User account creation re-imagined [video]
stefankendall.com
stefankendall.com
I had a small chuckle--I hope that's not the future of signup pages.
Here's a description of the video, for those on their phones or flash-impaired devices:
When requiring an account, have only two fields, username and password. Auto-generate both randomly and show them both in plain text. If the user changes the password, save that -- it's their new password. They can enter it on another device. Likewise, if they change the username, save that change.
If they change both username and password to an existing and valid combo, consider that switching users, and I suppose you perform a logout and log in with the new credentials. (This is where it gets a little muddy, in my opinion.)
You're assigning a username and password to them. Are they going to take the action to change it to something they will remember? If not, how will they retrieve it when they forget? How is any of this an improvement?
If the physical security of the phone is your security, however, this seems like a reasonable level of trust.
There are many apps, like mine, that have non-sensitive data that just needs an account for persistence or extra-app activity.
You could adjust this to require the current password instead of showing it, but in my case that's an unnecessary level of effort. You could still get by with two input fields, I think.
The app is stored un-hashed and un-salted in the app, but if someone gets access to your phone, your powerlifting log is the least of your worries.