5 ms·
This is the correct answer. Just because the norm is to embed verification hashes in URLs to be clicked, doesn't mean it's the right way for it to be done. Why
by sleavey 5y ago
This is the correct answer. Just because the norm is to embed verification hashes in URLs to be clicked, doesn't mean it's the right way for it to be done.
Why not send a short random code by email for the user to then copy into the sign-up form they were in the process of filling in?
- vbezhenar 5y agoIt takes more effort and more users will decide to move elsewhere. I don't really believe that if someone can't bother to copy code from e-mail, he's worthy to have as a client, but some company are obsessed by metrics and percentage of successfully registered users is one of those metrics.
- toshk 5y agoI understand your way of thinking, but we ended up having a flow for a government site where users had 2-3 steps what normally could be done in 1. Also many were not tech savvy and confused. So we ended up adding JS to automate the click.
- inetknght 5y agoYou automated a click on a government website? So tell me: how'd that audit go?
- acdha 5y agoThis depends on your willingness to turn away business, and may not even be legal depending on where you work. In the United States, I would not want to defend that copy and paste scheme as being compliant with the Americans With Disabilities act having seen usability tests from people trying to accomplish that exact workflow using screen readers. Remember that things like cognitive impairments count and, like vision and motor control/range of motion, most of us will be affected at some point in our lives. What I do think would be reasonable is having a well-labeled link which takes you to a confirmation form: someone can follow it easily and choose to submit it with far less friction and it leaves standard web semantics intact.
- duckmysick 5y agoClicking a link (one action) is easier than copying a code and pasting it (two actions). It's possible the user will copy the wrong thing or paste the code into a wrong field, including the browser address bar. All of that may affect the sign-up rate.
- ace2358 5y agoKinda. I often read my email on my phone while working on my desktop. (Or visa versa). In these situations, a code is always better. I hate the links personally.
- duckmysick 5y agoHow many times having to click a link (instead of entering a code) stopped you from finishing a sign-up process?
- tonypace 5y agoNobody remembers the exact moment they stopped thinking about something because it was easier not to. Ragequitting is one way to exit a process, but just not going to the next step from distraction is surely more common.
- duckmysick 5y agoI'm asking because often when I talk to people about things they hate, they end up admitting it's not that big of a deal. The annoyance is minor enough they don't look for alternatives or abandon whatever they were doing. The original discussion was about clicking links vs reading and entering the code in sign-up confirmations. The former takes less steps and is easier to complete. Power users with unusual habits might disagree. But if they complete the sign-up anyway, it makes more sense to focus on regular users.
- prepend 5y agoIt’s pretty easy to measure. I had a site with a verification step. And we would see like 20% drop off of people who clicked on the link but never confirmed. Not sure why. We didn’t have them copy and paste anything, just click a confirm button. Switching to no confirm obviously changed this to 0% drop off of people who clicked the link, but the number of people who clicked was the same. It was curious to me why people wouldn’t go through with the confirmation step, but never learned why. We just learned that for some reason more people click once instead of twice.
- Cthulhu_ 5y agoVerification hashes in URLs are fine, as long as accessing the URL does not invalidate the hash yet.
- UI_at_80x24 5y agoThis is how Steam does it.
- prepend 5y ago> user to then copy into the sign-up form Extra steps are hard and boring and people don’t want to do them. I consider myself a savvy user and I want to click a link. Not click a link, then look up a code from the email, then paste, then click submit. I’d live with having to manually click “I’m sure I want to unsubscribe” or something. This is most annoying when the site wants me to type in my email address to unsubscribe. I have lots and lots of different email addresses that funnel into a single one. When the site doesn’t put my address in the “To” field, I dont know who they sent to. Services should be respectful of users time.
- sleavey 5y agoAre we really going to continue to break the paradigm that GET requests should be idempotent to save people an extra click or Ctrl+C and Ctrl+V? Standards matter. In this case Google are doing something that should be allowed, but being criticised for it because it breaks badly implemented services. Entering emailed or texted codes is becoming more common with 2FA for banking, PayPal etc. anyway so I think most people are going to broadly manage.
- prepend 5y agoSorry, GET requests aren’t idempotent. At the minimum they create log entries. So you can DDoS servers by filling their logs with “idempotent” GETs. UX is important, and I think saying “suck it users, I’m going to use GET the way I think is write” is not a positive way of thinking about it. I think the problem is just the mechanics of POST not being allowed in an email, so if there’s a way to POST from just clicking on a link I think we should use it. But there’s not, so having a GET that triggers something is the least bad thing. I like it better than javascript and forms in email. And better than autosubmitting, hidden forms on load.
- nickjj 5y agoThere were good suggestions in other comments in this HN post. One of them mentioned that you can continue keeping things as a 1 click solution with the token in the URL, but instead of doing the destructive action upon visiting the link -- instead you would get sent to a page with a form where the token is put into a hidden field that gets auto-submit as a POST request with Javascript. This way from your POV it's a 1 click solution. You only waste a second waiting for the redirect and if the user doesn't have Javascript enabled you can <noscript> the field as being an input field which is pre-filled out based on the value from the URL (this can be done server side). Now everyone is happy, unless gmail is going to go as far as auto-following redirects with JS enabled.