4 ms·
Interestingly, this was one thing PG pushed us to take out of Posterous registration. And he was right. You want to lower barriers. Since we already were gettin
by rantfoil 17y ago
Interestingly, this was one thing PG pushed us to take out of Posterous registration. And he was right. You want to lower barriers. Since we already were getting the user's email address, it really wasn't painful at all to let the 'forgot password' flow handle the case where the user mis-typed their initial pw.
- rapind 17y agoThat's a great point. The convenience to most users justifies the inconvenience to the few who miss-type their password.
- drusenko 17y agoYou have to both mistype your password AND mistype your email for it to be a problem. The percent of users who do that is minimal, and if it happens, it's not the end of the world: create a new account.
- zck 17y agoYeah, username + password + email would work. It's not as safe as username + password1 + password2, since you can mistype both, but it allows an escape plan. The way HN does it, with just username + password is dangerous, I think, because most people won't, immediately upon registration, go to their profile and put in an email; they'll just start using the site. And if someone mistypes their password once, and can't re-login to the site, they'll be very turned off.
- drusenko 17y agoAs long as the increase in sign-up rate is larger than the percentage of users who mistype their password, then it's a net win for the website.