Live data from Hacker News

Social Login Buttons Aren’t Worth It

blog.mailchimp.com

101–110 of 114 posts

Re: Social Login Buttons Aren’t Worth It

#101

There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send…

"Who is visiting a Facebook page for toilet paper." Well, 300,000 people LIKE it so something is going on. Based on what little I've done in the social realm and what I've heard from SM consultants, these thoughts are in play: - "Every brand has a Facebook page so we need one" - "Our website is just pages and all we can do it update copy" - "On Facebook we can distribute coupons, run contests, and get people to inter…

How exactly can #3 not be accomplished on Brand X's website?

People can then post said coupons and contests to FB, where they can interact with each other, using Facebook, instead of Brand X's website.

Why does Brand X need the interaction to happen on their site? It's not like FB is some magical land of coupons and contests that could not have been offered before.

EDIT: Also, why on earth do 300,000 people like a TOILET PAPER page? Is TP really THAT incredible? What business value comes from 300K likes on FB?

Re: Social Login Buttons Aren’t Worth It

#102
post #87

There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send…

If someone LIKES it on facebook, they now have a direct, reusable channel to communicate with an interested customer. That's worth a lot more than a website visit.

No, I think what you get is an easier channel to communicate with an interested customer, where "easier" is defined as "'interested' customer doesn't even have to visit our site and fill out a form to get an email ... we can just inject messaging into their feed".

Signing up for a coupon, contest, or other deals list via email is already the best direct, reusable channel. FB didn't improve this. They simply created a method whereby companies can take advantage of doing what email marketing does without ever having to ask the user for anything more than a click.

And still, this serves to cement FB's brand and position in the market far more than the interested company's, I think.

Re: Social Login Buttons Aren’t Worth It

#103
post #71

Earlier quoted context omitted.

What is Charmin going to put in their Facebook feed that has recurring value? New research on the best way to wipe your ass? I'll continue to get that from charmin.com, rather than risk a charmin app that posts to my wall that tells people I just learned how to wipe my ass.

It's a Facebook page, not an app, so they won't post things to your wall. It seems they have contests and media on their page, as well as coupons. Those things will show on 300,000 Facebook newsfeeds. I'd say it's better to drive traffic to their Facebook page rather than http://www.charmin.com/ .

Right, but you will see their content in your feed, and I think that was the point of the comment.

Re: Social Login Buttons Aren’t Worth It

#104
post #78

So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook inves…

> We've spent a lot of time working on every aspect of login, so that startups don't have to.

Really? I find this claim to be suspect and very disingenuous. The reason FB spent a lot of time on login was so startups don't have to? It wasn't, say, so your users would be secure ... and then a later realization hit that you could subsume startups into the FB universe by letting them use it?

If FB wanted to solve the login problem so startups don't have to, why not offer a standalone, drop-in login solution that doesn't require devs to hook their apps into FB, to have dev accounts, to get user info from FB, to display the Facebook brand, etc. etc. etc.

> Your job is to build whatever technology differentiates you from your competitors, and make it worlds better than theirs.

Probably best to think that, just like Facebook, every startup's "job" is to take care of their users, protect their information, and deliver a quality experience. And each startup is the only one capable of determining the value of doing it themselves.

> Any time you spend pfutzing with password hashing, building a better password recovery flow, or arguing about how to fail when people type in the wrong password is time you could better spend making a truly wonderful product. Unless you're trying to build a startup that helps people login, any time spent on this is better spent elsewhere.

You really do like taking this just that much too far, don't you? I consider the way startups and applications handle authentication, signup, etc. to be an integral part of how I determine quality of the product. And even though I have a Facebook account, whenever someone makes me go through Facebook, it fucking destroys any semblance of a nice user workflow.

When a startup spends time helping me signup and login to their service, I notice. And when they don't, I typically hear in the back of my head, "Fuck it, just slap Facebook on it. Problem solved."

Re: Social Login Buttons Aren’t Worth It

#105

Earlier quoted context omitted.

"Who is visiting a Facebook page for toilet paper." Well, 300,000 people LIKE it so something is going on. Based on what little I've done in the social realm and what I've heard from SM consultants, these thoughts are in play: - "Every brand has a Facebook page so we need one" - "Our website is just pages and all we can do it update copy" - "On Facebook we can distribute coupons, run contests, and get people to inter…

How exactly can #3 not be accomplished on Brand X's website? People can then post said coupons and contests to FB, where they can interact with each other, using Facebook, instead of Brand X's website. Why does Brand X need the interaction to happen on their site? It's not like FB is some magical land of coupons and contests that could not have been offered before. EDIT: Also, why on earth do 300,000 people like a TO…

"How exactly can #3 not be accomplished on Brand X's website?"

I think the whole point is, if charmin posts a new coupon on their website -- only normal visitors will see it.

Charmin posts a new coupon on Facebook and 300k people instantly see it.

Re: Social Login Buttons Aren’t Worth It

#107

Earlier quoted context omitted.

"Who is visiting a Facebook page for toilet paper." Well, 300,000 people LIKE it so something is going on. Based on what little I've done in the social realm and what I've heard from SM consultants, these thoughts are in play: - "Every brand has a Facebook page so we need one" - "Our website is just pages and all we can do it update copy" - "On Facebook we can distribute coupons, run contests, and get people to inter…

How exactly can #3 not be accomplished on Brand X's website? People can then post said coupons and contests to FB, where they can interact with each other, using Facebook, instead of Brand X's website. Why does Brand X need the interaction to happen on their site? It's not like FB is some magical land of coupons and contests that could not have been offered before. EDIT: Also, why on earth do 300,000 people like a TO…

First, I don't disagree with anything you said. I just was trying to demonstrate how non-hackers and marketing types think.

To be honest, I think they see Facebook as almost an "end-around" to having to deal with internal IT/web folks.

Re: Social Login Buttons Aren’t Worth It

#108
I never use a Facebook or third-party login, if I can help it. Why would I want to tie my real identity to some site I'm opting to _try_ for the first time? I might want to integrate an account to Facebook if the service provided some phenomenal value to me for doing so and the service had gained my trust. But providing my Facebook information to an unknown entity is far more intrusive than providing an email.

Re: Social Login Buttons Aren’t Worth It

#109

Earlier quoted context omitted.

You can use the same strategy there too: in the signup page, it can just say "a confirmation email has been sent to your email". In the event that the email is already known, the email will say "someone else has tried to sign up with your email -- if this was you click here to change your password". This way, the attacker will never know if the email genuinely resulted in a new account or not.

And you have absolutely terrible usability and tons of people fail to go through the signup process. So you gained imaginary security that doesn't actually do anything, and lost users. For most sites, that isn't a good tradeoff. I don't care if everyone knows I have a mailchimp account. How is it a security concern that people can find that out? If you are running some kind of freaky porn site it matters, but for 90%…

What is the issue with email verification for SIGNUP? This is pretty standard practice as it is. Eventually you need to contact the user, so better to make sure the email is correct from the beginning. If not, I could for example sign up for mail chimp with your email then proceed to send a bunch of people lude spam, leading to mail chimp then sending you angry emails. Even if they use it appropriately, if you later ever want a mail chimp account it will tell you you already have one, leading to true confusion.

Re: Social Login Buttons Aren’t Worth It

#110
post #78

So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook inves…

> We've spent a lot of time working on every aspect of login, so that startups don't have to. Really? I find this claim to be suspect and very disingenuous. The reason FB spent a lot of time on login was so startups don't have to? It wasn't, say, so your users would be secure ... and then a later realization hit that you could subsume startups into the FB universe by letting them use it? If FB wanted to solve the log…

Shoot - sorry if I came across as disingenuous! You're right that a lot of the reason we spend time on login is because we want our users' accounts to be secure - but a big advantage of our API is that we extend all that work to third parties. I think it is actually a pretty good drop-in login solution, but you obviously have to have some setup associated with it (the user needs to understand to whom they're disclosing their identity, etc). You don't need to ask for any permissions or query any data (though of course I think you can make things a lot more compelling if you do in a lot of cases).

Agreed that companies should determine how to deliver a great experience. In my opinion, a two-click login with something like FB is a much better experience than registering with another password and confirming your email address, and worrying about what the site's security is like (how do you evaluate this?). It sounds like we'll just have to agree to disagree here.

Post reply on HN