3 ms·
My biggest one is... Requiring users to login with a username or customer id. (instead of email).
by Solvitieg 8y ago
My biggest one is...
Requiring users to login with a username or customer id. (instead of email).
- iscrewyou 8y agoYeah, this is the biggest one. I remember Google used to do it too! (Not sure if they still do because I haven't tried it). Google would let you log in into your google account with a yahoo email address (or any email address I presume) as the google id. It threw me for a loop the first couple of times.
- frosted-flakes 8y agoMy username/email address for my Google account is not a GMail address. I don't use GMail, and it would be ridiculous if I was forced to create a GMail address to be able to sign in to YouTube, etc.
- Casseres 8y agoMy biggest (related) one is… In the sign-up process, validate the email (don't trust the user). I get a lot of emails that companies never validated, including for a while, from Wells Fargo.
- wccrawford 8y agoI was getting insurance claim information from a large company in another state for a while. I finally made a big enough stink that they took my email off the account. And yeah, I'm sure it was the real company and not some phishing emails.
- curun1r 8y agoUnfortunately, the trend is in the opposite direction. People have realized that email validation is a step in the funnel where you lose users. And when you look at it as a funnel conversion optimization problem, you arrive at myopic conclusions that are insecure and have externalities like the one you noticed.
- deleted 8y ago[deleted]
- funkymike 8y agoThis bugs me as well. American Express kept sending me information about someone else's credit card. It took arguing with their customer service for about 20 minutes to get them to remove my email address from the account.
- Ayesh 8y agoI always hesitate to even use a service that has customer IDs. Most of the frequent flier programs have numeric IDs and there's no way I'm going to remember them. It makes things worse because you don't always have a password manager-enabled device when you travel. There is also a bank in my country that your login username is first name+birth year. It's even worse than an email address as username.
- trizic 8y agoIn my experience I am glad that banks don't use email as login. Most sites compromised were using email as login which is now input for bots to test on other sites. Having a unique login ID per site such as using myemail+xyz@gmail.com could help.