Live data from Hacker News

Social Login Buttons Aren’t Worth It

blog.mailchimp.com

111–114 of 114 posts

Re: Social Login Buttons Aren’t Worth It

#111

Earlier quoted context omitted.

What is Charmin going to put in their Facebook feed that has recurring value? New research on the best way to wipe your ass? I'll continue to get that from charmin.com, rather than risk a charmin app that posts to my wall that tells people I just learned how to wipe my ass.

Coupons and offers which are built into Facebook now. "calbear81 just claimed an offer for $10 off 24 pack of Ultra Soft Charmin toilet paper".

It's shit like this that makes me cautious about Facebook for anything these days. An online newspaper I read have pictures of people who have 'like'd their paper on the front page. I notified a few of my friends about this and they were horrified and proceeded to unlike the paper. But the greatest atrocity was committed by Spotify when they put Facebook publishing of songs you listen to on by default. Afaik, they have it off now, but even Spotify goes out of 'private mode' automatically after 5 hours of inactivity. What is the world coming to? I've been a semi-active FB user since 2004 but now I am paranoid about the way their tentacles are infesting every part of the web.

Re: Social Login Buttons Aren’t Worth It

#112

Earlier quoted context omitted.

Yes, both of these UI features would reveal the fact that this username or email already exists. But isn't it impossible not to reveal it on the signup page anyway? You want users to have unique usernames (or emails acting as usernames), therefore the signup form has to tell them if it has been already taken. My suggestion would be to tell users if the username or email is unknown right away - and perhaps add a captc…

You can use the same strategy there too: in the signup page, it can just say "a confirmation email has been sent to your email". In the event that the email is already known, the email will say "someone else has tried to sign up with your email -- if this was you click here to change your password". This way, the attacker will never know if the email genuinely resulted in a new account or not.

This works with emails as usernames but not with non-email usernames.

You might say this is a good reason for only allowing email addresses as login names and that could be right although you need to think carefully about how to handle people who have lost access to their email address and in many contexts they may also need to choose a displayname.

Re: Social Login Buttons Aren’t Worth It

#113

Earlier quoted context omitted.

And you have absolutely terrible usability and tons of people fail to go through the signup process. So you gained imaginary security that doesn't actually do anything, and lost users. For most sites, that isn't a good tradeoff. I don't care if everyone knows I have a mailchimp account. How is it a security concern that people can find that out? If you are running some kind of freaky porn site it matters, but for 90%…

What is the issue with email verification for SIGNUP? This is pretty standard practice as it is. Eventually you need to contact the user, so better to make sure the email is correct from the beginning. If not, I could for example sign up for mail chimp with your email then proceed to send a bunch of people lude spam, leading to mail chimp then sending you angry emails. Even if they use it appropriately, if you later…

There is nothing wrong with email verification. There is something wrong with hiding what is going on from the user. If you try to "secure" your site from people finding out if a particular email is registered, you end up with a massive increase in login failures, which was the point being made. You also make it so that when I say "I forgot my password" and fill in the wrong email address, I am sitting and waiting for a password reset email that never comes. Every portion of the account handling process is made significantly worse by trying to hide account info, and there is absolutely no benefit to doing so.

Re: Social Login Buttons Aren’t Worth It

#114

This is exactly why Persona really needs to be adopted more and succeed. I'm tired of creating new accounts all the time and Persona solves this issue.

I'm really happy to see that Aarron's post highlights how important copy is to your success. It's super dull and tedious to get it right, but amazingly effective when done well. The post also confirms my suspicion that the highly secure "username and/or password is invalid" is a costly tradeoff.

Glad to see Persona mentioned in this thread. Full disclosure, I'm the UX Designer for Persona.

A couple of questions I have for MailChimp

* Why use usernames at all? They're a necessary evil for things like forums where users don't want to expose their real names. They are a major contributor to login failures. Email as the unique identifier is much easier to remember.

* How much pain did Mailchimp have to endure to migrate the user account that had been created via Facebook and Twitter? What copy did you use to explain? How many users did you lose?

* Would you consider implementing Persona? ;)

I do want to add a +1 to the concerns other folks have expressed about mixing the context of a personal Facebook account with a professional service like MailChimp. I see in my research one of the main concerns users have about using Sign in with Facebook is that they're unsure what will show up on their wall. Social sign in isn't right for either professional services or on the opposite side, anything that is socially questionable, like a gambling site.

Post reply on HN