Great password reset UIs?
-
Please share some great user interface examples involving password setup and password reset. We're going to be overhauling our webapp, and one of the huge UI nightmares is our password setup and password reset process. It's fairly standard, but I know I've seen better out there in the wild. Please share any links you have to either UI guides themselves that talk about password setup and reset, or live examples of sites with great UI surrounding this process. I'm looking for things that give users live feedback about password selection with AJAX, make it really simple to reset a password if they've forgotten it or their account is locked, potentially with e-mail verification, provide clear messages and wording, visually appealing and functional design, etc., If you've seen anything that hits on any aspect of this, please share. If you have some startlingly bad examples that might also be helpful in a "do not do this" kind of way.
-
Answer:
Some examples from http://ui-patterns.com/: http://ui-patterns.com/patterns/AccountRegistration http://ui-patterns.com/users/9154/collections/1896 http://ui-patterns.com/users/8623/collections/1659/entry/6876 The examples are cross-linked and you can search from the home page. Quora, http://www.quora.com/What-are-some-great-examples-of-a-forgot-password-UX-pattern http://worklogistics.com/2011/04/login-sequence/ diagram linked from the comments. Quora, http://www.quora.com/What-is-the-best-user-experience-for-resetting-a-forgotten-username-and-or-password Understanding Usability, http://blog.objectivedigital.com/40384541
odinsdream at Ask.Metafilter.Com Visit the source
Other answers
For me, the canonical "doing it wrong" account management belongs to http://www.centrelink.gov.au/internet/internet.nsf/home/index.htm At present, I can't even exercise the "register an account" function from that page because all paths through the maze end up at a "successfully logged out" page. That may change tomorrow. Resetting your password can only be done if you have previously created at least three "security questions" (of which you can create up to twenty IIRC). Why you need three is mysterious to me; you only have to get two of them right. Passwords must be exactly eight characters, are checked to make sure they contain at least one lowercase character, at least one uppercase character, and at least one digit. And if you try to use something like KeePass to create these and then paste them in, you get a pop-up window about functions being disabled and your clipboard gets cleared; persist, and you eventually get the option not to be told about that again, at which point pasting starts to work. But if your new password fails validation, the anti-paste pop-up thing starts again. And if you have created any security questions, you need to answer one of them correctly on every logon attempt. And there's a minimum-length limit on security question answers too, so it's just too bad if your first pet's name was "Rex". Other terrible practices I've seen from other sites: - sending emails including your password in plain text (variations: do this for initial passwords only, not for password changes; do this for "temporary" passwords after password resets; do this for password recovery, indicating that the server is holding your actual password rather than a salted hash of it). - no way to change password after logging in - closest is a "forgot password" facility available only before logging in (Simply Energy's old web site did this). Best account-creation facility I've ever used is Google's. About the only thing wrong with it is that the password strength meter is far, far too lenient about what it considers "strong"; there's clearly no attempt at all to derate passwords containing dictionary words.
flabdablet
I'm a big fan of how https://lastpass.com/ deals with passwords, both for the site itself and the way it stores passwords for other sites. I think the canonical example of what not to do is PayPal.
dfriedman
Regarding lastpass; I appreciate their service and we use it extensively, but we're looking for UI options for a self-contained system, so no OpenID, or "Login with Facebook" or Google Apps, etc., as nice as those are.
odinsdream
I found the user registration process at http://www.rdio.com to be slicker than usual. In particular, it only asks you for your email address at first, and then combines the email confirmation step with the remainder of the registration.
maxim0512
Funny, just last week I noticed how slick that Facebook's password reset is if you use Gmail.
rhizome
Related Q & A:
- How To Reset Joomla Admin Password?Best solution by Server Fault
- How To Reset Password?Best solution by Yahoo! Answers
- How do you reset the password on your iPod?Best solution by Ask Different
- How to reset the password on Hotmail?Best solution by Yahoo! Answers
- Why can't I reset my Yahoo password?Best solution by answers.yahoo.com
Just Added Q & A:
- How many active mobile subscribers are there in China?Best solution by Quora
- How to find the right vacation?Best solution by bookit.com
- How To Make Your Own Primer?Best solution by thekrazycouponlady.com
- How do you get the domain & range?Best solution by ChaCha
- How do you open pop up blockers?Best solution by Yahoo! Answers
For every problem there is a solution! Proved by Solucija.
-
Got an issue and looking for advice?
-
Ask Solucija to search every corner of the Web for help.
-
Get workable solutions and helpful tips in a moment.
Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.