Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Jabor posted:

which it does just fine, if you're signed in (e.g. if you're using the same device you created the account on)

if you're not signed in then all you need to do to confirm is sign in again, which isn't a huge burden since it's something you're going to have to do at some point anyway

that doesn't hold at all for a mobile app -- they work fine without a password until you set one and happen to log out (minority of users, but if they do it's very high odds they will want to recover), because all mobile platforms have built-in identifier, and "same device" isn't detectable between browser and app.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Jabor posted:

the app can sign itself up as the handler for that particular site's confirmation urls just fine

that substantially fucks the user experience if the browser is meaningful on the site

have you tried this and measured it? every confirmation pop up you put in people's way carves off percentage points of users, and percentage points of users is millions in revenue at IG's scale

FB runs a half-dozen login/signup experiments at any given time, for the main site and IG/WA. the results are consistently stacked against more steps

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

the extra step is "Open in Instagram?", and equivalent (but more terribly worded) on Android, for which the cancel rate is non-trivial in other scenarios

it's the same broken model used by every site on the web, assuming they bother to confirm at all. the failure mode here is loss of a new, low-value-to-user account. the failure mode of a more complex system is more users locking themselves out of older, high-value-to-user accounts because they didn't complete confirmation

I will pass your thoughts on to the account access team, though, so you can save the world with untried approaches!

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

cinci zoo sniper posted:

there's no good reason, so decent sites that don't cater to droves of non-technicals who die thinking of email have implemented a preverification on registration procedure. you enter email and say age, and confirmation link sent takes you to the registration form

can you give me an example of a mobile app that does this? I'd like to try the flow

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

bobfather posted:

One of my old email addresses (a gmail with a particularly popular name amongst a small group of people) became associated with a randos new Facebook account a while back. I did not have to click a link to verify the address for them, and I now get Facebook notifications meant for them.

yeah, I argued loudly against dropping confirmation there

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

no, multiple emails are for pymk purposes

the confirmation dropping was just friction reduction, afaik

e: the change predates custom audiences, but I guess it's useful for that now too

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Different topic:

How much room is there in the password manager space? My sense is "not very much", but the enterprise offerings seem weak so maybe.

Pitch I got:

quote:

[product] is an enterprise solution and the only password manager that encrypts and stores passwords offline on a smartphone while automating logins on any device. Nothing is ever stored in the cloud, giving convenience and peace of mind to the user and firm. The application uniquely turns a smartphone into a FIDO U2F certified token that only can be authenticated by the user / biometrics.

With random passwords, OTP (SecurID, Google Authenticator, FiDO U2F and Federated Login through SAML and OpenID Connect all running is a single app, [company] has the most comprehensive sign-on stack in the industry today.

Biometrics doesn't thrill me but I'm sure it's in demand. Cloudless is going to appeal.

E: I get a lot of security pitches ("hardware entropy as a service for quantum crypto"), let me know if there's interest in sharing them in the general case

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Powerful Two-Hander posted:

i used a well know UK energy switching site the other day and after going through its setup stuff it created me an account on their service which weirdly required no password, turns out what they do is just link your account to your email address then when you want to login send you a one time(i assume) link with a token in it.

i cant decide if this is good or bad. its something you'd use once a year maybe and this does make signup and login easier as you don't need to remember a password, just generate a 1 time link then forget about it

slack does this as well

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Avenging_Mikon posted:

Pardon my ignorance, but is sledging password managers just insulting them, or breaking them, or something else?

I believe it's a synonym for "slagging".

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that revocation fight is going to be so good

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

duTrieux. posted:

you didn't say my true name backwards

he said it forwards

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

if you're on XP, you want Direfox because it indeed does still update

gonna let that typo stand

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

XP is on the extended support release since March, so it gets much less frequently updated. they'll get security updates through September, then they're as hosed as they should have been years ago

vista is the same

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

FAT32 SHAMER posted:

Just backup your current settings then restore the backup of the original system when you go in ezpz

assuming you can unflip all the "poo poo was installed" bits after you ran whoever's node script all over the innards of your Miata

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

FAT32 SHAMER posted:

it runs on qnx iirc so if anything you can always run a script that does the opposite of whatever the sw888 node script did

sure, you just have to find all of the side-effects and hope the logging isn't append-only

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

quote:

It is hard to understate the critical nature of this site

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Ur Getting Fatter posted:

anyone use any of those "we scan your paper mail and send it to you via email" services?

it seems like the perfect recipe for identity theft but I'm not living in the states and no longer have someone who can reliably check my mail for me

I use Travelling Mailbox for both mail and packages. sometimes I have them scan the contents, but usually I can tell from the outside if I want it. works well so far (past year).

Subjunctive fucked around with this message at 23:06 on Jun 23, 2017

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I've had my card carbon-copied twice in the past three weeks, and it was very weird to me coming from chip-and-pin or NFC tap.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

quote:

(which was actually Telnet)
...
The software for all this access was still on Flanagan's home computer

:thunk:

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

flakeloaf posted:

it seems that knowing where you live would be a sensible prerequisite for buying things with a credit card

my address can show up as Toronto or York depending on who does the lookup, and some sites like to "correct" it

also, entering your apartment in the right way can be a pain. one of my cards insisted on "Apt C" with no . or as "Unit C" or such.

  • Locked thread