4 ms·
This is Bret Taylor, CTO of Facebook. The goal of Facebook for login is to improve signup conversion rates for your sites and make it easier for users (so they
by finiteloop 16y ago
This is Bret Taylor, CTO of Facebook.
The goal of Facebook for login is to improve signup conversion rates for your sites and make it easier for users (so they don't need to re-enter all the same information and re-find their friends on every site they use). This thread is really interesting for me and the rest of the Platform team at Facebook because it illustrates how far we have to go. Please keep the feedback coming, however harsh :)
I get the brand perception and trust issues - it is something we care a lot about and are actively working on.
Beyond that issue, we have internally been talking a lot about ways of making the user experience smoother, more familiar, and less intimidating. If all of you running startups have practical suggestions about how the experience of a user using Facebook for login could be improved to help out your site, we would be really eager to hear it. It is a great time to get the feedback, as we are actively iterating on ideas internally.
- jpeterson 16y agoI have a major idealogical problem with this recent trend of sites using Facebook connect. Don't take this the wrong way, but Facebook is a toy. People use it to share party pictures and play Farmville. I would just as soon trust a circus clown to be the central authority on my identity as you guys. And when I visited a site for the first time to see my Facebook contacts there, without ever having signed up for the site in the first place, I got angry. Really, really angry. And then I got even angrier when I went through the 30 step process of turning off this "feature". I don't know how representative I am of the population at large, but this stuff drives me nuts. Please stop.
- devin 16y agoYeah I find it pretty unnerving as well. Two opposing viewpoints on my mind: 1.) Facebook is for all practical purposes, fairly ubiquitous. +1 for Facebook Connect on that front. 2.) As you suggest, Facebook is a toy and has no place providing this kind of service. -1 for Facebook Connect.
- pinko 16y agoMy fear is that by using Facebook Connect to log into Site X, I will somehow allow Site X to access my Facebook data (my info, friends list, interests, posts, etc.) If I could be assured Facebook Connect was simply serving as an authentication service, and did not implicitly authorize sites that use it to access any data about me, or post to my Facebook page, I would probably use it for some sites.
- old-gregg 16y agoI doubt my feedback would make a difference, but this is precisely why I stopped using Facebook and made sure to close my Facebook account entirely. Linking my web activities to my profile simply freaked me out, certain extent of anonymity is something I expect online and having Facebook cookies on my laptop made me feel exposed: I want to be just "old-gregg" when I see fit and creepy facebook integration takes it away from me. Although I do appreciate you making yourself available to feedback in a direct ad-hoc way. Very unusual for a company of such size.
- wavesplash 16y agoThanks for reaching out Bret. Some suggestions going in order from user focused to app/site focused: 1) Fix graph.facebook.com to respect user permissions. graph.facebook.com/userid publicly leaks real names and UIDs even when users ask to be non-publicly searchable. This is creepy and makes users nervous that they don't have control over their privacy. 2) Give users back granular control to explicitly disallow sharing of any info they wish to keep private. This includes their friends graph, likes, wall access, etc. (empowering them to have the choice will reduce the sense of lack of control). 3) Let the application/site owners describe what they intend to use the information for. Ideally hold the app to the contract as well. example: "Need access to your wall in case you explicitly tell us to publish/share something on your behalf - we will never post to your wall without your approval". Anecdotal story: I showed someone Quora 2 nights ago as suggested they sign up. She said "Why do they need my Facebook? No way!". When asked "why?", she said, "I don't want that site spamming my wall - who are they?". My takeaway: If Facebook wants to be the login for the web, it needs to give people comfort that they have control over how an app/site behaves on their behalf.
- lsemel 16y agoBret, Thanks for chiming in here. At our startup we are trying hard to reassure users we're not going to misuse the Facebook access they're giving us. Even though we're asking for a fairly limited set of rights, the permissions screen that appears after the Facebook Graph login is quite intimidating. The design has a warning stripe across the type that is reminiscent of a danger sign, and combined with the copy, inspires a feeling of alarm. See http://developers.facebook.com/docs/authentication/ http://developers.facebook.com/docs/authentication/ for a screen shot. It would be better if the screen were friendlier and less evocative of danger. Another way to improve the user experience would be to consolidate the login form and permissions to a single screen. Twitter's oauth login screen does this well. Screen shot: http://followfridayhelper.com/images/help-login-via-oauth.png http://followfridayhelper.com/images/help-login-via-oauth.pn... Additionally, the oauth tokens should be long-lasting by default. We originally set up our site to not ask for an extended-life token, because we wanted to reassure users that we weren't going to be posting things on behalf when they weren't using the site. But this ruined the user experience. A short time after logging in to our site, a user would initiate an action, but because their token had expired, we had to pop open a new Facebook login window, interrupting what they were doing. Users were annoyed at having to constantly re-login to Facebook. So we now ask for the extended life permission. While this improves the user experience, it adds another intimidating message on the Facebook permissions screen, implying we're going to be posting on their behalf even when they don't initiate it. Happy to chat more about what we're doing and give additional feedback. Lee Semel
- cloudbrain 16y agoUser's are terrified that an app will spam their friends. The users that aren't are pre-teens that don't care or older adults that don't know what spam is. On one of our apps, we improved FB connnect usage by 50% by adding the disclaimer "This won't post anything to your wall or friends. We promise." under the connect button. Developers need help reassuring user's that an app is not evil. The current FB dialogs are sterile and ambiguous and don't help. I realize this might not be winnable because (1) many apps are trying to spam and (2) Ultimately, Facebook wishes users would share as much as possible.