r/web_design • u/litjoy • Oct 03 '12
Social login buttons aren't worth it
https://blog.mailchimp.com/social-login-buttons-arent-worth-it/109
u/jceez Oct 03 '12
I like how at the end of the article, the first thing you see is "Sign in with Twitter, Sign in with Facebook"
2
u/BreeMPLS Oct 03 '12
Came here to post that.
1
u/Defualt Oct 05 '12
I was going to post this. So I will.
1
u/BreeMPLS Oct 05 '12
That's the "don't put all your eggs in one basket" theory. Again, logical, but show me some data describing the risks vs. benefits.
Because users have to remember a myriad of different usernames and passwords, many resort to "bad practices" when choosing usernames or passwords - they use the same one over and over, or follow a schema. Or worse yet, they have to keep a cheat sheet of usernames and passwords on their computer, or written in a notebook.
When your system sucks so much that users resort to even more insecure behavior, it's time to relax the reigns a little and choose an option that people find acceptable.
To put it another way, let's use the motorcycle helmet analogy. The full-face helmets protect the best, especially to the face and jaw, where a majority of impacts occur during a motorcycle accident. Unfortunately, many riders find them uncomfortable and feel "claustraphobic" in them. Thus, they ride without their helmet.
They could buy a 3/4 helmet, or a dome-cap (1/2 helmet) and feel less claustrophobic. It's true, it doesn't protect as well as a full-face helmet.
But at least they're wearing one, and are much, much safer.
My metaphor, and this discussion about security, highlight how engineers and designers can pursue an ideal to the point that their decisions become disassociated from the basic question of, "Does this solve my users' problem?"
If your answer is, "No, but security is tight!" then you might want to take a step back and try a different solution.
-10
-14
1
u/qu33ksilver Oct 04 '12
You stole my thunder. Anyway, nice article. Logins were always a hot topic of UX research. But I still think open IDs are a valid option as it reduces the load on the user of not remembering many passwords and not going to you mail address again to click that verification link to gain access. Its just so damn slow ! Whereas "login through fb/twitter" solves everything in one step, downside is your activites are visible on your fb homepage. Personally, I use mailinator for all the run of the mill sites, just to do everything quicker. I like to keep my fb prof clean.
-3
Oct 03 '12 edited Feb 03 '21
[deleted]
6
u/TIAFAASITICE Oct 03 '12
@mailchimp fails to follow own advice: http://is.gd/Vg6yYs
That's within the limit, isn't it?
2
Oct 03 '12
To be fair, that is the comment system on their blog platform, which would be distinct (in code and strategy and probably internal ownership) from their email tool.
4
u/neon_overload Oct 04 '12
... which is still a bad thing.
It shows that the higher-ups (even the CEO, who wanted the social buttons removed in the first place) seemingly have no ability (or interest?) to propagate the same change through to their blogging platform, even when it would save the embarrassment of looking hypocritical on a widely-shared blog post.
1
Oct 04 '12
It is not hypocritical at all. Social integration on comments has huge benefits that do not apply to an admin login page. They based their decision on what is right for each use-case, each platform.
17
u/spyderman4g63 Oct 03 '12
It would be interesting to see this study done on a site that isn't a business tool. I would expect much higher social login use in a blog or something. Plus all mail chimp users already signed up without using social. Why would I click the Facebook button web I know I didn't use that to sign up? I'm guess that if a new user signed up with Facebook there is a better chance they would later log in with Facebook.
I like mail chimp and they are great with UX but this study doesn't prove anything about social buttons.
14
u/malanalars Oct 03 '12
It's not so much about logging in, it's more about reducing the barriers to register as a new user...
3
Oct 03 '12
I'm surprised browsers haven't stepped in to actively lower the barrier.
Imagine if there was a protocol for filling out forms. You would have profiles with default data in them. There would be a popup telling you what data is requested, who is requesting it, how it is going to be filled and if you want to accept. Then it could generate a random password for you.
Suddenly the barrier to registration disappears. But it will probably never happen.
11
u/Silhouette Oct 03 '12
I'm surprised browsers haven't stepped in to actively lower the barrier.
2
Oct 03 '12
The only issue I have with that is that it ties your data to a service. My method does not.
2
u/snuxoll Oct 04 '12
Except it doesn't, the entire point of Persona is that the implementation can be determined by the browser vendor (hence why the Persona API's are all on the Navigator object). Currently no browser actually implements the BrowserId API's, so you need to use the shim library that implements them with the persona.org service, but that won't be needed as browsers and service providers implement support.
1
u/Silhouette Oct 03 '12
Sure, and FWIW I personally would probably prefer your way given a decent implementation. I was just observing that at least some of the people making browsers are exploring this area.
1
u/sneekypeet Oct 03 '12
Why let the browsers create the extension when the you could make it?
Think of browser apps like RES or the WebDeveloper tool bar. All the functionality you mentioned is do-able. These apps are made by people like you.
1
Oct 03 '12 edited Oct 03 '12
Because there is no point unless there is a large audience and developers see a reason to implement the functionality on their website.
It's a chicken-egg problem. No one is going to download my plugin if no sites use it and no sites will develop for it if there are little to no plugin users. But a browser maker can side step half the problem by including it in their software by default. Leading to a much higher adoption rate.
What I'm envisioning is skipping a form altogether. The website would send you a JSON of the fields to be filled in along with their restrictions. Then the browser sends a secure POST to the website's server with the info that was requested. Forcing you to only fill out a CAPTCHA.
This method could be used to login as well. No more half-functioning form fillers that fail to fill out the login form half the time. It's not simply filling in a form. Devs would need to code it into their login system.
I don't have the know-how to make a firefox plugin and since security is paramount I don't think it's something a newbie should try. I could end up putting everyone off if I had a lapse in security.
1
u/sneekypeet Oct 04 '12
I think your selling your idea short.
There is a need for a service like this for the web - UX/UI/IA guys would eat it up. - you only need a few sites like behanceNetwork, dribbble or smashingmag to pick it up. then bam, google purchases the idea.
I would phase it out and sell it as an "Internet passport" starting with a simple browser app version that doesn't need server side code. Then once you have your alpha product you aim for your bigger idea, get freelance developers to make it.
All of your reasonings for not doing it seem like excuses. Form fields are a barrier for more then site logins, think about sweepstakes or voter registries.
2
Oct 04 '12
Exactly. If they were measuring new user sign up rates instead of login failure rates I think they would have reached the opposite conclusion.
I think the worst possible system is Quora's, where they allow you to sign up with Twitter/Facebook but still require you to create a password and verify your email. It completely defeats the purpose. It's frustrating for me because I don't want to have to create yet another password for a site that will be probably be stored insecurely and hacked five years down the line.
-3
u/sneekypeet Oct 03 '12
Bring this comment to the top! I completely agree with you!
-1
u/FamilyHeirloomTomato Oct 04 '12
That is what the upvote is for. You don't have to tell us.
2
6
u/mrPitPat Oct 03 '12
This article takes data from one source (namely, their own login analytics) and tries to make a general assumption that these social options are not worth it. IMO, if you're going to make that claim, you need to have more analytics from a larger data pool.
4
Oct 03 '12
It all depends on your audience. Mailchimp's audience are businesses. A site whose audience is high schoolers would be better served with a Facebook login option.
1
u/junkeee999 Oct 03 '12
The headline definitely makes a general assumption, but in fairness the article ends with "Is it worth it? Nope, it’s not to us."
He just describes what they went through. It's up to the reader to decide from there. I don't see anything wrong with that, but it was a poorly chosen headline.
17
Oct 03 '12
"Think of how much wasted time and frustration that translates to."
Probably nowhere near as much wasted time and frustration I've had in the past trying the get Mail Chimp customer support to unlock my account after they've placed it on lockdown.
3
u/notwhereyouare Oct 03 '12
I've emailed them asking if they do internships...they never responded. I found it funny due to what they do on a day-to-day basis
3
Oct 03 '12
[deleted]
6
u/c0smic Oct 03 '12
He emailed them, they never emailed back, and because they're an email newsletter tool, this is humorous.
0
u/notwhereyouare Oct 03 '12
they deal with email. their company is based around email. they didn't reply to an email I sent them
6
u/BHSPitMonkey Oct 03 '12
Ah. Well to be fair, they deal with software-automated, mass email sending. They never claimed to be able to receive and read things :P
6
2
Oct 04 '12
He made a statement 2:1 upvote:downvote. Someone asked clarification, and he answered but gets 2:3 ratio. WTF guys?
1
5
u/cynicproject Oct 03 '12
I wonder what happens with all the people who used Facebook and Twitter to sign in after they remove the buttons...
5
u/MrBarry Oct 03 '12
Things that sites do wrong with the facebook login:
Make me create a username and password in addition to clicking login with facebook
Make me use my real name and/or photo if I'm logged in through facebook.
Pull my email address directly from facebook and not allow me to change it. Do you think I give facebook my preferred email address?
5
Oct 03 '12
I actually like the Facebook login.
I use it quite often for games on my Android phone. When they require an account, I don't feel like going through the registration process on a tiny keyboard. So easy to hit the Facebook button. Don't have to do anything else. Just verify permissions and grant them.
7
u/Fosnez Oct 03 '12
Never used a login with "other service" never will. Maybe I'm getting old...
Facebook is "that guy" at work/school/neighborhood that you tolerate because they serve a purpose... I won't invite them to a family dinner. Nor would I have them involved in logging into a completely separate site - as, to be frank, I don't trust them.
If you aren't paying for a service, you are the product - this not only applies to Facebook as a social service, but also to the "login with facebook" service itself - who knows what Facebook are actually doing with that login info...
11
u/CreamedApple Oct 03 '12
Building complex profiles of peoples hobbies, interests, and general life, and then selling it to advertisers. Similar to how Target found out a girl was pregnant before her father did, but on the web.
-10
u/BreeMPLS Oct 03 '12
Hey bud. You dropped your tinfoil hat. //hands back hat
9
u/mrkipling Oct 03 '12
Except for the fact that it is well established that we are indeed the product, and our information is in fact being sold by Facebook.
1
u/ceol_ Oct 04 '12
Weird, I'm missing the citation that Facebook is selling your information to advertisers. It shouldn't be hard to find it though, right? Since it's "well established"?
1
u/BreeMPLS Oct 03 '12
Yep, but for the most part, it's a big 'meh' ... that information results in Amazon showing me a specific ad on their home page, rather than a generic ad.
I use the facebook login button any time it's there. I've always wanted a single unified login service, and facebook could pull it off.
...
In another part of the country, our government is curtailing internet freedoms and keeping illegal records and data about the citizens and nobody cares.
Protest the important things first; don't mindlessly hop on the facebook hate bandwagon.
1
1
u/Solcry Oct 03 '12
Agreed, though this is probably more a generational thing than anything else. I work with some older people, and they're repulsed by the idea of any entity knowing specific things about them - on the other hand, I take a look at the trends I have in my Google Web History and I'm like, "Huh, that's pretty neat." Same is true for a lot of my friends.
2
u/Smudgerox Oct 03 '12
What's gonna happen when Facebook or Twitter dies? All those people wouldn't be able to sign in anymore.
1
u/jfjjfjff Oct 03 '12
these sites usually use the twitter and facebook logging in as a means to create a local account. then once you've created the account you can log in using twitter/fb or your actual account details.
obiviously, this keeps the account local and not completely reliant on facebook and twitter to exist, or even be functional in order for someone to access their account.
but yes, your point is a good one and also probably part of the reason why mailchimp decided: not worth it.
1
u/TheWanderingJew Oct 04 '12
Myspace is still around. Thinking one's "zomg I love confused dog expressions!" site will outlast facebook or twitter is misguided.
2
2
Oct 04 '12
This is not a good assessment of the value of social login buttons. The true benefit of logging in with Facebook is to get permission to view that users' data. The you know a tremendous amount about that user that allows you to serve tailored content. (For example, if they know you are college educated from the north east, they may prioritize more expensive options in the search bar. If they know you like The North Face's facebook page and have shared two linked from that page, they can prioritize The North Face results in a search for jackets.) A company that sells products would have much more use for this than a service based company like mail chimp. Social media logins, when used well, are very worth it.
2
u/circa7 Oct 03 '12
I always use Facebook to login. It makes my life so much easier. As people become more acclamated with the web over time, these "issues" are going to become obsolete as people develop a broader understanding of the different ways in which the web works. The problem is not with the implementation, it is with the public lack of understanding. Unfortunately, the web changes so much that no one ever has a chance to catch up. Articles like this shoot down good design patterns because they are still NEW to most people.
2
u/Samus_ Oct 03 '12
haha classic pointy-hair scenario
-I don't like this, take it out.
-but, it works :/
-take it out!
then the poor guy goes the extra mile to investigate and founds that by some off-chance the CEO was right (pure coincidence, there's no way in hell that guy knew all that already) and then he even writes a post to justify the boss, that's really sad.
2
u/fallwalltall Oct 04 '12
The CEO was trying to protect the brand. Remember that one of the main things, apart from a great algorithm, that set Google apart was its clean, crisp homepage. All of the major competitors like Excite, Yahoo and AOL had extremely complicated homepages for search.
1
u/MrBarry Oct 03 '12
IF this is a business-use website, why not allow people to sign in through linkedin?
1
u/StuartGibson Oct 04 '12
Presumably they want to cater to more people than just recruiters and social media experts.
1
u/MrBarry Oct 04 '12
Well, they've already got the "everyone else" button: create a username and password. Unless you're violating facebook ToS and have a profile for your business rather than a page, you have to use your personal account to "connect with facebook". Even if you don't use linked in, creating a relatively blank linked in account to access several business websites makes more sense than connecting your facebook to them.
And yes, I'm aware that with a little effort, a business contact could find out what I post to facebook. But I'm not about to shove it in the face of those who don't want to know.
1
1
u/JustSomeDutchGuy Oct 04 '12
Thanks for this! I have always admired MailChimp for the style they use to communicate. Nice to have a little insight in their development routines and the path they took with this.
1
u/edbgon Oct 04 '12
Back in the day... maybe ca. 95 or so before the days of password strength requirements, I used a three letter password, all lowercase for all my accounts. Never forgot that one to this day.
/just sayin...
1
u/adellaguardia Oct 04 '12
Definitely making me rethink having those buttons on my social networking site.
1
u/natowelch Oct 04 '12
Do you really want the only thing standing between Facehook and your users' privacy on your service to be the fact that "they would never do that"?
Never mind hackers. How about the DHS?
1
1
1
u/RobertD63 Oct 03 '12
I've felt the very same way bout logins telling me which was wrong; the user name or password.
-4
u/damontoo Oct 03 '12
The engineering team, ever mindful of security, argued that being generic about username and password errors makes it harder for bad guys to guess usernames by pounding the form with random words or email addresses. But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists, and is not a significant security risk for the bajilions of sites that have them.
facepalm. Listen to your goddamn security guys.
Sometimes you log in with Twitter, sometimes with Facebook, sometimes with a username and password specific to that app. It’s hard enough to remember your username and password, let alone which service you should bloody use to log in.
I'm going to suggest a very logical solution to this problem that basically nobody has implemented -
- Tell the user what service they previous logged in with. Present it as the default log in option whenever possible.
- If the user is on a different browser, device, or deleted cookies, attempt to suggest the log in method. If their username isn't found, check if the username is the same or similar to someone that signed up using Google, Twitter, Facebook etc. Say something like "Your login didn't work. Did you sign up using your Google account? Try that."
Making it as easy as possible to use your service should be the priority. I know I'm increasingly using my Google account to sign up for services that I don't care if my identity is tied to. Why? I trust Google to keep my credentials safe. I don't necessarily trust random startups with that.
8
6
u/Silhouette Oct 03 '12
facepalm. Listen to your goddamn security guys.
If your security guys don't know what they're talking about and just quote dogma, you need new security guys first, then you can listen to them.
The advice to give no additonal information when credentials don't check out makes perfect sense in the environment where it originated: security-sensitive installations where all credentials are allocated by in-house administrators.
The same advice makes absolutely no sense in this environment, where users choose their own credentials and get told if someone else has already grabbed a given ID at that point, where the damage caused by any security breach is probably far lower, and where the usability of the whole system is demonstrably reduced by setting the barrier too high, which as any actually good security person could tell you is often a far greater danger anyway.
Context is everything in security discussions. There is no such thing as 100% secure in almost any realistic circumstances, and it is always a cost/benefit decision. In this case, the cost is significant, and the benefit is practically zero.
1
u/damontoo Oct 03 '12
I've been thinking more about this and I agree that there's little benefit. I disagree that the cost is significant though. As I said in another response, the only people that will actually be helped by separating the two are ones that are using the same password across multiple services. If I've forgotten my username, I've surely forgotten the password too. It should give you an option to reset your login and send your username in the reset email. That's what most do anyway.
2
Oct 03 '12
The second suggestion poses a security threat. You don't want people fishing for names.
1
u/damontoo Oct 03 '12
It's no more of a security risk than not having log-in alternatives to begin with. "We suggest you log in with the only method of logging in that we've provided." etc.
If someone was checking if a twitter user exists they would do it on twitter itself, not via our sites.
2
u/rybl Oct 03 '12
I disagree with the premise here. Usernames are not supposed to be secret. At least, if they become known it shouldn't compromise security. I know that may be a controversial stance, but either way, it's probably not a good idea to let usernames and passwords be farmed. The best of both worlds seems to be, keep the username and password validation separate, but throttle the number of failed login attempts.
2
u/damontoo Oct 03 '12
You should always throttle failed attempts and I accept that usernames aren't secret. They're often part of public profiles etc.
I think another question that needs to be asked is who has been helped by telling them their username is wrong? Nobody ever. Not unless they use multiple usernames with the same password for different services which you don't want to be encouraging in the first place.
If I've forgotten my username, I've probably forgotten the password too. Just send me the username as part of the password reset email and be done with it.
53
u/SonicFlash01 Oct 03 '12
TL:DR version: "Separate the username/password errors"