You make a proposition to an entity, they evaluate the risk-benefit and respond.
Unless of course, you think adults are actually childiren and should be protected from themselves by the technocrats.
You make a proposition to an entity, they evaluate the risk-benefit and respond.
Unless of course, you think adults are actually childiren and should be protected from themselves by the technocrats.
It has been established as minimal practice, that NO ONE should be asking you about your password. If this would become a normal, it would also make regular people more likely to give out their passwords.
And email is key to your online kingdom, so it's a big deal, if it gets compromised.
You're right that the wording is important, and we do a bad job explaining what passwords actually mean, and how to treat them. A simpler analogy: Don't give your house keys to strangers, McDonald's has no business asking you for your keys to confirm your order.
I don't think users need to understand why, they just need to understand what to do / not to do. I've taught my mother to never give anybody her passwords, not even me, and if anyone asks her for her password to call me. She's mildly annoyed when I'm helping her with something and I tell her to please input her password, but she's gotten used to it. Did it work? It did. The representatives for a car sharing company were poorly trained and asked her to write her email and her password into a form. She refused, walked out and called me because she was worried that they were trying to get into her bank account. Turns out they wanted her to choose a password for their service, and were just very bad at wording it (and had the terrible idea to have customers hand-write it into a form and let somebody transcribe it into the computer system) and the guys working in the office had only been handed a script, they didn't actually know what information they were supposed to get. I'm certain that they accidentally harvested a good number of valid email/password combinations since it's a leading company that is owned by a major car manufacturer and has a good reputation.
I mean a random but common example is stolen credit card details. Out of automatism most people will fill those in when they're ordering something, without wondering whether the site is secure. And usually they are secure enough at the time of writing, only a few years down the line someone dumps them onto a public S3 bucket by accident. Whoops. If the system was secure by default - that is, CC data never passing to the webshop - that would be a preventable occasion.
Email in this case is the same - don't give FB access to your emails in the first place and they'll never be able to "accidentally" read all your emails.