Confirming Passwords Is Annoying: Is There a Better Way?
konigi.com
konigi.com
Edited to add: Context for why that number is so low: The vast majority of my trial users are up-or-out within 3 days, and since I default to setting a 2 week "remember me" cookie, typically only my most interested users ever have to type their password ever again.
By the way, you would be astonished how many users I have think they cannot type their school email address from their home computer and vice versa.
I wonder if other people have a similar reaction.
Might be better to make users type in the password a second time rather than give them a queasy feeling in the pit of their stomach.
Don't ask for confirmation.
Solved.
(The ####### protects against someone peeking over their shoulder the exact instant they register, who wants to steal their password. It's not really very plausible and certainly not worth the hassle.)
Some friction is necessary -- if you make it too easy the user won't be sure of what they're doing.
Also, are the typos you've seen more often in the LHS or the RHS (of the @) in the email address? The RHS is relatively easy to spot check, by doing an MX and A DNS lookup to see if the domain exists -- you'll check actual delivery later. I've found this to be more robust than regular expressions that attempt to "validate" email addresses (see HN postings from earlier today) and assume a fixed size on the RHS, and are often overly aggressive in trying to detect "illegal" characters on the LHS, like +, which is not actually an illegal character.
http://foxxtrot.github.com/Chroma-Hash/
However, I don't see how it's more effective than a callout or alert noting "these don't match" ... just less annoying and way sexier.
http://www.coderjournal.com/2008/02/lotus-notes-aol-corporat...