How much is Facebook Connect limiting Quora's growth?
quora.com
quora.com
The goal of Facebook for login is to improve signup conversion rates for your sites and make it easier for users (so they don't need to re-enter all the same information and re-find their friends on every site they use). This thread is really interesting for me and the rest of the Platform team at Facebook because it illustrates how far we have to go. Please keep the feedback coming, however harsh :)
I get the brand perception and trust issues - it is something we care a lot about and are actively working on.
Beyond that issue, we have internally been talking a lot about ways of making the user experience smoother, more familiar, and less intimidating. If all of you running startups have practical suggestions about how the experience of a user using Facebook for login could be improved to help out your site, we would be really eager to hear it. It is a great time to get the feedback, as we are actively iterating on ideas internally.
And when I visited a site for the first time to see my Facebook contacts there, without ever having signed up for the site in the first place, I got angry. Really, really angry. And then I got even angrier when I went through the 30 step process of turning off this "feature".
I don't know how representative I am of the population at large, but this stuff drives me nuts. Please stop.
Two opposing viewpoints on my mind:
1.) Facebook is for all practical purposes, fairly ubiquitous. +1 for Facebook Connect on that front.
2.) As you suggest, Facebook is a toy and has no place providing this kind of service. -1 for Facebook Connect.
If I could be assured Facebook Connect was simply serving as an authentication service, and did not implicitly authorize sites that use it to access any data about me, or post to my Facebook page, I would probably use it for some sites.
Although I do appreciate you making yourself available to feedback in a direct ad-hoc way. Very unusual for a company of such size.
1) Fix graph.facebook.com to respect user permissions. graph.facebook.com/userid publicly leaks real names and UIDs even when users ask to be non-publicly searchable. This is creepy and makes users nervous that they don't have control over their privacy.
2) Give users back granular control to explicitly disallow sharing of any info they wish to keep private. This includes their friends graph, likes, wall access, etc. (empowering them to have the choice will reduce the sense of lack of control).
3) Let the application/site owners describe what they intend to use the information for. Ideally hold the app to the contract as well. example: "Need access to your wall in case you explicitly tell us to publish/share something on your behalf - we will never post to your wall without your approval".
Anecdotal story:
I showed someone Quora 2 nights ago as suggested they sign up. She said "Why do they need my Facebook? No way!". When asked "why?", she said, "I don't want that site spamming my wall - who are they?".
My takeaway: If Facebook wants to be the login for the web, it needs to give people comfort that they have control over how an app/site behaves on their behalf.
Thanks for chiming in here. At our startup we are trying hard to reassure users we're not going to misuse the Facebook access they're giving us. Even though we're asking for a fairly limited set of rights, the permissions screen that appears after the Facebook Graph login is quite intimidating. The design has a warning stripe across the type that is reminiscent of a danger sign, and combined with the copy, inspires a feeling of alarm. See http://developers.facebook.com/docs/authentication/ for a screen shot. It would be better if the screen were friendlier and less evocative of danger.
Another way to improve the user experience would be to consolidate the login form and permissions to a single screen. Twitter's oauth login screen does this well. Screen shot: http://followfridayhelper.com/images/help-login-via-oauth.pn...
Additionally, the oauth tokens should be long-lasting by default. We originally set up our site to not ask for an extended-life token, because we wanted to reassure users that we weren't going to be posting things on behalf when they weren't using the site. But this ruined the user experience. A short time after logging in to our site, a user would initiate an action, but because their token had expired, we had to pop open a new Facebook login window, interrupting what they were doing. Users were annoyed at having to constantly re-login to Facebook. So we now ask for the extended life permission. While this improves the user experience, it adds another intimidating message on the Facebook permissions screen, implying we're going to be posting on their behalf even when they don't initiate it.
Happy to chat more about what we're doing and give additional feedback.
Lee Semel
The users that aren't are pre-teens that don't care or older adults that don't know what spam is.
On one of our apps, we improved FB connnect usage by 50% by adding the disclaimer "This won't post anything to your wall or friends. We promise." under the connect button.
Developers need help reassuring user's that an app is not evil. The current FB dialogs are sterile and ambiguous and don't help.
I realize this might not be winnable because (1) many apps are trying to spam and (2) Ultimately, Facebook wishes users would share as much as possible.
I don't like when things get complicated too much and that simple approach seems ok, but on the other hand, it lacks detail that would make users feel safe about using fbc. If 'publish on your wall' had specified settings for the webservices, it'd be much more effective.
That doesn't scale so well.
Maybe the login screen is part of the problem: I might've posted anyway if it had four fields: "User name" "email" "password" and "retype password." As it is, signing up sounds too invasive or too tedious to bother for a short comment.
I don't mean created a unique account on the site then linked your FBC (and Twitter, etc) to it, I mean actually created the account by registering on the site through FBC.
Do you lose all your accounts on the other websites too, or do they somehow remain even though you didn't create a unique userid, pwd, email for the account on those sites?
As someone using FB Connect, we don't support it, and I'm guessing most small/medium sites (like mine) don't either. It's such an edge case that most people that fall in that bucket are SOL.
If you run a site that uses Facebook for login, when you log someone in via Facebook, you can ask for their email address via the "email" extended permission. Your site can then support a password reset page (like most sites already do) to enable those users to create a password via email if they decide to delete their Facebook account. Requesting email address is a good "escape valve" for users if you are concerned about this aspect of Facebook login.
Personally I love the fact that I can use FB, as I dont' really care that much about my facebook account.
Anyone got any theories on why that is?
Now I'm not saying these issues are present in Facebook Connect, but I don't have the time to find out and I don't want to gamble that everything will be dandy in the future, especially with a company so removed from ethics as Facebook.
When you name a new product using your old and renowned brand (like Facebook Connect using Facebook), both positive and negative karma is inherited from the old brand. This also may explain why some don't like FB Connect.
And, if you use another company's product (like with Quora and FB Connect), you risk inheriting the consequences of its negative karma as well.
I do have a twitter account, but honestly I don't want to use it to sign-up at other pages. If you don't want to handle user names and passwords, use openid.
I ask as I like OpenID enough that at least for my services alpha, I'm only implementing OpenID.
When a user goes onto Quora they are looking for information. Then, when they see the FB connect button, that goal of finding info suddenly becomes related to social relationships. Now the user has to switch mental contexts and think about the social impact of their decision. That invokes an emotional response when all the user wanted to do was quickly find an answer to a question (or at least explore a site that might have this answer).
I've done user tests with FB connect buttons. I've seen users actually pull their hand off the mouse and take pause when the button appears. It invokes a powerful emotional response in some users.
It's not a million miles away from asking one of us for our private keys.
For others, Facebook is a very strong online representation of their actual real-life identity. They joined when they entered college. It became THE platform for staying in touch with friends from home and new friends on campus. Photos on Facebook catalog their entire lives from that point onward. They have literally more on Facebook than they do off of it.
Asking these types users to Connect with Facebook is no different than asking them to login to sites with real information only. It's akin to requiring HN posters to use real names for usernames, real contact info, include real pictures in their accounts, etc. This is something the vast majority of HN would not accept.
Quora wants to be a QA service where every account is linked to something real. That's how they intend to deliver a quality product. That's what makes them different from other QA sites. This obviously slows their growth, but they need to do this to make their site worth anything. Eventually, they will try to convince more and more Facebook users that it's okay to reveal themselves on Quora. Until then, we will just make the Facebook-account-equivalent of spam-only e-mail accounts, and use those for sites like Quora.
It isn't he same without identity.