Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that the vast majority of websites I've seen handle the whole process involving passwords horribly (registration, resetting, etc), which induces users to use bad passwords just to get it over with.

Some let you fill out the form and then click on submit and tell you a problem with your password or something. You change it, then they tell you it has to be shorter than 15 or 10 characters, and impose such conditions you almost wait for them to tell you "use: 2Hx,!rJ" as your password. Some don't even support "special" characters, spaces, or hyphens. By the 4th or 5th attempt to register, you're basically trying to come up with the stupidest password you can to feed this monstrosity.

Mind you, somme of these are big companies websites. I think password or registration management also affects things like talent acquisition. Companies using Taleo for instance are doing a great job of repulsing normal, mentally sane, people. The whole approach of registering one account for each company on a different company subdomain on the same domain (company1.taleo.net, company2.taleo.net) and for each one fill out the profile all over again is beyond the realm of my comprehension.

The browser asks you to save the password/username for the website, but it does so for the domain, not the subdomains which all have different passwords. I give up on a company if it's using Taleo. I'm not talented or competent, but I'm sure really competent people wouldn't want to put up with this either and it hurts recruiting.



>The browser asks you to save the password/username for the website, but it does so for the domain, not the subdomains which all have different passwords. I give up on a company if it's using Taleo. I'm not talented or competent, but I'm sure really competent people wouldn't want to put up with this either and it hurts recruiting.

This sounds like your browser's password manager's problem, namely assuming that users will only have a single password per top-level domain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: