6 ms·
If reducing friction is the priority, then maybe skip email completely. Let people sign up with any username and don't require an email at all, like HN allows.
by MichaelCollins 4y ago
If reducing friction is the priority, then maybe skip email completely. Let people sign up with any username and don't require an email at all, like HN allows. Most sites that require an email don't need an email, and only ask for it so they can spam users with nonsense like product updates.
- marcosdumay 4y agoAny site that requires a password will need an email for password resets.
- MichaelCollins 4y agoIf the site doesn't need email for anything besides that, then it doesn't need email for that either. Let the user set an email for account recovery if they want, but don't require it. If users who choose not to give an email forget their password, they can simply create another account. This is the way HN works. It's the way most websites used to work, until maybe 15 years ago, give or take. Today almost all sites ask for verified email addresses, but this used to not be the case. Besides the commercial value of having user email addresses, I think it's mostly done for the webdev's ego: > Users need to hear about my new update! (Because if I don't spam their inbox, nobody will notice or care about the thing I just did.)
- ben0x539 4y agoI think the webdevs are right about this one. People lose or forget passwords all the time (in general not using password managers). Permanently losing access to an account sucks a lot. Tying account ownership to email primarily with passwords being more or less an optional convenience saving you the email roundtrip seems worth it.
- parminya 4y ago> Permanently losing access to an account sucks a lot. But mostly that's all. Usually it's a minor inconvenience. Occasionally it sucks a bit. Rarely it sucks a lot. Almost never is anything of value lost. It can be wholly eliminated by good data practices e.g. backups. (No one backs up their Amazon account data. It isn't designed for it. Because the "webdevs" think of the data as their boss's - squarequoting "webdev" because the effective decision is the CEO's and the "webdev" is just taking some abstract, ill-thought-through decision and making the ramifications concrete.) On the other hand, it also sucks a lot when your gratuitously collected private information is taken to the darkweb. As countries become more accustomed to dealing with databreaches, they are beginning to consider legislating harsh compensation requirements and painful fines. Once that's happened, almost all of the private data that the user has in their account? Let the user keep it. We webdevs and our mortal enemies in business/sales/product will have to innovate new decentralised databases - where each node is a users' computer. And yeah, some things will be harder or not even possible (for the user). Other things will become possible that aren't at the moment (for the user). And at least you won't go bankrupt when a state level actor decides your database is valuable.
- EamonnMR 4y agoMost people need to back up is a receipt for their transaction, and the main method people expect for receiving it is... email.
- Alupis 4y agoThere are some exceptions to this. Notably, Amazon is ruthless in enforcement of their "One Person, One Account" policy (worded not so eloquently in their official terms). If you lose access to your Amazon account and open a new account, there's a non-trivial chance they shut it down without explanation. If your account ever participated in the marketplace from a seller side, then this policy is even more ruthlessly enforced. Which means... email address verification is necessary for Amazon to at least guard against type-o's and other common form data-entry errors.
- jhauris 4y agoIs this policy for a specific kind of Amazon account? I didn't recall seeing anything in the TOS, and they appear to have first class support for people with multiple accounts. https://www.amazon.com/gp/help/customer/display.html%3FnodeId%3DGVJHDP5AF9RB7R4R https://www.amazon.com/gp/help/customer/display.html%3FnodeI...
- echelon 4y agoI worked for a big fintech. - Zero email validation at signup measurably reduces friction. [1] - Require email validation for bank deposits, once your customer is further onboarded and invested in the product. - Encourage 2FA and other measures as the customer grows. [1] (Much to the chagrin of all security-adjacent, marketing, account owning, risk, ATO prevention, etc. teams. I was directly in the path of these decisions, and it was interesting to see the various stakeholders argue their points. Growth funnel wears the pants.)
- EamonnMR 4y agoYeah you may not realize that a significant fraction of people don't remember passwords at all and need to reset on every login. If you don't allow self serve password resets you're creating a huge customer service burden.
- fabiospampinato 4y agoNot true for end to end encrypted stuff, the server can't reset anything.
- matt-attack 4y agoI’ve had my Reddit account for 15 years. Never given them an email.
- ruined 4y agosending those messages is part of the same business case as reducing friction by not confirming the address :)
- blacksmith_tb 4y agoI'd say that depends on what 'a conversion' is - if it's buying physical things (and getting shipping confirmations for them), an email is maybe not absolutely required, but most of your customers would probably still rather they got those?
- MichaelCollins 4y agoMaybe they want SMS updates to their shipping, does that mean you should ask for confirmed phone numbers on signup? Of course not. Let them enter their email or phone number for shipping updates when they're confirming their purchase. Ideally you shouldn't require users to make an account to make a purchase at all. There should be a "guest" path for purchases. Some sites still get this right. I can buy anything from plane tickets to pizzas without having an account on the company's website. Meanwhile half the "Show HN" non-commercial toy websites I come across seem to require a confirmed email for no good reason at all (probably because the webdev is hoping his little toy website somehow becomes a real business, and then he can spam my inbox with updates about this and turn me into a paying customer.) Off the top of my head, here are some companies that don't require me to confirm my email address when making a purchase or an account: Southwest Airlines. Dominos Pizza, Hacker News, Reddit. If those guys don't need a confirmed email address, probably your site doesn't either.
- Alupis 4y agoThese are not good examples of everyday websites. Southwest Airlines knows an awful lot more information about you than you provide them. They don't need your email address because they know who you are - and they make it your responsibility to monitor changes to your schedule/flight. Dominos Pizza allows you to monitor in real time the status of your delivery on their website after checkout. You can provide an email address to access the tracking status page again if you close it. Hacker News is not a good representation of anything outside of a very tech-focused forum. It's designed to be anonymous, there is nothing to keep track of (order status etc) and if you lose your password to HN, you might just be SOL. That's not going to fly for the general public. Reddit is focused on eyeballs and clicks - nothing else. You're not buying things on Reddit and waiting for them to deliver to your house or whatever. Reddit just needs you to click and look at things to make money. Reddit also requires an email address, but if you don't provide a real one then you're SOL if you lose access. Again, not going to fly for the general public. The reality is, most regular sites do need a reliable way to contact you for business reasons. Some are even required to have your contact information (for international shipments, as one example). Your email inbox does a good job of holding emails for you, so let's stop pretending it's a huge burden to get an email... and if you find your way onto some newsletter list just click the unsubscribe button. It's not that hard...
- gauravphoenix 4y ago>spam users with nonsense like product updates IMHO, not all product updates are nonsense.
- MichaelCollins 4y ago[x] - Send me emails about product updates. (Receiving these emails should be opt-in. But companies often find lame excuses to ignore this preference so I prefer to not hand over my email address at all.)
- renewiltord 4y agoUsers are trained to put in their email. Making them choose a username increases friction if the username is non-public (i.e. it's not instagram). Ideally, using SSO speeds the whole thing up, but if not, then it's better to just use email.
- jstarfish 4y ago> Most sites that require an email don't need an email, and only ask for it so they can spam users with nonsense like product updates. Not the only reason. It adds friction for people trying to create an army of sockpuppet accounts.
- account42 4y agoNot a lot of friction. Especially if you don't restrict the allowed email providers.