Live data from Hacker News

Social Login Buttons Aren’t Worth It

blog.mailchimp.com

41–50 of 114 posts

Re: Social Login Buttons Aren’t Worth It

#41
post #38

Social login is a shadow issue here - like a sheet over a chair, the little buttons are obscuring a larger issue: Mailchimp found that clarifying login error messages reduced login failures by 66%!! The rest of the story is a coincidental tale about the CEO trying to pull a "Jobs" by thinking he knew what his customers wanted better than they did. The social media buttons only had an effect on 3.4% of their users, a…

Amen. The clarified login error message finding is way more interesting than the vague platitudes on branding and security. No one will get rid of their social buttons solely on the basis of this post, but hopefully many people will now work on improving their error messages after reading this.

> The clarified login error message finding is way more interesting than the vague platitudes on branding and security

The part about security isn't platitudes. Not displaying informative messages in response to failed logins is a security orthodoxy, something you are almost always told is a compulsary practise if you care about security. So a very key part of the story here is that they abandoned this standard security practise as a tradeoff in favor of usability. Whether this ever bites them or to what extent is something we may never know the answer to. So we have been told the good outcome of their tradeoff and not the bad side. It sounds to me like it was worth it, but I wouldn't like every web service to jump on this uncritically.

Re: Social Login Buttons Aren’t Worth It

#42

The way I read this, it's about the CEO overriding the decision based on aesthetic reasons. Personally I'd much rather log in with Google in this case, which means there would need to be three buttons: Twitter, Facebook, and Google. I'm sympathetic to the "nascar-ization" argument, but I also believe your customers are smart enough to process at least as many options as there are in their wallet for providing identit…

> The way I read this, it's about the CEO overriding the decision based on aesthetic reasons. I read this as the CEO overriding the decision based on experience, not aesthetics. Reducing choices reduces errors.

This seems unreasonable, since he was presented with evidence that showed a strong correlation between more choices and fewer errors. In hindsight, this turned out to not be a causal relationship, but the CEO had no way of knowing that at the time.

Re: Social Login Buttons Aren’t Worth It

#43
I think telling people that just their password was wrong was a bad move. The author argues that this is not a security risk because the "username reminder form already tells you if a username exists". However, this simply displays a further security issue. I don't have the link handy, but there was just a (really good) article the other day here on Hacker News about why you should not reveal whether the email address is necessarily associated with a username or password in these kinds of forms (always just give the same generic "we will send it if it exists" message).

Re: Social Login Buttons Aren’t Worth It

#44
post #41
post #38

Earlier quoted context omitted.

Amen. The clarified login error message finding is way more interesting than the vague platitudes on branding and security. No one will get rid of their social buttons solely on the basis of this post, but hopefully many people will now work on improving their error messages after reading this.

> The clarified login error message finding is way more interesting than the vague platitudes on branding and security The part about security isn't platitudes. Not displaying informative messages in response to failed logins is a security orthodoxy, something you are almost always told is a compulsary practise if you care about security. So a very key part of the story here is that they abandoned this standard secur…

Sorry, I meant the security of relying on the services in general, not of exposing that someone has an account with you. Obviously, that's a serious security consideration, and each service should weigh the costs and the benefits.

In this case, it seems like they are already exposing it with the account checker, so making this change didn't open up any new vulnerabilities.

Re: Social Login Buttons Aren’t Worth It

#45

I think telling people that just their password was wrong was a bad move. The author argues that this is not a security risk because the "username reminder form already tells you if a username exists". However, this simply displays a further security issue. I don't have the link handy, but there was just a (really good) article the other day here on Hacker News about why you should not reveal whether the email addres…

Yes, both of these UI features would reveal the fact that this username or email already exists.

But isn't it impossible not to reveal it on the signup page anyway? You want users to have unique usernames (or emails acting as usernames), therefore the signup form has to tell them if it has been already taken.

My suggestion would be to tell users if the username or email is unknown right away - and perhaps add a captcha if they are trying out too many different usernames.

Re: Social Login Buttons Aren’t Worth It

#46
I am probably in a minority but for me, my Facebook and gmail is more valuable than almost all other accounts. When I see a site that forces me to sign up using Facebook or a google account, I usually hit back. Why? Because in my mind I'm giving access to my entire Facebook to a bunch of guys I know little about. I'm not as fearful that these guys are evil and may directly harm me. I'm more fearful they will post something to my timeline or that they may repost say my public posts for SEO etc.

This is one reason I am extremely pissed at instagram. Instagram as a product gives you a sense of privacy because it provides very limited ways to access your photos. You can't just goto instagram.com, login and begin browsing. On the other hand, few people realize that your instagram pictures are public by default and there are dozens of sites which using instagram's API(I'm guessing) are republishing our photos without even your knowledge.

Re: Social Login Buttons Aren’t Worth It

#47
few things don't add up here.

1. they added the social buttons late in the game, and are surprised about 4% of users are using the social buttons. what if that 4% was compromised entirely of users who registered since you added the buttons? that would be a totally different ballgame.

2. the problem they were trying to solve was login errors. that's not the problem facebook and twitter sign in solve. therefor it seems fallacious to say "they aren't worth it" when you're not even considering the standard use case.

Re: Social Login Buttons Aren’t Worth It

#48
post #15

I love being able to log in using an OpenID provider rather than creating an account. Because it's one less !$@%!@$! password to remember. Or it's one less $@&%!@$ hassle adapting my password creation formula to a new site's password requirements. Or it's one less place where my don't-care-use-it-everywhere username/password key is stored, perhaps @$2( ! in the clear. Or perhaps it's just one less time I have to type…

I agree. But unfortunately, OpenID can magnify the problem for some people. For example, my girlfriend has at least 4 different Stack Overflow accounts because she can never remember which OpenID provider she used, so she keeps accidentally creating new ones.

The simple solution is to setup a priority and stick to it.

e.g. Google > Twitter > Email >>> Facebook

Re: Social Login Buttons Aren’t Worth It

#49

I joined mailchimp ~7 months ago after Jason (thisweekin.com) pleaded viewers to check it out so i signed up for the free trial (2000 subscribers free no credit card). I'm amazed by everything that they do. Elegant api and ux that "you get" from the get-go. It is a huge problem to solve and i'm now engaging with 1100 subscribers. Now i want to pay ($30/m) but they don't accept paypal - the service i use to pay for ev…

Couldn't you just get a debit card for your paypal account then? https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-cont...

Re: Social Login Buttons Aren’t Worth It

#50
There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook.

What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin"

What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send traffic to Facebook and diminish or even completely fail to promote your own bran?

OK, the other question might be: Who is visiting a Facebook page for toilet paper. The point is that I've seen this many, many times from all kinds of companies.

Maybe someone can explain? Maybe this is just sheep following sheep off the cliff?

Post reply on HN