5 ms·
Ugh. That reset procedure did not play well with LastPass. I logged in (old password), hit change password (old password), then had LastPass generate a new pas
by larsberg 13y ago
Ugh. That reset procedure did not play well with LastPass.
I logged in (old password), hit change password (old password), then had LastPass generate a new password, which it handily saved over the old one in LastPass. Hit Save. And then the site asked me for the old password a third time.
Whoops! I don't have that anymore...
- jyxent 13y agoHa ha. I did the same thing. If you edit your password in Lastpass, there is a history option that will show your old passwords.
- SideburnsOfDoom 13y agoYep, I had almost exactly the same thing using a different password manager. I had to find another copy of the password storage file on a different machine and bring the old password over from it. Note to Kickstarter: It is not good UX to ask for the new password, and then the old password. But that's likely the least of their worries right now.
- Silhouette 13y agoNote to Kickstarter: It is not good UX to ask for the new password, and then the old password. That is at least debatable. It might be a good idea to warn users that this will happen, if it's not immediately obvious from the form layout, but reauthenticating at the end of a lengthy or multi-step process is often a sensible precaution. Every system I use where security really matters (transferring significant amounts of money to another party from my bank account, filing statutory tax returns, etc.) does this. (This isn't to say that a process for resetting a password that required the old one three different times would be sensible. But I don't accept your general-looking claim that it's bad UX to ask for the old password after the new one.)
- SideburnsOfDoom 13y agoI take the point that this may not be as general as I thought, and that warning up front is an alternative. But in this case (or any password change case, really), it is not a "lengthy or multi-step process" and putting the old password at the end has surprised a number of people in a bad way. Not just here, I've seen the exact same thing mentioned on twitter. See https://twitter.com/blowdart https://twitter.com/blowdart , "Wow, the kickstarter change password process is AWFUL. Prompt for existing password after? Screws up lastpass flow" - it has multiple retweets and "me too" replies. I would have no problem with entering my password at the end of a lengthy high-value transaction, so long as that transaction hasn't also changed my password to something else earlier. Which it shouldn't. A rule of thumb is that if a lot of people find the process is broken then the UX is probably bad, and needs a redesign.
- Silhouette 13y agoA rule of thumb is that if a lot of people find the process is broken then the UX is probably bad, and needs a redesign. That is true, though in this particular case it's not clear whether it really is "a lot" of people or more a vocal but possibly small group who are also using another specific tool, which might itself be the problem because it isn't flexible enough to do the job here. It sounds like you have a password generation/management tool where it is easy to delete a valuable password before you're done with it and with no way to get it back, which I would argue is probably a much more serious usability problem! Ideally the change password process would be made clear for everyone and avoid the problem entirely, of course, and if we're just talking about a simple old/new password form (I haven't seen it) then surely that should be possible here. I'm not defending the status quo (again, I haven't seen it). I'm just saying I don't think this issue is quite as simple as you previously suggested, and possibly Kickstarter aren't the only ones with room for improvement here.
- SideburnsOfDoom 13y ago> more a vocal but possibly small group who are also using another specific tool This has now been mentioned as a problem in 4 different tools: LastPass, KeePass, iCloud password manager and RoboForm. While it is sadly still true that people who use password managers are a small minority, they are among the most security-conscious and technically literate users. > It sounds like you have a password generation/management tool where it is easy to delete a valuable password before you're done with it You could look at it that way. But I think that would be myopic. It's IMHO closer to the truth that this website is perverse about when you are done with the old password. And no other website that I have come across shares this defect. > if we're just talking about a simple old/new password form (I haven't seen it) Wow. So much invested in evaluated something you haven't experienced, but could easily.
- PaulKeeble 13y agoYep that got me as well. Ironic considering its the tool they recommend. Clearly they never tested that update procedure.