6 ms·
Yes, actually we don't want ANY login/registration. Just put auth info in a cookie, and let the user associate it with an e-mail address later, once he actuall
by uribs 14y ago
Yes, actually we don't want ANY login/registration.
Just put auth info in a cookie, and let the user associate it with an e-mail address later, once he actually knows he will keep using the service.
I believe "I can't be arsed to register" is one of the top reasons websites lose prospective users.
- yebyen 14y agoI learned today that StackOverflow (and company) have responsive support persons who respond via e-mail, that will help you recover and merge your cookie-based StackExchange accounts if you've lost access and there is sufficient evidence that they belong to you. (I thought I had registered the account under the myid.net provider (who is now defunct?) but no.) That has to cost a lot of money. With the dozens of ways you can authenticate with StackExchange, I don't know why I was surprised to learn I had previously created an account without actually creating an account, but it was so. Also, anyone who reads Korean can tell me if this says "sorry we're closed"? http://kingdon.myid.net http://kingdon.myid.net
- rogerbinns 14y agoWhat is infuriating about the stackoverflow sites is that they treat each site separately so you end up with multiple logins across the "network" that you really don't care about. Then they do that annoying thing where they display the page, then detect you are "logged in", and then tell you to refresh.
- k3n 14y agoThat site is very good at Q&A, but UX wise it's terrible. It's as if they've only ever tested it with their own devs, and never done any real hallway or external usability testing. I've tried to participate in their "meta" site, but the pedantic and condescending tone there is even worse than it is on the main sites.
- presidentender 14y agoFurthermore, Atwood seems to take the success of the platform as a ringing endorsement of all its characteristics, as evidenced by the recent commentary on user experience and the development of his forum.
- twic 14y agoBob Martin's recent "And I'm very sorry that when you finally brute-force your way to some modicum of success that you will credit your bad behavior, and recommend it to others" has sprung unbidden into my mind once again ...
- fryguy 14y agoI think this is mostly to do with cookies not working cross domains (for obvious reasons).
- jessaustin 14y agoThis seems likely. Still, with a bit of planning they could have gotten around this. Everything dealing with identity could have been served from a single domain. There probably would still have been issues, but they would have been resolvable.
- TazeTSchnitzel 14y agoBut Google manages to do this, I'm unconvinced.
- yeonhoyoon 14y agoit reads: thanks for using myid.net so far, we have decided to discontinue the service. date of close : 2013-02-27
- yebyen 14y agosomehow I knew this question would get answered here, thanks very much!
- jdechko 14y agoYes! I hate it when I have to register for a service, wait for the email activation link only to find out that I that the service isn't for me. Then I have to delete the account and wait for emails to come to unsubscribe to those.
- k3n 14y agoEven worse is that many times you can't delete your account, or if you can, it's just a soft-delete -- and now that site has your email address (at a minimum), and sometimes may have much more information about you. Call me paranoid, but I think "deleting" your account has the potential to actually do more harm than good, since in doing so you are voiding any agreements or terms that you had previously agreed to, including those that promise not to sell or otherwise abuse your info.
- Amadou 14y agoI use mailinator for pretty much every site that wants an email address. Pick an obscure enough address and your risks are minimized to practically nothing but you get all the convenience of "deleting" your account simply by never thinking about it again.
- k3n 14y agoI have a domain with a catch-all address, and so I just makeup addresses to use on the spot, but I know people like me and you are in the vast minority; none of my non-tech friends and family would ever do this. Also, sites like mailinator are often banned from sign-ups.
- yebyen 14y agoI know this will not work everywhere (not everyone implements correctly the RFC's regarding e-mail) but if you have an address, you can make up addresses on the spot by using the + notation eg messages to myrealemail+mytag@gmail.com will always be received by myrealemail@gmail.com I too have a domain with catch-all, and I do that rather than using the + notation, but it's something you can teach your friends who would never do that.
- mrweasel 14y agoThat is absolutely true, or at least I think it is. The single best thing we did it to allow our customer to do a purchase without being logged in. If the email address entered on our checkout page is already in our database, we link that purchase to the relevant account. If the customer want to login, they can, if not, that's cool to. We get a lot of wrong matches which needs to be fixed, but that seems to be a price we can and will pay. We have had customer adding orders to other people accounts, because their email address was entered wrong ( even though we require the customer to enter the email twice. ) and we have customers ending up with multiple account that we need to merge. Despite all the problems, customers love not having to log in before doing a purchase. It's hit and miss in a few cases, but we try to do what our customers expect, matching their purchase to their account, regardless of login credentials. That's what consumers want.
- ersii 14y agoJust wanted to say Thank You. I wish more people/stores would do this.
- tracker1 14y agoWe did the same thing with one of the sites at work... You can make a purchase without login, and the related emails to a given order includes a token so you can see that order's status without login.. If there isn't an account at that email, we generate one with a few space-separated random words, and email the user... password recovery is email only and pretty easy. All in all, the user experience has been pretty well received. Now that I've seen this in practice, it would be my preferred way moving forward. It didn't/doesn't take that much effort to do things this way. The bigger issue is in the occasional phone order our demographic is mostly men 50+, so some genuinely don't have email.. we use an internal address in that case...
- tracker1 14y agomeant, we generate an account were the password is some random words...
- eric_the_read 14y ago
- vy8vWJlco 14y agoOne could use something like a copy-and-pastable session/state string/encoding (that a user should keep secret, if secrecy is important to them) at the bottom of every important page that a person might want to return to (rather than in the URL or the invisible, and therefore unmanageable, cookie). If they care enough to save it, they have an account (ex, they don't have to fill in their shipping info for the 9th time...). If they don't care enough to save it, it can be automatically deleted after a period of inactivity. (This was a common solution to "saving state" in older video games without persistent memory. It wasn't "too complicated" either. People used it, if they wanted to get back to that difficult boss level.) A login is a continuation, or a state/session key. So is a link/URI. There's no need for a mandatory "account" just to be able to pick up where you left off, even if it's to continue checking your email. (Though one could opt-in to further "protect" pages with passwords, biometrics, non-invasive mucus swab samples, and so on...)