4 ms·
Automated password resets are a solved problem. Either email a new pw or reset link to a known address, or authenticate with "secret questions". Both have thei
by synnik 16y ago
Automated password resets are a solved problem. Either email a new pw or reset link to a known address, or authenticate with "secret questions".
Both have their problems, but no small company should waste support time when established techniques are available.
- michaelbuckbee 16y agoThe items you mentioned mitigate but do not "solve" the problem. We often have users forget what email address they used when they first signed up (work, personal, their kids email because they aren't a "computer person", etc). Probably not so coincidentally, these same users are the ones that struggle the most with basic computer tasks like opening a URL from an email, etc.
- Hexstream 16y agoYou can just let users initiate a request with their login name, no?
- michaelbuckbee 16y agoUnfortunately that is even tougher for users to remember as there is even less context.
- saurik 16y agoThis assumes that something like their e-mail address is static: in the real world it isn't. Normal users often use e-mail addresses assigned to them from their ISP, school, or work, and think nothing of the fact that these are needlessly transient identifiers. In practice you simply cannot automate the problem "I forgot my username/password". (EDIT: Oh, and I misunderstood your comment: no, you cannot have them initiate the request with their username, because they probably also forgot their username. I thought you were saying that they could initiate a request to look up their username before looking up their password, which has the "no stable identifier" problem I ended up going into.)
- saurik 16y agoThis assumes that the user remembers his username (very unlikely: their favorite username was likely taken on this site; my mother actually had a binder where she had written down every username she had been forced to use on every website she had ever gotten an account with) and that he has a static e-mail address (end users don't: they use temporary e-mail addresses assigned to them by their ISP/school/work) or at least remembers the answers they left to those challenge questions (which people often just type random gibberish at because they consider the answers private/personal). When you get users e-mailing you, incredibly angry, insisting that you help them because they are spending $X at your website and they can't even log in, you realize you can't pretend that these fully automated solutions work for normal people. Hell, if you want to know real pain: normal users don't even have a single Gmail account, so my #1 support issue is actually users who log into my site with the wrong single-sign-on account and then get angry that none of their stuff is there anymore.