource everything...

Point is that exclusively relying on facebook (or whatever) login is that it is downright fraudulent and also signals that you are lazy and don't care the slightest about your users. It is that easy, you can't get away from that.

Offer a facebook login alongside your own solution (if you think it's worth the hassle implementing facebook connect/whatever), even if 99% of the users choose facebook the fact that there is an alternative is guaranteed to make them feel better about using facebook in the first place. If you don't think that is worth it, your site most likely isn't worth even trying either...

As from the user point of view, if you really think it is worth it (probably isn't): Just create fake facebook account(s).

Re: Social Login Buttons Aren’t Worth It

#84
post #80
post #78

So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook inves…

Most websites that are adding social login buttons also keep their own registration/authentication setup. I think by adding social login buttons you also increase attack surface on your website, no matter how good third party security is.

My point is that you shouldn't bother spending any time rolling your own registration / authentication step.

Do you think that using 3rd party auth in lieu of your own auth decreases security?

Re: Social Login Buttons Aren’t Worth It

#85
post #83
post #78

So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook inves…

1. True, but irrelevant. 2. It is very easy. SQL injection etc. isn't something you magically get rid of because you use a facebook login... The reason so many get this wrong is because they don't even try. And if you don't even try you won't get any other aspect of security right and outsourcing your logins isn't going to solve any of that. If you have to outsource this to facebook, the moment you get big you will,…

1. What's irrelevant about having robust and constantly-evolving phishing detection, and optimized flows for getting people back into their accounts? Both of these are important in a high-quality login system IMO.

2. You're right that a lot of folks fail to even try for security, but I disagree that outsourcing password management to facebook won't help them. If they get popped and have no passwords, all that leaks is the information specific to their site. If they get popped and have passwords, then in addition all those users' passwords (which they likely share with other sites) are now in the open. The damage has spread beyond the one clowny site and screwed over those users' experiences on wherever they shared passwords. We actually invest a fair amount of time in automated systems that look for leaked password dumps from such sites and help clean up users whose leaked passwords match their Facebook ones.

Also, even in cases where people did things more-right, it's still incredibly damaging. Look at LinkedIn (who was hashed but not salted) or Gawker (who was hashed and salted, albeit poorly).

3. I guess I didn't convey this very well, but my point was that building your own login system is difficult. Getting everything right to ensure it's secure is actually pretty difficult, and requires constant attention if you're under any kind of targeted attack.

As for making fake Facebook accounts... please don't do that. You'll just open yourself to a bunch of headaches, as we're pretty aggressive with removing fake accounts from the site.

Re: Social Login Buttons Aren’t Worth It

#86
The actual point of this article is "Social login buttons aren't worth it... for Mailchimp".

Obviously a business-focused company is going to have less people logging in with Facebook than a consumer-focused company.

People shouldn't write generalizing blog posts unless they have some understanding of proper experimental design.

Re: Social Login Buttons Aren’t Worth It

#87

There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send…

If someone LIKES it on facebook, they now have a direct, reusable channel to communicate with an interested customer. That's worth a lot more than a website visit.

Re: Social Login Buttons Aren’t Worth It

#88
As others pointed out, I believe the 3.4% was simply down to social logins introduced much later. When I fist signed-up for mailchimp ages ago, the only option was creating a new user account.

I think the article dismisses one huge benefit to federated logins:

* ease of use for users - instead of choosing a username, entering all the customer information, verifying the email address etc, choosing a password, you can sign in with one or two clicks.

Re: Social Login Buttons Aren’t Worth It

#89
post #42

Earlier quoted context omitted.

> The way I read this, it's about the CEO overriding the decision based on aesthetic reasons. I read this as the CEO overriding the decision based on experience, not aesthetics. Reducing choices reduces errors.

This seems unreasonable, since he was presented with evidence that showed a strong correlation between more choices and fewer errors. In hindsight, this turned out to not be a causal relationship, but the CEO had no way of knowing that at the time.

If you started making decisions based solely on rational arguments and facts, would those lead to better decisions?

Almost all business are built on intangibles. Emotion, creativity, personality, feelings, loyalty, love etc. These intangibles are extremely difficult to explain yet most decision makers instinctively understand them.

The CEO probably made a decision on instinct. He was not rationally arguing the social integration, he instinctively denied its value. Rationally, you could probably prove the social buttons to be beneficial but you would have to disregard the intangibles.

Re: Social Login Buttons Aren’t Worth It

#90
For me the most important bit in that was the last line.

"Is it worth it? Nope, it’s not to us." (my emphasis)

Not all businesses are the same. B2B businesses like MailChimp usually don't see major increases in value through third party auth. They're providing serious value. People will go to the effort regardless.

With a casual use B2C site removing even the tiniest piece of friction in the login process can mean the difference between a purchase and people just going away.

It depends. This is why we test shit :-)

(Also - unrelated to this - is that the "login" bit is often not where the biggest win for third-part auth is. It's in reducing friction in registration. I've seen high single digit percentage improvements in abandonment of registration for some B2C sites due to getting profile info from twitter/linkedin/etc. cutting the time it takes to setup accounts fully. Lifetime value also increased since profile info was generally better from those sources which was an important part of users getting value out of the system, and so the business getting value out of those users).

[edit: also - they seem to be looking at total numbers, rather than doing any kind of cohort analysis on the folk using twitter/facebook/whatever... which may well lead to different conclusions]

Post reply on HN