Live data from Hacker News

Confirming Passwords Is Annoying: Is There a Better Way?

konigi.com

11–15 of 15 posts

Re: Confirming Passwords Is Annoying: Is There a Better Way?

#11
post #3

I simply don't confirm the password (or email). The overwhelming majority of people are going to type it properly, as substantiated by my failed login stats (less than 1%). For the remaining 1%, I'll concentrate on recovering from their error easily rather than depressing conversion among ALL users by making the signup form two fields longer. (And, ahem , if all of them were to get frustrated and abandon their trial,…

Combine this with JulianMorrison's suggestion (don't do the ####) & I think this a good approach.

Re: Confirming Passwords Is Annoying: Is There a Better Way?

#12
I can't tell you how many times I've tried logging into HN using the signup form (which, of course, doesn't ask for your password confirmation). The password confirmation, I think, has become a necessary input field to let users instantly recognize and know that they're signing up for an account. Qwerty keyboards, for example, aren't the most efficient way to type, but the layout has become so ingrained into our brains that we can't imagine any other way to type.

Re: Confirming Passwords Is Annoying: Is There a Better Way?

#13
One option might be to not ask for a password at all and auto generate it. Most sign ups include some form of confirmation email, perhaps a password could be sent with it? Not appropriate for every app but registration with nothing more than email address is getting as stripped down as possible.

Re: Confirming Passwords Is Annoying: Is There a Better Way?

#15
post #11
post #3

I simply don't confirm the password (or email). The overwhelming majority of people are going to type it properly, as substantiated by my failed login stats (less than 1%). For the remaining 1%, I'll concentrate on recovering from their error easily rather than depressing conversion among ALL users by making the signup form two fields longer. (And, ahem , if all of them were to get frustrated and abandon their trial,…

Combine this with JulianMorrison's suggestion (don't do the ####) & I think this a good approach.

Back in the day when I wasn't using keepass and just had 2-4 passwords I regularly used (one for sites I considered safe... and then a couple more for unsafe sites), I found that seeing my password in plain text on the screen was really unsettling. Even if I was home alone and there was no chance of anyone looking over my shoulder, it just felt so... unsafe.

I wonder if other people have a similar reaction.

Might be better to make users type in the password a second time rather than give them a queasy feeling in the pit of their stomach.

Post reply on HN