Just put auth info in a cookie, and let the user associate it with an e-mail address later, once he actually knows he will keep using the service.
I believe "I can't be arsed to register" is one of the top reasons websites lose prospective users.
Just put auth info in a cookie, and let the user associate it with an e-mail address later, once he actually knows he will keep using the service.
I believe "I can't be arsed to register" is one of the top reasons websites lose prospective users.
If the email address entered on our checkout page is already in our database, we link that purchase to the relevant account. If the customer want to login, they can, if not, that's cool to. We get a lot of wrong matches which needs to be fixed, but that seems to be a price we can and will pay.
We have had customer adding orders to other people accounts, because their email address was entered wrong ( even though we require the customer to enter the email twice. ) and we have customers ending up with multiple account that we need to merge. Despite all the problems, customers love not having to log in before doing a purchase. It's hit and miss in a few cases, but we try to do what our customers expect, matching their purchase to their account, regardless of login credentials. That's what consumers want.
Now that I've seen this in practice, it would be my preferred way moving forward. It didn't/doesn't take that much effort to do things this way. The bigger issue is in the occasional phone order our demographic is mostly men 50+, so some genuinely don't have email.. we use an internal address in that case...
That has to cost a lot of money. With the dozens of ways you can authenticate with StackExchange, I don't know why I was surprised to learn I had previously created an account without actually creating an account, but it was so.
Also, anyone who reads Korean can tell me if this says "sorry we're closed"?
I've tried to participate in their "meta" site, but the pedantic and condescending tone there is even worse than it is on the main sites.
date of close : 2013-02-27
Call me paranoid, but I think "deleting" your account has the potential to actually do more harm than good, since in doing so you are voiding any agreements or terms that you had previously agreed to, including those that promise not to sell or otherwise abuse your info.
eg messages to myrealemail+mytag@gmail.com will always be received by myrealemail@gmail.com
I too have a domain with catch-all, and I do that rather than using the + notation, but it's something you can teach your friends who would never do that.
I'd never want to depend on that for anything, it's really just a novelty; a simple regex will nullify any effect you'd gain for using that.
Yeah, I'm counting on e-mailers to send mail to the address I give them. No, I don't expect folks to send me spam unsolicited, or sell my address when I give it to them. I don't consider my name or e-mail address to be secret, and I'm also counting on anyone who sells my contact info to be doing it in bulk, not paying enough attention to strip out +tags, and by passing the address to spammers unaltered (or losing control of their database), give themselves away when I start receiving spam at that address.
Honestly I don't use the feature very often and I had not considered it to be a security measure before. Maybe novelty is the right word.
If I give myaddress+dropbox@mydomain.com to Dropbox, and they mail me from different addresses, I would be able to catch them all and put the "Dropbox" tag on them all, rather than having to make a filter for *@dropbox.com or some other extraordinary measure for classifying their mail.
It's part of the RFC, and supported by every mailer that I know. What part of this technique seems like obfuscation?
So, if you only use +tag for your own personal organizational purposes, then have at it! But if your goal is to conceal your account ID with Google in the interest of personal security, then you really need a better angle.
On a related note, some spammers have really done a number on me. First they impersonated thousands of addresses at my domain in the form of xxxxxx@mydomain.com where x is a hex digit. This is despite me having DomainKeys and SPF enabled. So not only did I get a lot of bounced spam to my catch-all, the spam that went through ended up in places that other spammers picked it up as a valid address so now I am getting spam sent to those randomized addresses.
At first I figured I could put together a rule to block all hexadecimal address of six digits but it turns out that at least another round of spammers started using the full alphabet and variable lengths.
I've come to the conclusion that I'm going to need to include a cookie in the addresses I use - so instead of dropdox@mydomain.com and amazon@mydomain.com it will be something like DOQ.dropdox@mydomain.com and DOQ.amazon@mydomain.com - addresses without the cookie get binned. But that's not going to help with all the addresses I've used over the last 15 years, and haven't kept track of.
It's like making you buy a car without allowing you to take it for a test drive. At least the reasons for photocopying your license before taking a test drive are understandable.
A login is a continuation, or a state/session key. So is a link/URI. There's no need for a mandatory "account" just to be able to pick up where you left off, even if it's to continue checking your email. (Though one could opt-in to further "protect" pages with passwords, biometrics, non-invasive mucus swab samples, and so on...)