Why Facebook Connect Shouldn't Be Your Only Sign-in Option
bijansabet.com
bijansabet.com
With our latest updates in November, we allowed a 'generic view' --- a user can search what's happening in a city without logging in. We've put in educational messaging and explain why the Facebook connect is important to being able to personalize results. Based on what you like, what your friends like, where you've been, where they've been etc. The data is core to the experience, but some people still don't want to give access to Facebook. We did, however, see our bounce rate cut in half when we provided a generic view. Customers were spending more time on the site (upward of 5 minutes) and even returning to use the site without the account.
I think the key is giving clarity, but this is a topic we've gone back and forth on as we don't think we can deliver on our promise of 'personalized advice in any city' without having the Facebook basis. We'll be changing this over time but for now, it's generic or Facebook account.
Conversely, at the last place I worked, offering both options was the #1 cause of customer support requests. People sign up through both paths, then ask why everything is fucked. We ended up dedicating a lot of resources to a crystal-clear UX to avoid this problem.
Finally, when someone signs up through Facebook, you're often able to offer them a better product, because people empirically respond really well to their friends' faces, and everything else that comes with fb. Facebook permissions also promote your business goals like woah.
I'm open to more information, but this article doesn't have any. "Giving users only one way to sign in and FB as the only option is going to turn off a large number of users"? I've reread that sentence several times and I can confidently state there are no numbers in it.
[1]: https://browserid.org/about
I haven't evaluated it completely, but it seems like the best option right now.
Have you seen janrain? http://www.janrain.com/
How do you guys solve that problem? I think, this might be even the bigger problem than having 20% or 30% "drop out" on sign up process.
how would you suggest your customer which login to use the first time she tries to sign in on another device?
Further, some customer bases are perfectly happy using FB connect only. If you object to logging in with Facebook, maybe you're just realizing that you're not the target market for the product. No harm, no foul. If you end up offering lots of log-in options and your customer base only really wants FB, you waste development time and actually run the risk of confusing your customers.
Mathematica offers a non-Facebook sign in. So does Safeway.
1) Is really hard to get right from the security standpoint ( https://www.owasp.org/index.php/Authentication_Cheat_Sheet )
2) Actually requires quite significant work. It might be easy to add short sign-up and login forms to a site, but I doubt that implementing any external authentication mechanism would be really that much more work. However, with password auth. the work doesn't end here. We typically need password reset/recovery and password change. The latter usually entails some kind of profile/settings page, while the former might require at least a dedicated login page.
In general, external authentication providers are good, as long as we don't limit ourselves to a single one. Adding Twitter / Google / BrowserID / Open ID / etc. is not that much more work, as the whole flow can be somewhat generalized. Having multiple authentication options also makes us prepared (from implementation PoV) for eventual support of user&pass auth., should we need it in the future.
I think there's a danger in giving users too many options, because it's easy for a user to forget which one they used, but there's also a danger in only offering a 3rd party sign-in, as some users just won't be up for it. For me, FB + email is the happy medium.
But yes, there's a lot of little things to implement when you have your own user auth system. I'm using Flask, a microframework that doesn't have a user system built in, so I've had to code basic things like reset-password and change-password from scratch. Worth it, though.
Homepage: interesting concept. I like the clean design and the gigantic "start" button + "take a tour" option.
Next page: A little annoyed that I have to basically squint to see the alternative to Facebook signin. No, I don't want to join your social network.
Signup page: I'll admit, the number of fields to fill out gave me pause. I almost exited out. But I'll grudgingly give it a shot. (Specifically: you don't need my last name, it makes me feel like you want to sell my info. You don't need my location. You don't need my birthday, and the years starting with "1900, 1901, ..." makes me feel like you want to sell my info. You don't need my photo -- if I like your site, maybe I'll give one. But we just met. The lack of a "confirm password" box makes me slow down and carefully type my password, and makes me feel like closing the website. This is all happening in the span of about 3 seconds.)
Next page: Perfect; absolutely perfect. The defaults are spot-on, and the optional infotext (question mark buttons) is nice.
Next page: Hmm.... Reminders? I don't really want annoying reminders yet; I just want to see what your site is like. The lack of a 'skip this' button would make me close the site.
Next page: You want me to spam my friends. No... thanks.
Next page: We're at step 5. It's now gone from cute to annoying. No, I don't want to share my food logs with the world.
Done with the signup. Then you show me http://screencast.com/t/NXMzgOjjR50q ... it's not really clear what I should be doing next, or how it will benefit me. I think there's probably just too much raw text. Separately, each element is good -- "Prep your pantry", for example. And I like handy guides. But the sheer number of things I could be doing next makes me close the page and hope you don't spam me too much.
Apologies if this wasn't useful. I assume website owners like honest feedback, and understand that my viewpoint != the average person's. I have no idea whether your site is good or bad; I was just broadcasting my raw thoughtstream as I went. For example it might be a bad idea to cut the "invite friends" step, even if I am personally annoyed with it -- maybe it's valuable in practice. I don't know.
Best of luck to you!
Of course, I would love to see some actual numbers on whether it was worth it for Spotify (I suspect it was), but my point is that's a bit of a special case.
With Google Login i never get those.
That's a pretty low option of foreigners; in practice I think they take which bits of American culture they like, adapt it if necessary and ignore the rest. I would guess most of FB's non-USA users use it for the same reason USA-users do; its good at what it does, and all their friends use it.
Any Facebook authorization dialog that asks for all of those permissions in the Topsy example is doing it wrong. It is not like you need to ask for all of those permissions up front. Offline access and publish stream is a very dangerous combination and should only be requested when a user is turning on a feature within the app that requires them. Let the user in with the bare minimum of permissions (user_about_me), build their trust, and then only ask for more permissions as and when they are needed.
Plus when you cancel out of the Facebook authorization dialog on Topsy, you get a 500 error response. Topsy fail on multiple levels.
Personally, I like the Joel test for abstraction/outsourcing. Identify your core competency, then go one layer below it in the stack. That's how deep you should go in-house. I think for many sites/apps, user accounts fall within this realm. That doesn't mean you can't interoperate, but don't be solely dependent on FB.
What happened to the days when you just had to implement a simple website for 1 browser, without having to worry about multiple browsers, supporting iPhone, iPad, Android, and enabling Facebook/Twitter/OpenID logins, and finding friends through facebook/twitter/gmail?
New technologies for consumers are great, but for producers who rather create the next Facebook instead of using it, they can be a hassle to support.
Actually I know that "one point". It was when Mozilla completely destroyed their browser platform with the horribly broken Netscape 4. Everybody stopped using it immediately.
Back then it was like "does it work on ie" and maybe "should we build an AOL presence?".
AOL then = Facebook today.
You're welcome, young people.
How many of those companies are still in business, relative to their competitors who chose instead to bet on cross-platform standards in the long term?
If you're developing now, you know how much time you save just not worrying about layout in dying browsers.
Do you really yearn for those days? Think about what you can build now vs. what you could build then.
Last time I checked, if there was no internet in the year 2012 you could invent that too. I don't really see it existing as a hindrance to your potential creativity though.
http://www.omniauth.org (Ruby/Rack)
https://github.com/bnoguchi/everyauth (node.js)
https://github.com/ciaranj/connect-auth (node.js)
On the node.js side - just look at everyauth and connect-auth examples - they didn't even work on my computer! there's another lesser known library called passport.js that does the job very well: http://passportjs.org/
Authorization and account management is really easy to screw up. If you leave it to Facebook, you'll save a lot of time. The only question is whether or not it's worth it.
Is there a company that just sells a no-frills user enrollment and login service and also provides strict isolation between sites? (I.e., they resist the temptation to leverage their aggregate user base.)
There are six 'simple' providers listed. Spot checking: One of them has broken SSL (https://www.myopenid.com/signup sources https://api-secure.recaptcha.net which has an invalid certificate). One of them looks completely broken for new accounts: http://claimid.com/register "This account is hidden or does not exist."
And of course there's this: http://www.untrusted.ca/cache/openid.html which describes various security and privacy problems with OpenID.
Or, if I'm not, I've polluted your user database with one of my throw-away Facebook accounts just so I could see what was behind that search result that caught my eye.
userid, password. What part of that do you not understand?
However, there is a security concern. Abusing other peoples Facebook/Twitter accounts is quite common (frape for want of a better word). People do not sign out of Facebook (I don't), so blindly allowing access to sensitive data like this could be an issue. How about quickly asking for their password? Very few will be offended, and those that are should be cut down to size with an explaination of how security concious you are.
Now we are going back to FB + Twitter + native but making our lazy login even lazier and I believe that has the most bank for the buck.
Sometimes though I might want to use an app for work purposes that I don't want in any way linked to my normal persona.
Or I may want to use something which I know will in no way interest any of my friends and I don't want it posting anything for me.
Really, if I can't take the time to create a username/password for a site then I probably wasn't that interested in using it.
I'll put you on my list of "people I will never do business with on principle", but if I'm your target market then you've got much bigger problems than that.
“Google and Facebook would have you believe that you’re a mirror, but in fact, we’re more like diamonds.”
Give them the choice if they want to create a new ID for your service or not.
When it get's down, you are screwed.
I haven't got an account and I certainly have no intention of getting one ever.
Why would anyone design a site to use an FB only sign-in? Jeez ...
A) Failwhale, anyone?
B) Twitter doesn't provide serious options for protecting their users' login credentials. It's the same username/password combo which is easily phished & replayable.
Sadly, I've pretty much given up on the hope that we'll have a healthy ecosystem of OpenID providers, but at least Google's login system does offer some two-factor options.
I'd rather just go the hacker news model. Choose a strong password and if you forget it, we send a new one to your email address.
Works fine, offloads a lot of security issues to email providers (who tend to be good at it), easy to code.
I use Hacker News with OpenID ;)
I've just signed up for a free trial to Netflix and they seem to be determined to force you to link its account to your Facebook one (you can avoid it by signing out of FB before going on the Netflix site, but even if you do that it then attempts to link the two together in the background next time you go on the Netflix page). But I don't want my FB page filling up with a list of things that I've watched. Partly because I may sometimes want to watch something I don't want to broadcast to the entire world, but mostly because I doubt that most of my friends have the slightest interest in keeping track of my everyday viewing habits.