3 ms·
I can't say how common this is, but many (most?) online accounts I personally interact with are disposable, represent no sensitive information, and I couldn't c
by kylebyproxy 5y ago
I can't say how common this is, but many (most?) online accounts I personally interact with are disposable, represent no sensitive information, and I couldn't care less if they're compromised. They're one-time sign-ups, junk accounts, free trials, free tiers, etc.
> one of the most frustrating experiences
I understand this frustration as a mismatch between the user's non-expectation of security and the service's obeyance to industry security best practices.
Placing a cognitive burden of memorizing a new password just to try out your product strikes me as cruel.
Maybe only enforce password rules as progressive enhancement once sensitive information comes into play? After all, what's the point of protecting junk?
- MomoXenosaga 5y agoYes every service considers itself critical. But users don't give a shit if some forum they signed up for 3 years ago gets hacked. For me I just see it as a sign of pretentiousness when you expect me to come up with a 20 character password. Luckily Firefox has a built in password generator now.
- johannes1234321 5y ago> But users don't give a shit if some forum they signed up for 3 years ago gets hacked. It depends on the forum and the hacker. Most hacks won't have a practical implication, but a targeted attack by somebody unhappy with your comments might abuse your identity or information the account reveals. Or a forum can reveal information you don't want to have revealed (medical help forums, sexual stuff, ...) And sometimes you are really to leave "child times" behind you, which might reach surface again later. (Say when you get into a political career ten years later and somebody finds your mail address and searches through dumps of leaked data etc.)
- zamadatix 5y agoPasswords often protect things like random niche forum boards from grief more than they protect the user's sensitive information in such cases. 3rd party auth is a great solution but a lot of people don't want to tie their "real" accounts to the low tier sites. MFA is of even greater help for low tier site's pains but if you can't get someone to use a decent password or link their identity how likely are you to set up 2FA for it? In the case of "free" services type signups they want you to onboard your information or link your identity and an account workflow is the easiest way to do that as it's a small percentage that will go through the trouble of burner or temp emails and fake info yet at least you have an easy way to rate limit such users from hijacking your "free" offerings. Also you're not supposed to be memorizing anything for logins. At the very least you should be letting your browser use the randomly generated password and save it to the browser password store if you're not using a full blown password manager.