Rethinking email confirmation
blinkingcaret.com
blinkingcaret.com
The problem this idea proposes to solve is an edge case, and there are better solutions. For example after registering an account a user can be immediately logged in with a banner displayed at the top until their account has been validated via email, with the option to change their email address if they entered it incorrectly on registration. There's no additional friction, and the minority of users who do make a mistake with their email are covered.
The later might be required for user who porvided a fake address when just testing the service or want to make sure they wont be spammed by the site owner. A reminder with a "don't show me again" check box would address these cases and everybody would be happy.
That still wouldn't solve the problem the author proposes to solve. If you accidentally entered someone else email, that someone might click on the link and you'll never see the banner.
- website that use a username as the primary identifier will make it clear that the email address has not yet been verified. They will nag the user to confirm the email address, or at least prominently indicate that the email is not yet verified. It will be difficult for the user to not notice an unverified email address.
- most websites use the email address as the identifier. If the user used the wrong email address to create the account, they will not be able to subsequently log in.
- some website require you to verify the email address before you create the account, even though they ask for all the information on a single signup form.
I'll address two common situations:
If the site uses the email address as the primary identifier and there is no separate username, it is OK if someone confirms a mistyped email address. In such situations, an account should not be created until the email address is confirmed. Let's say matt@gmail.com is sitting in front of the computer and creates an account for mattt@gmail.com. mattt@gmail.com confirms the email address and is now the owner & controller of that user account. matt@gmail.com does not have access to that account, nor did he get a confirmation email. Ideally, he will realize something is wrong and will try creating the account again.
If the site uses a username, and the email is just a contact method, the process of confirming the email address should ask the user to re-enter the password.
There are always users who exceed your expectations.
A website needs to make a determination how important it is for them to have a verified email address. If the email address is used only for notification or marketing purposes, then there it should not put too much pressure on the user to validate the email address.
If, on the other hand, the email address is required for something important, such as password recovery, it should make a concerted effort to get a user to provide one.
You must verify the address -confirm the opt-in- before you start to send stuff to it. If you don't you're spamming.
You can do even better! You can just let a user start using your application without even providing an email address. Keep track of the user via a cookie at first. Present them with opportunities to provide an email address (and other info) if they wish to return in the future. Once they do, associate the account with the email address. After that, continue asking for more information on a need-to-know basis.
This is not better from a business 101 perspective. You've just traded the ability to communicate with some of your users without requiring their e-mail.
You know what I do when I come across a service that forces me to sign up before I can see if it's any good? I hit the back button.
The taster can be in the form of a descriptive home page, landing page, or article. It could also be in the form of a completely friction-less trial that does not ask for any user info. The latter are rare.
It's up to the user to decide if they should invest their time in trying out the product based on whatever taster the website offers.
It's quite silly because you'd think for a big platform like this, they would have thought about such a case, but they obviously didn't.
when you have just a "enter your email" field and nothing more, you already gave someone an email and got nothing in exchange yet, then at the next step, you click the link, and they ask you about 100 mandatory things to finish registration, asking about everything including your shoe size. Then you might not want to register to this kind of site out of principle, and also can not unregister anymore usually.
(To be fair, sometimes pages have multi-step registration and do the same, asking few innocuous things first, and more privacy-invading things later. I hate that.)
Secondly, if the user decides to not register after all, just give them an unlink mail button at the registration form. This way they can stop the registration and use the mail in the future if they change their mind.
This is one of those things that never get implemented by 99% of teams due to "why would someone need it" / "additional complexity not worth it" / "we'll do it later"
Unless the service sends out regular email reminders or something to anyone who has entered their email address, then I can understand the need for an unsubscribe link.
If a person enters the wrong email address at signup, no damage is done. He can just sign up again with the correct email address. The account with the incorrect email address will either remain uncomfirmed and deleted at some point, or belong to someone else. Doesn't matter, it's an empty account. You should prune unconfirmed, empty accounts periodically anyway.
If you really want users to have a separate username, nickname, handle, or whatever, that's fine. But that should be separate from the login, especially if it's going to be visible to other users.
OP's suggestion is just an extreme version of the same principle, since it won't even allow people to set a password until their email is confirmed.
It's fine to use an email address as the thing you enter into a login box. But internally you really want the user records to be keyed by something else, and just associate an arbitrary number of email addresses to that.
No, it's not even unique.
A related problem there isn't a one-to-one mapping between email address and person, one person can have several email addresses. If you want to let a person have many accounts and keep track of which accounts a person has (like ebay does) then you're going to need a person primary key too and can't make an assumption about email = person.
Its my opinion natural primary keys should be used very, very sparingly if at all. There's basically no "person" natural key. Even social security numbers are subject to various problems when used as primary keys. SSNs can (rarely) change. Laws and policies around SSN use and storeage also change.
- Tell people how to get to your profile in person (and remember how to get to someone’s profile without needing a link)
- Mention people by name
- Keep your e-mail address private
You might also want to associate the same e-mail address with multiple profiles.
This seems like an overgeneralization.
No you can't.
Lets say I download a database leak of email/password combos from a popular service. I can't go onto bankofamerica.com or whatever and start iterating through that leak for password reuse, I don't know the username for a given email account.
Usually password reset goes something like this:
If I click on "forgot password" it asks for username and email address to email me a password reset link. If I click on "forgot username" it asks for email address and other information a financial institution would know, like SSN, account number, credit card number, CVV code. You can't do anything with just email and password. You can't even do anything with access to that email address and password. I just reset my password with Wells Fargo last night and it even gave me security challenge questions from my credit report to change my password (questions like what car did you own, what's the payment amount for your mortgage, what address are you associated with, where does $(relative) live?).
As someone who got their last name at gmail in 2004, I've gotten a lot of emails for other people over the years, and A LOT of services don't require verifying your email for signing up.
I've gotten a Twitter, Instagram and Fiverr account without signing up (on top of probably hundreds of smaller services, golf clubs, local news, charities, etc), and definitely without ever clicking a link in an activation email I didn't sign up for. The latter of which I can't delete, nor change my username, effectively burning that email address for that service.
I'm sure those named services have since fixed that, but that it was ever an issue in the last 15 years baffles me.
Nowadays I use my own domains for email, so it matters less, but I wish even confirming emails at all for services was more enforced.
I'm sure this is all rooted in services wanting to grow their "user"base rather than have real users.
> the person that actually owned the jon.smith@email.com was a kid that was curious and clicked the email from TheService asking him to verify his email address.
Unfortunately, most comments to this article miss this point and argue about unconfirmed addresses instead.
Cached version: http://webcache.googleusercontent.com/search?q=cache:Er9PEaJ...
I wonder if anyone has implemented a non-optional version of this on any decent scale? i.e. is anyone using passwordless 'email link'-only login?
Or people who use long complicated passwords and don't want to type them on mobile (yes, yes, I usually copy/paste my password manager generated passwords, but magic link is still easier)
Yes, Craigslist.
There's username and passwords now but I believe that's relatively new. The typical workflow doesn't include registering and there wasn't originally an idea of an account (if I recall correctly).
edit: found it, it was overcast
if user doesnt verify email within a few days, that email "expires" and is removed from the account. Add a message to nag the user to add a proper email to their account.
this removes the edge case mentioned in the article and reduces sign up friction.
There's still many other possible scenarios but I think it generally does what the author wants in a not so annoying way.
From the article:
> What happened?
> Well, turns out that the person that actually owned the jon.smith@email.com was a kid that was curious and clicked the email from TheService asking him to verify his email address.
> He himself forgot about this until a couple of years later when he heard about TheWebsite from some friends, and decided to try it. He tried to create an account and got an “account already exists” error. He used the password reset functionality and that’s that. He now owns the original John Smith’s account.
Doesn't this solve the issue presented?