13 ms·
There's been a recent tendency to split login forms into username/password over two screens as mentioned in this article. It's maddening. Password managers can'
by colinramsay 8y ago
There's been a recent tendency to split login forms into username/password over two screens as mentioned in this article. It's maddening. Password managers can't deal with this, unsurprisingly. I don't see the benefit this provides for anyone.
- amaccuish 8y agoThat is quite useful however with some federated auth flows, where you just need the email to see where to send them for the actual auth (e.g. Office365 and SAML login), otherwise you'd needlessly be entering your password. I also much prefer it to the previous way e.g. Office365 worked, where once you'd tabbed away from the email box, they'd detect you needed to be redirected and send you off, whilst most people had begun typing their passwords.
- 8ytecoder 8y agoYeah, federated flows were my guess too. However, the password fields could have been present and hidden in the same page supporting both password managers and avoiding a page transition. And also the hundred other sites that don't need federated flows but think they need to copy this feature as well. Together it's annoying to hit password managers twice for every login.
- amaccuish 8y ago> However, the password fields could have been present and hidden in the same page supporting both password managers and avoiding a page transition But then you run the risk of your password of being submitted to the wrong portal no? > And also the hundred other sites that don't need federated flows but think they need to copy this feature as well Very true. It seems to be becoming increasingly prevalent :(
- 8ytecoder 8y agoi) Hidden and ii) Nothing I enter should be submitted anyway in an SSO flow.
- blattimwind 8y agoPage 1: Email/account name, Page 2: Okay, here are some recatpchas, Page 3: Password. Mistyped it? Start back on Page 1 please.
- tomc1985 8y agoPretty sure that is why... you enter your username and it checks to see what authentication flow to use, if it's a password flow then you get a password screen. Pisses me off too
- deleted 8y ago[deleted]
- jrwoodruff 8y agoBingo. This is why we went with a stepped process. Did you log in with Google, Twitter, Enterprise SSO, or Email? Do you even have an account, maybe you need to create one? It frustrated everyone. Since we've implemented the stepped process (and made other changes) complaints have all but disappeared, and the number of failed sign in attempts has been significantly reduced, successful logins has increased slightly, and overall login attempts dropped. It's not perfect, but all indicators are it's better than a screen full of options - it allows us to guide users to the correct action. Sure, it can still be annoying, but less so than what it was.
- StavrosK 8y agoYour comment confuses me, can you clarify? > This is why we went with a stepped process. [..] It frustrated everyone. But then: > Since we've implemented the stepped process (and made other changes) complaints have all but disappeared
- thisacctforreal 8y ago"[..]" was a list of all the problems that frustrated people before the stepped process.
- StavrosK 8y agoOh, I see, thanks. The list sounded to me like a description of the stepped process, so I was confused.
- 8y ago
- chayesfss 8y agoYes, splitting up auth flow allows you to query auth requirements, query apis for risk/security and more
- joshklein 8y agoWhat reasons are there to avoid doing this asynchronously? (Please note that I’m opposed to requiring user agent javascript to access something claiming to be a website, but let’s assume we’re talking about something behaving like a single-page application post-authentication anyway.)
- enlyth 8y agoI'll give my perspective as a web dev, it can be tricky to time the requests and decide when to query the API asynchronously. Consider a user starts typing an email address, when do you send out the first async request to find out what authentication flow is required? On each onChange event, first time the email is valid, would have issues that your email is foo@bar.com, but foo@bar.co is already valid, so you're probably going to debounce the call by a few hundred ms. What if the user makes typos, or if they are typing in the email very slowly, and so on. You might say it doesn't matter, just don't show any UI feedback until its valid, or keep refreshing the current status, but the problem is your control flow is decided by the email that's typed in. You want to redirect certain users to an SSO page, others to type in their passwords, and so on. susan13@domain.com might need a different authentication flow than susan13@domain.co, which are both valid addresses. Another choice is the onBlur event, but this becomes clunky. Think about when it's triggered and how you would incorporate this into a nice UX, I don't think it's possible. The inversion of control, giving the user time to fill the form in, and press an explicit "Ready, I've typed my correct email in, what's next?" button, makes the flow easy to code. I hope this helps.
- Raidion 8y agoThis is so true it hurts. It honestly sounds like a pretty great idea, so I can see why product would be behind it. "We won't have a login experience like other providers, it would be a total $BRAND_EXPERIENCE_HERE" Then you start getting into the weeds and it's really just not possible to do well.
- jakob223 8y agoDropbox does an AJAX request when you enter your username, and it's fast enough that when you get to the password field it's already greyed out if you use SSO.
- khalilravanna 8y agoThis should be the answer. As soon as the user enters a valid email (regex test) send a request to server to figure out what path they need to go down in the “federated flow”. What we shouldn’t do is diminish the experience for some because the flow for some others is different.
- underwater 8y agoYou shouldn't have a giant sign asking people for something they don't have, it's confusing and discourages people from using your product.
- franciscop 8y agoIt should be onblur, otherwise you'd send requests for: - me@example.c - me@example.co - me@example.co. - me@example.co.u - me@example.co.uk And you'd have to account for all those tricky race conditions happening there
- pmontra 8y agoAnd me@example.co could be the email of another user, so you'll never be able to login with yours.
- velobro 8y agoHelpScout's login is anothrt good example! Definitely echoing other's thoughts that it's the correct way to handle it
- jakear 8y agoDropbox manages to provide both fields, but instantly switch the password to be a “sign in with blah blah” when you’ve typed your email and it recognizes it as using a different provider.
- chrisan 8y ago> That is quite useful however with some federated auth flows This can't be a large majority. I only ever hear complaints. Whats wrong with the suggested way (Harvest example) of having both on the same screen and letting the user choose
- WrtCdEvrydy 8y agoTwilio does this and LastPass can work with it if you type your email address in the first screen, it will fill the password.
- tylerrobinson 8y agoI can't argue with the lack of password manager support. But I know where Product is coming from on these approaches. Asking for an email address on its own screen allows the form to check whether you have an existing account or need to set up a new one. You avoid a link that says "Don't have an account, Register Here". Is it worth it? I suppose it's subjective. Maybe the designer thinks that is a good reduction in friction. Probably more compelling is that the form can pick up your email domain and redirect to Single Sign On if the domain is known.
- etxm 8y agoIs there no longer a panic over letting an attacker know that an account does exist? I remember that being a thing for a while, but haven’t built user facing UI systems in a few years.
- nevir 8y agoIt's still a concern, but often forgotten.
- reificator 8y agoI haven't heard an update on that front for many years, so I'd assume it should still be a concern. Many of the same sites that do this will also have a recovery form that refuses to leak information.
- etxm 8y agoThat’s important. I find it funny[1] when you get the “email does not exist” error on a password reset page. [1] by “funny” I mean not funny
- reaperducer 8y agoI wonder if that's a way for spammers to harvest known good e-mail addresses.
- zrail 8y ago1Password handles this just fine. You just have to hit the button twice.
- mbesto 8y agoSure, but it's definitely YMMV.
- numbsafari 8y agoCame here to say the same. This absolutely works with 1Password, even if you have multiple accounts for a single site (eg Google, or multiple test accounts for a site you run). Split logins are very useful for federated auth, as well as for supporting different kinds of multi-factor auth.
- reaperducer 8y ago1Password isn't the only password manager in the world.
- behringer 8y agoSo submit a bug report to your favorite password manager.
- enobrev 8y agoBitwarden and LastPass seem to handle it fine as well in my experience
- dankyung 8y ago1Password X actually handles this without having to hit the button twice.
- jackweirdy 8y agoIf your platform supports 2FA, differing authentication mechanisms, or really anything that can make one accounts login process different to another, splitting it into 2 steps allows you to request the user ID first, then show the appropriate auth form for the second step. I agree you can achieve this by other means, but services may have their own reasons for doing it this way.
- deleted 8y ago[deleted]
- scarface74 8y agoI’m thinking about how sites like the Amazon card payment site works. You enter your username and password, it sends you an MFA text that iOS automatically recognizes and offers to populate in the field.
- usgmr 8y ago>Password managers can't deal with this, unsurprisingly. I use a password manager too and often wonder about this. Does this responsibility fall on the website's designer/developer or the password manager? In one hand, I'd like my password manager to work on every site too but on the other, being a web developer/designer, I don't want another thing to support. We already have browsers and browser versions, and browsers and browser versions in specific platforms to keep track of. Do I want another layer of something to keep track of? (This is totally unrelated but another thing I apply this question to is a page's/websites ability to support reading mode. You have straightforward pages that you can read wholly in something like Firefox's Reader View or Instapeper/Pocket. Then there are those pages that rely too much on some javascript library (sliders, read more, etc.) to display properly that gets broken when seen through reading mode.)
- mikeash 8y agoThinking pragmatically, a password manager can fix this in one spot, while weird web pages will always be around.
- brianpan 8y agoBoth. It's basically an accessibility problem. Should screen readers be able to handle some unusual pages? Yes. Should websites design for accessibility? Yes.
- mnm1 8y agoAs a developer you should support a proper form that works with password managers. Period. Anything else is a failure on the developer's part to create a working login. It's also a massive security hole you've introduced by encouraging people not to use password managers. They will try to remember the password and we all know where that leads to. Sorry, if you think you can develop a login form that doesn't support password managers and call that a decent effort, you're badly mistaken. That's just shit engineering.
- hombre_fatal 8y agoWhy don't you respond to one of the comments that point out sensible reasons why a website might do this instead of using this as an opportunity to suggest that people are just incompetent?
- DannyB2 8y agoNot only, as someone else pointed out, does the 2nd step of the login (eg, password) vary depending on WHO is logging on, it is theoretically possible that there is no 2nd step in some cases. Maybe you have a USB dongle, and after entering your name or email, you are authenticated. Maybe the machine is trusted for any user who logs in, because it has a USB dongle. Or maybe only certain users, but more than one user is trusted associated with that USB dongle. Or maybe if YOUR phone is detectable as near by, then you have no 2nd login step. There are lots of arguments why putting the user ID and password onto a single form is just plain wrong. This isn't the 20th century anymore.
- optimuspaul 8y agomy password manager has no problems with this
- andrewshadura 8y agoThe Firefox’s built in password manager deals with it just fine. No idea how, and no idea why others can’t cope if it can.
- dontbenebby 8y ago>Password managers can't deal with this, unsurprisingly Maybe I'm overly paranoid but I choose to manually copy my passwords out of my manager into the login form. Then again I also use a PW manager that doesn't support cloud storage. (Though you could always throw your DB into Dropbox if you desired)
- jakelazaroff 8y agoWhat's the benefit of doing it that way?
- dontbenebby 8y agoI've seen some CVEs where malicious websites induce your browser to autofill (basically steal passwords). So the intention is that I stop some script from siphoning my passwords. This admittedly opens me up to phishing, but to mitigate I also have containers set up for various facets of my life. (So it's a big red flag if what's supposedly my bank doesn't open in the "bank" container".) Edit: I also value storing the database locally versus "in the cloud"
- wccrawford 8y agoThat's why you should turn off auto-fill.
- saagarjha 8y agoThis is why most password managers no longer autofill without user interaction.
- FabHK 8y agoYour web browser doesn't have any connection to your password manager. Who knows what your web browser is doing, why would you give it any access to your credentials?
- donarb 8y agoThe Safari browser can be linked to the Keychain Manager, both products coming from Apple.
- Scooty 8y agoThe few times I've seen this (Google and Amazon I think), my password manager (Lastpass) has had no problem, but I've run into several sites where simple two input and a button login forms don't autofill correctly. Usually the username field will get cleared when the password gets autofilled, so I have to manually paste the username. I wish password managers would become popular with non-tech people already. I can't wait for a day where there's just a "Sign in manually" link for the few people that manage to remember their 1200 usernames/passwords. Password managers shouldn't need to rely on autofilling inputs at all.
- SlowRobotAhead 8y agoAgreed. I have a handful of split username then password on a new page sites, and LastPass handles those just fine. It doesn’t do well with banks that think they are being clever though.
- swiftcoder 8y agoI'm honestly not sure why the password managers don't offer federated login (with SSO helped out by their browser extension). As a website owner, I'd love to be able to throw a "login with lastpass" link on the sign in page.
- Too 8y agoOpenID provides federated login and is already widely used. It's not frictionless however and didn't really take off as much as people first expected due to usability problems with login-urls as user ids and anonymity to website owners.
- jiveturkey 8y ago1password deals with this just fine.
- blktiger 8y agoMicrosoft does this and the built-in password manager on Safari works with it just fine.
- Semaphor 8y agoWhile it can't handle the email part, at least mine nowadays handles the password field. I use KeePassXC-Browser (connecting to KeePass despite the name) and it recognizes the password field even if I entered the email in an (annoying) extra step.
- varjolintu 8y agoActually it can handle the email part also. You just have to add the site URL to Site Preferences in the extension's settings and enable Username-only detection. It's a necessary extra step so the credentials wouldn't be filled to search fields or to other single input fields. It's quite hard to detect if an input field is actually a username field.
- Semaphor 8y agooh, that's good to know. Thank you, this will make Microsoft logins much more bearable.
- avip 8y agoSecurity.
- TomK32 8y agoBrowserpass doesn't have any problem with those.
- bobbybroadcast 8y agoIt doesn't? Am I confused about something? When I do it I always have to enter the login, then click again and enter the password.
- tylerl 8y agoActually this is necessary in order to support federated auth. Password managers have already figured out how to support this transparently, so it's a non-issue anymore... Including even Chrome's built in manager, which is not exactly cutting edge. If yours can't cope then it's a sign that your software isn't being actively maintained very well.
- icebraining 8y agoYeah, haven't had problems with Firefox's manager either.
- deleted 8y ago[deleted]
- __jal 8y ago1Password has gotten confused a few times for me. (No way I'd ever use Chrome's. Or Apple's, for that matter.) Although now that I think about it, I think not in a while. Still annoys me - a classic example of offloading the costs of technical decisions on the user, even if those costs are "just" mental energy and a page load. At the very least, if you feel you need to do this, make the login pages very, very lightweight. One I log in to daily has huge background images that are utterly, stupidly useless, wasteful, annoying and for some reason uncacheable.
- krferriter 8y agoWhy is it a requirement to have two separate views? Why not just do the check when the user leaves the username textbox. I don't see the reason for the other page to be displayed separately.
- gammateam 8y agoThis was my first thought too I saw it on Expensify yesterday Doesn't this break a best practice? If you input an email address it tells you whethere there IS or ISN'T a user, and if there IS it asks you for their password. I thought the best practice was to make it unclear whether an email or username is in the system, which would make this a huge regression
- hombre_fatal 8y agoIt doesn't change anything. If the email doesn't exist, you can always redirect to the password form. If the user is confused about their credentials, they'll have to use the "I forgot" system in both cases.
- gammateam 8y agoExpensify shows an avatar for the user
- erichurkman 8y ago> I thought the best practice was to make it unclear whether an email or username is in the system It's useless obfuscation. 99% of systems that tell you "if you entered a valid username, we'll email you a password reset link" also don't allow duplicate accounts by email. Try to register a duplicate on their sign up page and they will tell you "this email address is already in use." Useless "security" obfuscation and creates a terrible user experience trying to reset passwords.
- pbreit 8y agoI don't see why password managers can't deal with this. In fact don't most handle it OK?
- 0xfeba 8y agoYeah I can set a delay or custom keypresses, or field IDs in KeyPass. This and OP just have to configure it properly.
- Operyl 8y agoMy password manager can deal with it: Cmd + \, Enter, Cmd + \, Enter. It is a little saddening, perhaps, but to say it’s breaking password managers entirely is a wrong.
- weej 8y agoReally? I don't have that problem with LastPass. It simply inspects the domain in the URL and DOM element name for the given web page. If it's a password field in the form (even if on separate page that's stand alone) maps back to the domain the creds are stored in LastPass it will give me the option to inject the password into the form field.
- peterhunt 8y agoFor good reason. It gives you more flexibility for when to throw login challenges to mitigate credential stuffing attacks.
- manigandham 8y agoChromes built in password manager handles this fine.
- scarface74 8y agoThe built in iOS password manager handles it.
- hnu0847 8y agoKeePass allows you to program a delay between entering the username and password, but I agree having two separate screens is annoying.
- astura 8y agoThe only time I've seen this an issue with LastPass is when the username field is on a different domain than the password field. In this case I'll save the username and password as different password entries. Otherwise it's a non-issue. Great Lakes Credit Union is an example of a site that does this.
- Benjammer 8y agoEnterprise authentication flows for multi-tenant applications with internal users, tenant users, super users, and de-coupling the identity resolution from the authentication resolution and authorization resolution.
- davchana 8y agoGoogle chrome perfectly handles my bank HDFC login, split on two pages.
- sbr464 8y agoOne possible solution is to allow a url or query param to load a full auth form for each supported provider, in addition to the default stepped screen. That would allow a user to bookmark the form relevant to their auth method.
- SomeHacker44 8y agoI never have problems with 1Password and login screens split into two or even 3 screens (for MFA). Just sayin'.