9 ms·
A user deletes their Facebook or Twitter account. I don't have their email address. They try to login and can't. They have to now email me and prove to me which
by Lockyy 12y ago
A user deletes their Facebook or Twitter account. I don't have their email address. They try to login and can't. They have to now email me and prove to me which account is theirs so I can reset the password, give it an email and let them regain access.
The account may be a free account but it can still contain data a user wouldn't want to lose. Ensuring from the get go that they can recover their data just makes things easier.
Regardless of how legitimate you think my usage of email addresses is the inability to even ask for it _is_ a downside. For those use cases that do require it immediately you now have a system where the user clicks the 'Login without filling in a form' button and gets thrown to a form anyway, which is exactly what we were trying to avoid.
- moron4hire 12y agoThis is called "over-optimizing for low-likelihood scenarios".
- cessor 12y agoWell yeah, a crime - or should we say contravention - that we are all guilty of at some point in our professional lives. Depending on how many users his service has, this could be a significant amount of work, even though the absolute probability of it happening is very low.
- cessor 12y agoI see, you are asking for the email address, so that people can unlock their account in case they delete their oauth token provider (i.e. their tw/fb account), did I understand that correctly? But do you have to do this whenever a completely new user tries to access the website? Is setting up an alternative access method not a very different concern?
- mreiland 12y agoyou could ask for a unique identifier that isn't an email address.
- billiamram 12y agoSimilar to how google asks for a phone number eventually as a back up convenience in case you get locked out, would dong the same with email make sense? That seems like it would build trust and give the user control over their own risk.