9 ms·
Social Login Buttons Aren’t Worth It
- codinghorror 14y agoThe way I read this, it's about the CEO overriding the decision based on aesthetic reasons. Personally I'd much rather log in with Google in this case, which means there would need to be three buttons: Twitter, Facebook, and Google. I'm sympathetic to the "nascar-ization" argument, but I also believe your customers are smart enough to process at least as many options as there are in their wallet for providing identity. Perhaps the best solution is even more minimal: no login options at all! Let the browser auto-generate credentials and a unique password on your behalf, then automatically use that to log you in every time it sees that website. http://www.codinghorror.com/blog/2011/09/cutting-the-gordian-knot-of-web-identity.html http://www.codinghorror.com/blog/2011/09/cutting-the-gordian...
- jbigelow76 14y agoI think some distinction should be made in the different types of websites out there. Social logins may be fine for social type sites but Mailchimp is ostensibly more business oriented, except for maybe a niche of bloggers or social media types whose personal/social identities are interchangeable with their professional identities, I think the majority of users out there would want to keep their personal and business credentials separate. I can understand why the CEO would not want to blur the lines between the professional persona and the social one, after all if in Twitter and Facebook the users are the product and not the customer that could lead me, a Mailchimp customer, wondering how Mailchimp perceives me as well.
- bunderbunder 14y ago> I think the majority of users out there would want to keep their personal and business credentials separate. Yup. Luckily it's pretty easy to maintain one set of online credentials for business activities and another for personal ones.
- mratzloff 14y ago> The way I read this, it's about the CEO overriding the decision based on aesthetic reasons. I read this as the CEO overriding the decision based on experience, not aesthetics. Reducing choices reduces errors.
- omni 14y agoThis seems unreasonable, since he was presented with evidence that showed a strong correlation between more choices and fewer errors. In hindsight, this turned out to not be a causal relationship, but the CEO had no way of knowing that at the time.
- khet 14y agoIf you started making decisions based solely on rational arguments and facts, would those lead to better decisions? Almost all business are built on intangibles. Emotion, creativity, personality, feelings, loyalty, love etc. These intangibles are extremely difficult to explain yet most decision makers instinctively understand them. The CEO probably made a decision on instinct. He was not rationally arguing the social integration, he instinctively denied its value. Rationally, you could probably prove the social buttons to be beneficial but you would have to disregard the intangibles.
- anigbrowl 14y agoI too would rather use Google, but via a browser hook of some sort. I don't like all the social/sharing buttons that festoon most websites these days, and use Ghostery to get rid of them. To some extent it's a dislike of being tracked, but mainly it's just too much crap on my screen.
- Tipzntrix 14y agoAt the bottom of this article, there are "Sign in With FB/Twitter" buttons.
- bluetidepro 14y agoThis. I cracked up when I saw that and wondered about the irony of it all! Haha Screenshot: http://bluetide.pro/EXq4 http://bluetide.pro/EXq4
- digitalengineer 14y agoTo their defense (in the comments): "Yeah, it’s a valid point. We’re using a plugin on our blog called Social that we built with the folks at Crowd Favorite because we saw our blog comments heading to Facebook and Twitter. For blog comments, we’re willing to suffer the social logins so people can talk to us in the channels they’re accustomed. The blog is at the heart of our community, and communities gather in social spaces. But logging into or signing up for the app is another use case all together. That’s where we feel like we’re giving up too much control. That’s what we’re trying to spark a conversation around with this post."
- rsobers 14y agoWow, they dramatically simplified the login form. Here's what I get at the moment: http://i.imgur.com/LExHd.png http://i.imgur.com/LExHd.png
- mnicole 14y agoInteresting, but MailChimp didn't start with these social media login options, did they? So the low percentage of people using those to sign in probably means that most of those people registered after they were in place? Also, regarding the CEO's email and the confusion of so many options on the homepage, that's merely a design issue. Those buttons don't need to take up so much room or be so bold. They could simply be links with tiny corresponding icons underneath the default login form. Taking those options away would be a detriment to both current users of those methods and future users who prefer the quick registration process it provides. The argument thereafter that these logins could easily dissipate and are therefore unreliable is solved the same way SoundCloud does it; allow the user to set a username and password separate from their social networking account in their settings. The only problem with the SoundCloud method, at least at the time I did it, was that in order for it to activate, you had to reset your password. As far as the security point is concerned, that's a risk the user takes and another benefit to having both site-specific credentials and the social media tie-in.
- bluetidepro 14y ago>"Interesting, but MailChimp didn't start with these social media login options, did they? So the low percentage of people using those to sign in probably means that most of those people registered after they were in place?" That was my exact first thought after reading. How can they accurately judge the usefulness of the buttons if (for all we know) hardly any of the users created an account that way from the get go. I would like to see how those same stats stack up to the amount of people that DO have a log using Facebook or Twitter with them. That would be much more relevant on the accuracy of the buttons "worth." Or maybe, you can never really accurately get that data at this point since it was never there in the beginning. The data will always be skew, to some extent.
- bduerst 14y agoYep. There isn't anything very scientific about how he came up with this conclusion. It would be better to try a study in which you give half the users the social network login, and half the users the regular login, and track their activity.
- bunderbunder 14y agoI love being able to log in using an OpenID provider rather than creating an account. Because it's one less !$@%!@$! password to remember. Or it's one less $@&%!@$ hassle adapting my password creation formula to a new site's password requirements. Or it's one less place where my don't-care-use-it-everywhere username/password key is stored, perhaps @$2(! in the clear. Or perhaps it's just one less time I have to type in a @$@(%^! username and password. Or @*($&%! create one.
- eridius 14y agoI agree. But unfortunately, OpenID can magnify the problem for some people. For example, my girlfriend has at least 4 different Stack Overflow accounts because she can never remember which OpenID provider she used, so she keeps accidentally creating new ones.
- tszyn 14y agoExactly. I used to run a small StackExchange site. One day I had a look at my user dump and was surprised to see how many duplicate (and triplicate) accounts there were.
- Tichy 14y agoHaven't been able to log in to StackOverflow for weeks.
- thomaslangston 14y agoThe simple solution is to setup a priority and stick to it. e.g. Google > Twitter > Email >>> Facebook
- jes5199 14y agoYeah, that happens to me to. I need there to be a system that says "We've never seen that ID before! Do you want to link it to some other account?" Which means maybe you should have a separate button for "I want to create an account here" and "I want to log in again here". I know that's heretical to the OpenID community, but I usually know whether or not I have some account on a site, but I usually don't know whether I typed in my openID url or hit the Google button.
- cowboyhero 14y agoI think he buried the lede: Social login buttons can hurt brands. This'll date me, but I'm still amazed that so many companies eagerly slap other company's logos on everything they do. Even if it's just a blog post. This page is a case in point: Facebook's brand appears four times. Twitter's appears a dozen times (more because of the comments). Mailchimp? Just once.
- latchkey 14y agoThis is exactly why Persona really needs to be adopted more and succeed. I'm tired of creating new accounts all the time and Persona solves this issue.
- crystalbeasley 14y agoI'm really happy to see that Aarron's post highlights how important copy is to your success. It's super dull and tedious to get it right, but amazingly effective when done well. The post also confirms my suspicion that the highly secure "username and/or password is invalid" is a costly tradeoff. Glad to see Persona mentioned in this thread. Full disclosure, I'm the UX Designer for Persona. A couple of questions I have for MailChimp * Why use usernames at all? They're a necessary evil for things like forums where users don't want to expose their real names. They are a major contributor to login failures. Email as the unique identifier is much easier to remember. * How much pain did Mailchimp have to endure to migrate the user account that had been created via Facebook and Twitter? What copy did you use to explain? How many users did you lose? * Would you consider implementing Persona? ;) I do want to add a +1 to the concerns other folks have expressed about mixing the context of a personal Facebook account with a professional service like MailChimp. I see in my research one of the main concerns users have about using Sign in with Facebook is that they're unsure what will show up on their wall. Social sign in isn't right for either professional services or on the opposite side, anything that is socially questionable, like a gambling site.
- drelihan 14y agoWhat about having a generic "Third Party Login" button drop down? On a click, a drop down appears with the different login options. This makes the options available to users, but lets the main brand shine.
- BryanB55 14y agoWe've always found that by replacing "username" with "email address" makes logging in a lot easier. Most users already know their email address. By using a username thats one more thing they have to remember.
- RandallBrown 14y agoUsing an email address instead of a username is SO HUGE of a usability win. I can't stand when companies don't do this. My email address is going to be unique. I don't have to pick one of the few standard usernames I use and hope that it's available. I know my email address will be. Have you ever been to a site that says username, but really wants an email address? It's absolutely infuriating.
- chris_mahan 14y agoI use several email addresses for login, including some that are no longer active. When I forget my password on those, I just orphan the account.
- bwooce 14y agoI struggle with this. I acknowledge all your points, but it doesn't cover the usecases of: 1. Changing ISP and getting a new email address. This is really common. 2. Having multiple addresses (work/home, etc). Also see #1 This breaks password resets and creates a "I want to change my credentials" flow that doesn't exist with usernames. It is especially complicated as emails to the old address won't work/are not accessible. Most companies want to keep track customers over their lifetime and not have them create a new account when they change ISP/job. If you want to see an example of this not working at all well, see Apple IDs. The pain surrounding them, purchases, @me.com, @mac.com, changing countries and the attached purchases is inspirational in its depth and breadth.
- JeffL 14y agoWe used to require an email for signing up for our game, but when trying to actually email people, nearly half the emails provided turned out to be fake or bounce for some reason. My takeaway from that is that people don't want to give out their email, so we stopped requiring it. Does anyone have any measurements on if requiring an email instead of a username reduces the number of sign ups?
- netmau5 14y agoI've grown to seriously hate OAuth as a login mechanism. It's great for connecting accounts for integration, but I've been burned by it as a login. On one of my previous projects, Twitter was the only allowed login method. After some complaints, we implemented an email-based login and reduced the bounce rate by over 50%. Another anecdote: whenever my Asana session expires, I always struggle to remember which Google account I registered with or if I used email. The worst part of their flow is that if you're wrong, a new account is created and you login to a blank slate. It takes forever to find the log out button to try again too.
- cookingrobot 14y agoSocial Login buttons are liked by some users (about 30% from our research [1]) and have the added benefit of giving extra biographical data / friends graphs / etc. Some services need that extra data for sharing features etc. We run a service that makes it simple to add Email&Password style login, or Social login to your site: http://www.dailycred.com http://www.dailycred.com [1] http://dailycred.tumblr.com/post/30602034530/surprise-people-hate-being-forced-to-use-facebook http://dailycred.tumblr.com/post/30602034530/surprise-people...
- sologoub 14y agoOne thing that jumped out at me with the "better" error messages, is that it makes it that much more hackable - if I can hit the service and find valid usernames, I can then try to get into those. If you have a catch-all error message, it's much harder to guess the username/password combo.
- MortenK 14y agoThat argument is actually adressed in the post: "The engineering team, ever mindful of security, argued that being generic about username and password errors makes it harder for bad guys to guess usernames by pounding the form with random words or email addresses. But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists, and is not a significant security risk for the bajilions of sites that have them".
- matthewowen 14y agoThat exact point was addressed in the article (or were you simply unconvinced by how it was addressed?)
- nedwin 14y agoAs the article states, they decided that this was a worthwhile risk to take. Users could already use the error handling in new username creation to determine if a username existed. They decided that the net result outweighed the increased risk.
- jules 14y agoYou are very likely already exposing that via a timing attack. If you disallow many login attempts in quick succession then it is also a non issue. If you have that in place and somebody is able to guess the password of a random account (it's an account found by randomly trying usernames after all), then it must be an extremely bad password. The benefits far outweigh the minuscule security risk.
- deleted 14y ago[deleted]
- stephengillie 14y agoSocial login is a shadow issue here - like a sheet over a chair, the little buttons are obscuring a larger issue: Mailchimp found that clarifying login error messages reduced login failures by 66%!! The rest of the story is a coincidental tale about the CEO trying to pull a "Jobs" by thinking he knew what his customers wanted better than they did. The social media buttons only had an effect on 3.4% of their users, a small group compared to the reduction in failed logins. By making the social login buttons the main point of their blog article, they hide this valuable tidbit.
- yahelc 14y agoAmen. The clarified login error message finding is way more interesting than the vague platitudes on branding and security. No one will get rid of their social buttons solely on the basis of this post, but hopefully many people will now work on improving their error messages after reading this.
- zmmmmm 14y ago> The clarified login error message finding is way more interesting than the vague platitudes on branding and security The part about security isn't platitudes. Not displaying informative messages in response to failed logins is a security orthodoxy, something you are almost always told is a compulsary practise if you care about security. So a very key part of the story here is that they abandoned this standard security practise as a tradeoff in favor of usability. Whether this ever bites them or to what extent is something we may never know the answer to. So we have been told the good outcome of their tradeoff and not the bad side. It sounds to me like it was worth it, but I wouldn't like every web service to jump on this uncritically.
- yahelc 14y agoSorry, I meant the security of relying on the services in general, not of exposing that someone has an account with you. Obviously, that's a serious security consideration, and each service should weigh the costs and the benefits. In this case, it seems like they are already exposing it with the account checker, so making this change didn't open up any new vulnerabilities.
- matthewowen 14y agoI think the bigger point has nothing to do with social buttons or login UX. Test your changes independently, and make incremental changes They thought social buttons improved login success. They didn't. An unconnected copy change improved login success. If you test these things independently, you'll get much better insight into what makes a difference.
- nhebb 14y ago> Test your changes independently, and make incremental changes That was my take-away as well. I'm prone to accumulating a list of changes that I'd like to make to my site and then, when change fever strikes, I do them all in unison. When something goes wrong (or right), it's impossible to tell which change had what effect. It's a hard habit to break.
- geerlingguy 14y agoPosted earlier too: http://news.ycombinator.com/item?id=4602425 http://news.ycombinator.com/item?id=4602425
- Zelphyr 14y agoIncreasingly there are going to be people like me who don't trust Facebook, Google, Twitter, etc... enough to have an account (or, at least, a real one) with them. So using them for logging in somewhere else isn't helpful. ONLY being able to use them to log in somewhere else is obviously a reason to never sign up with that "somewhere else" site altogether.
- Nursie 14y agoAnd that's not even taking into account that the random dragging in of resources from these places allows them to track which of their users visit which other sites.
- lifeisstillgood 14y agoAll the comments below (ha I hope!) are arguing for Mozilla persona * I want to use email as username * limit the number of possible ways to login (no NASCAR) * I want to keep personal and business logins seperate * don't slap competitor logos all over my pages (CEO quite right there) this however all begs the question how do I move accounts to a new login? Few sites (stackoverflow is a shining exception) allow you to associate more than one login with one account. And fewer give different settings by login (admin, power user etc) we have been lulled by oauth and openid into thinking we have just to authenticate me, rather than authorise a role - and few sites have concepts ofanything other than one role == one set of privileges == one login. There is a reckoning coming - it is when these sites need to provide fine grained control, as businesses run on them full time, we shall discover why ACLs exist, and what chmod is for. It's going to be painful. But then it's better for mailchimp to take the pain in a couple of years than not be there at all now go install persona. And allow me to associate more than one login with one account
- propercoil 14y agoI joined mailchimp ~7 months ago after Jason (thisweekin.com) pleaded viewers to check it out so i signed up for the free trial (2000 subscribers free no credit card). I'm amazed by everything that they do. Elegant api and ux that "you get" from the get-go. It is a huge problem to solve and i'm now engaging with 1100 subscribers. Now i want to pay ($30/m) but they don't accept paypal - the service i use to pay for everything since i'm a digital vendor. There are companies in the U.S that don't understand that alot of foreigners do business solely with paypal. There are those who dig it though(Elance, Envato, Odesk) mailchimp take the leap! eeee
- ericcoleman 14y agoCouldn't you just get a debit card for your paypal account then? https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=marketing_us/debit_card https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-cont...
- propercoil 14y ago"Sorry, you're not eligible for the PayPal Debit MasterCard®. This may be because you live outside the United States"
- tolmasky 14y agoI think telling people that just their password was wrong was a bad move. The author argues that this is not a security risk because the "username reminder form already tells you if a username exists". However, this simply displays a further security issue. I don't have the link handy, but there was just a (really good) article the other day here on Hacker News about why you should not reveal whether the email address is necessarily associated with a username or password in these kinds of forms (always just give the same generic "we will send it if it exists" message).
- ProblemFactory 14y agoYes, both of these UI features would reveal the fact that this username or email already exists. But isn't it impossible not to reveal it on the signup page anyway? You want users to have unique usernames (or emails acting as usernames), therefore the signup form has to tell them if it has been already taken. My suggestion would be to tell users if the username or email is unknown right away - and perhaps add a captcha if they are trying out too many different usernames.
- tolmasky 14y agoYou can use the same strategy there too: in the signup page, it can just say "a confirmation email has been sent to your email". In the event that the email is already known, the email will say "someone else has tried to sign up with your email -- if this was you click here to change your password". This way, the attacker will never know if the email genuinely resulted in a new account or not.
- MarkMc 14y agoInteresting. So we have a clear-cut case of having to choose between (a) more security; or (b) a simpler sign-up process which means more revenue. It seems to me that choice (a) will not always be the right one - it depends on how much security would improve and how much revenue will be lost. If you find the previous HN article on this topic that you mentioned I'd be curious to read it.
- 14y ago
- badclient 14y agoI am probably in a minority but for me, my Facebook and gmail is more valuable than almost all other accounts. When I see a site that forces me to sign up using Facebook or a google account, I usually hit back. Why? Because in my mind I'm giving access to my entire Facebook to a bunch of guys I know little about. I'm not as fearful that these guys are evil and may directly harm me. I'm more fearful they will post something to my timeline or that they may repost say my public posts for SEO etc. This is one reason I am extremely pissed at instagram. Instagram as a product gives you a sense of privacy because it provides very limited ways to access your photos. You can't just goto instagram.com, login and begin browsing. On the other hand, few people realize that your instagram pictures are public by default and there are dozens of sites which using instagram's API(I'm guessing) are republishing our photos without even your knowledge.
- jes5199 14y agoFacebook nowadays asks you to confirm the permissions you're granting to another site, and if you give timeline-post permissions, then it asks what privacy level the posts should be. I always mark "Private: nobody but me can see those posts." Problem solved.
- catshirt 14y agofew things don't add up here. 1. they added the social buttons late in the game, and are surprised about 4% of users are using the social buttons. what if that 4% was compromised entirely of users who registered since you added the buttons? that would be a totally different ballgame. 2. the problem they were trying to solve was login errors. that's not the problem facebook and twitter sign in solve. therefor it seems fallacious to say "they aren't worth it" when you're not even considering the standard use case.
- robomartin 14y agoThere's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send traffic to Facebook and diminish or even completely fail to promote your own bran? OK, the other question might be: Who is visiting a Facebook page for toilet paper. The point is that I've seen this many, many times from all kinds of companies. Maybe someone can explain? Maybe this is just sheep following sheep off the cliff?
- djt 14y agoPeople are spending a lot of money on Facebook promo these days. I have a lot of people that tell me the number of likes on their business pages boosts their credibility etc.
- Bullshituserid 14y agoWishful thinking and a lack of common sense. Ask them if they check out the number of "likes" a business has before deciding whether to transact business with them. It's a meaningless number. In most cases, you'll have no idea what the total size of the business's market is, or whether its customers tend to be heavy Facebook users. GM might have millions of likes and still suck, whereas a machine shop might have 1000 likes and be the best business of its kind in its entire region. When you look at ridiculous and desperate flailing like QR codes and businesses begging for "likes", you realize that we haven't learned anything.
- hakaaak 14y agoI'm not a fan of social login buttons, but I've visited a lot more brand pages on FB than I have product individual sites, usually because those FB pages are running a promotion where you "like" them and then fill in a form to get some product for free. Sometimes I'll unlike them afterwards, but sometimes I leave my "like" as-is. However, neither FB nor branded product sites have really influenced my purchasing decisions. What does? A product that I research via the web, consumer reports, or Amazon ratings and determine is good, a product that is on sale or is more attractive or just "looks" better (or maybe even has a higher price), and for services and applications, I do the same- look at reviews and determine if there is a free product or service that I feel comfortable using instead. Marketing and ads are a HUGE con game, as people mostly ignore them.
- taylonr 14y agoI see this as two problems. 1. Too many options. They even mentioned it "Did I log in with Facebook or Google or Twitter or what." 2. Having both social & native logon. You could actually solve both by either 1. Only using native logon. or 2. Picking one (maybe 2) social logins. I went with #2. Granted it was on a small test site, but the trade off of managing customer logins sucks. I'd rather have google get busted for getting hacked than for my little SQL DB getting attacked. The way I look at it, I have time to write code and secure it to the best of my ability. However, Google and other social logins have whole teams that can manage security and keep up to date with the latest technology etc. So there is more to social logins than the actual act of logging in. And some of the problems listed aren't really with social logins, but rather with a particular implementation.
- vampirical 14y ago> But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists [...] Alright so this security hole already existed in their system elsewhere. After raising the issue that this type of message leaks data, which is a completely valid concern, they dropped it because they were already leaking that data elsewhere? It isn't like email based account reset/reminder forms have to leak the existence of an email within the system, a fact they just gloss right over. For a system that stores quite a lot of very sensitive data it is surprising to see them knowingly keep such a hole open. I understand the desire to smooth out the user experience but this honestly seems more driven by the desire to not field customer support requests for what feels like a "stupid issue". I'm not currently a MailChimp customer but I used to be and before reading this I would have chosen to use them again if the need was there. Please don't compromise the security of customers for convenience.
- papsosouid 14y agoIn what way does people being able to find out you have a mailchimp account cause a problem for you? Are you concerned someone is going to threaten to go public with this shocking information if you don't pay them off?
- nnash 14y agoI wonder what Pinterest's numbers on this are.
- tsurantino 14y agoOne thing that has been really interested about the discussion of social logins has been the re-emerging critical outlook on online identity. I think that social logins are a double-edged sword, where they give us the ability to easily connect with sites for which our social identity is relevant or for which setting up a whole new custom identity is unnecessary. One the other hand, the obvious drawback is the implicit promotion of the social network as the de facto identity standard, which is dangerous and totalitarian (Facebook owns who you are, sort of). I think the simple value for social login is context. There's an obvious overuse case and a useful use case.
- steeleduncan 14y agoThe problem isn't that social login buttons harm your brand or look ugly, it is that by using social logins you are working to expand the social networks user base and not your own. Online companies are largely valued by the size of their userbase and by working to build Fb or twitter's userbase rather than your own, you are sacrificing the value you add to your own company for the sake of the social network that a user signs in with.
- vseloved 14y agoFinally, someone has the guts to say, that failed logins should tell the user, what is wrong: username or password
- mkjones 14y agoSo I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal opinions. "Social login buttons put security in someone else’s hands" You're damn right they do! I argue that in 99.9% of cases that's a great thing, for 3 reasons: 1. Facebook invests significant resources in both keeping bad guys out (we have been able to dramatically reduce large-scale phishing with a number of updates to our login security systems) and ensuring everyone else can get into their accounts easily. I can only speak for us, but I assume Twitter spends a lot of time on this as well. I imagine it'd be tough for a startup to keep up with the 10-20 people we have working on this problem at any given time. 2. It's incredibly difficult to build a password system that is both easy to use and secure. There's an almost endless ever changing list to make sure you're hashing and salting properly, don't have SQL injection flaws, implement robust rate-limiting without allowing DoS, etc. We've all seen many people screw it up in recent years. One of the largest benefits of Facebook Connect for startups is the ability to leverage our investment in these systems, without having to invest the significant time we have spent iterating on them. 3. We've spent a lot of time working on every aspect of login, so that startups don't have to. Your job is to build whatever technology differentiates you from your competitors, and make it worlds better than theirs. Any time you spend pfutzing with password hashing, building a better password recovery flow, or arguing about how to fail when people type in the wrong password is time you could better spend making a truly wonderful product. Unless you're trying to build a startup that helps people login, any time spent on this is better spent elsewhere.
- steelaz 14y agoMost websites that are adding social login buttons also keep their own registration/authentication setup. I think by adding social login buttons you also increase attack surface on your website, no matter how good third party security is.
- mkjones 14y agoMy point is that you shouldn't bother spending any time rolling your own registration / authentication step. Do you think that using 3rd party auth in lieu of your own auth decreases security?
- tylermenezes 14y agoThe actual point of this article is "Social login buttons aren't worth it... for Mailchimp". Obviously a business-focused company is going to have less people logging in with Facebook than a consumer-focused company. People shouldn't write generalizing blog posts unless they have some understanding of proper experimental design.
- gingerlime 14y agoAs others pointed out, I believe the 3.4% was simply down to social logins introduced much later. When I fist signed-up for mailchimp ages ago, the only option was creating a new user account. I think the article dismisses one huge benefit to federated logins: * ease of use for users - instead of choosing a username, entering all the customer information, verifying the email address etc, choosing a password, you can sign in with one or two clicks.
- adrianhoward 14y agoFor me the most important bit in that was the last line. "Is it worth it? Nope, it’s not to us." (my emphasis) Not all businesses are the same. B2B businesses like MailChimp usually don't see major increases in value through third party auth. They're providing serious value. People will go to the effort regardless. With a casual use B2C site removing even the tiniest piece of friction in the login process can mean the difference between a purchase and people just going away. It depends. This is why we test shit :-) (Also - unrelated to this - is that the "login" bit is often not where the biggest win for third-part auth is. It's in reducing friction in registration. I've seen high single digit percentage improvements in abandonment of registration for some B2C sites due to getting profile info from twitter/linkedin/etc. cutting the time it takes to setup accounts fully. Lifetime value also increased since profile info was generally better from those sources which was an important part of users getting value out of the system, and so the business getting value out of those users). [edit: also - they seem to be looking at total numbers, rather than doing any kind of cohort analysis on the folk using twitter/facebook/whatever... which may well lead to different conclusions]
- voyou 14y ago"The "login" bit is often not where the biggest win for third-part auth is. It's in reducing friction in registration." Yes, which makes it particularly annoying when a website advertizes sign-up via social network only to immediately follow this sign-up with its own registration form, making the social network signup stage an additional stage in signing up, rather than a substitute.
- inthewoods 14y agoAnybody have any data on whether using social login buttons on landing pages increases/decreases conversion?
- pbreit 14y agoWhile I'm disinclined to take UX tips from MailChimp, there are at least two good situations to use 3rd party registration/login: 1) when you're getting more out of it than simple reg/login and 2) mobile.
- shizzy0 14y agoI never use a Facebook or third-party login, if I can help it. Why would I want to tie my real identity to some site I'm opting to _try_ for the first time? I might want to integrate an account to Facebook if the service provided some phenomenal value to me for doing so and the service had gained my trust. But providing my Facebook information to an unknown entity is far more intrusive than providing an email.