|
|
|
|
|
by tdrp
2107 days ago
|
|
Regarding simple passwords, we added a check against the top 100K seclist passwords when first registering, to keep users from using easily guessable passwords (we also had an experiment where we checked if that password was one of the frequently compromised ones). Literally this converted into: 1- Users abandoning on sign-ups "oh how am I supposed to find a password I will remember" 2- Users bashing us on the app store reviews: "make it super hard to sign-up" even though we only ask for username and password, not even an e-mail 3- Users logging in, liking the app, then a few months later when they got logged out for whatever reason, completely forgetting what their password was and not having a fallback e-mail. We ended up pulling it back. We just have a small note now that says "easily guessable password" but allow them to proceed with registration. |
|