Re: Password recovery

John Ozturk <[email protected]>
Newsgroups gmane.comp.web.chi-web
Message-ID <[email protected]>
One thing also to consider.
Since you mentioned 'free' trial, adding a CAPCHA is also a good idea to
prevent bots signing up.

John Oktay Ozturk
Manager, eServices Delivery

Teranet Inc.
1 Adelaide Street East, Suite 600
Toronto, Ontario
M5C 2V9
Phone: 416-643-1063
Fax: 416-360-0665
E-mail: [email protected]
Please consider the environment before printing this email
____________________________________
The information in this e-mail is confidential and may be 
legally privileged. It is intended solely for the addressee. 
Access to this e-mail by anyone else is unauthorized. If 
you are not the intended recipient, any disclosure, copying, 
distribution or any action taken or omitted to be taken in 
reliance on it, is prohibited and may be unlawful.
_____________________________________



-----Original Message-----
From: ACM SIGCHI WWW Human Factors (Open Discussion)
[mailto:[email protected]] On Behalf Of Hal Shubin
Sent: Tuesday, October 14, 2008 3:40 PM
To: [email protected]
Subject: Password recovery

When you want people to sign up for a free trial of a Web application,
you want the signup process to be as quick as possible. 
Email address and password (plus password confirmation) seems the be the
least amount of information.

But, what happens when that user has to recover her password? Because
the signup didn't ask for any sort of security information, how can we
verify that it's the right user? We need some other information, but
that makes signup longer.

This seems trivial (just ask for the customer's first pet's elementary
school principal's favorite color), but I'm sure the Marketing folks
will balk when I suggest adding to the nice, short signup process.

I thought of the explanation Staples.com gave when they started asking
for ZIP/Postal codes before showing products: we can serve you better if
we know where you live, and know what stores and products are nearby (or
something like that, and they don't seem to do it anymore). If we do ask
for a security token, explaining the purpose might make it seem like a
*good* thing to prospective customers.

Any thoughts or experience with this?

thanks				-- hs

. . . . . . . . . . . . . . . . . . . . . .
Hal Shubin
Interaction Design, Inc.
617 489 6595
www.user.com

    --------------------------------------------------------------
    Tip of the Day: Use the archives to research common questions
     CHI-WEB: www.sigchi.org/web POSTINGS: mailto:[email protected]
              MODERATORS: mailto:[email protected]
       SUBSCRIPTION CHANGES & FAQ:  www.sigchi.org/web/faq.html
    --------------------------------------------------------------

    --------------------------------------------------------------
    Tip of the Day: Suspend your subscription if using auto replies
     CHI-WEB: www.sigchi.org/web POSTINGS: mailto:[email protected]
              MODERATORS: mailto:[email protected]
       SUBSCRIPTION CHANGES & FAQ:  www.sigchi.org/web/faq.html
    --------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.