Email+password vs. "social" signin
Posted: Thu Feb 13, 2014 1:18 pm
I'm curious how folks feel about the topic of signing up/in to Web sites and applications, specifically around providing an email+password vs. using a "social signin like Facebook, Twitter, Google, etc.
As a user, I'm not really eager to give people access to my Facebook account. I feel less wary of giving them my Twitter account because I don't really put much personal info in there or use it that much. It rarely occurs to me to use my Google credentials. I think I sort of prefer using an email/password, although it generally means getting spammed. But at least I can use an email address I don't care about, one that's not tied to any of my personal contacts/friends/etc. At that point I don't feel like I'm giving much away.
As a smalltime developer, I am seeing an insane amount of spam email+password signups on the Song Fight! Jukebox. I thought if I made it so that you were generated a random password and you had to get the password via the email you provided before you could log in, that would stop spammers. Not only are the spammers signing up, but they are receiving the password email, then using that password to log in. There are >20k of them from the last couple months. I have no spam accounts that signed in via Twitter/Facebook. Frankly this makes me tempted to just switch my site over to social signin only, with no option for signing up with an email+password. I have no resources for dealing with spam accounts, whereas, Twitter, Facebook, Google, etc. have whole departments dedicated to fighting spam accounts.
So personally I'm conflicted about the subject, and wondering how others feel about it, as users, and for a few of you, as developers.
As a user, I'm not really eager to give people access to my Facebook account. I feel less wary of giving them my Twitter account because I don't really put much personal info in there or use it that much. It rarely occurs to me to use my Google credentials. I think I sort of prefer using an email/password, although it generally means getting spammed. But at least I can use an email address I don't care about, one that's not tied to any of my personal contacts/friends/etc. At that point I don't feel like I'm giving much away.
As a smalltime developer, I am seeing an insane amount of spam email+password signups on the Song Fight! Jukebox. I thought if I made it so that you were generated a random password and you had to get the password via the email you provided before you could log in, that would stop spammers. Not only are the spammers signing up, but they are receiving the password email, then using that password to log in. There are >20k of them from the last couple months. I have no spam accounts that signed in via Twitter/Facebook. Frankly this makes me tempted to just switch my site over to social signin only, with no option for signing up with an email+password. I have no resources for dealing with spam accounts, whereas, Twitter, Facebook, Google, etc. have whole departments dedicated to fighting spam accounts.
So personally I'm conflicted about the subject, and wondering how others feel about it, as users, and for a few of you, as developers.