SlideShare a Scribd company logo
1 of 46
Download to read offline
7 Password 
Creation & Recovery 
Frustrations 
Every Designer Should Know About 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Password creation and retrieval 
can be a painful activity. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
What’s more, a frustrating sign-in experience 
can prevent users from returning to your site. 
To make it easy for users to sign up and keep 
signing in to your site, take a look at these 
common user frustrations and their solutions. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Password Creation 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #1: 
Missing instructions 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
It’s no fun for users to enter the password of 
their choice, only to receive an error message 
stating that the password didn’t meet the 
requirements, which were never described in 
the first place. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
Make all password requirements clear from 
the beginning. 
Be sure the requirements aren’t in the form 
field itself, where they will disappear when 
the user starts typing. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Clearly stating the requirements saves time 
and sanity for your users. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Password strength meters indicate whether a 
user has successfully met all the requirements, 
and they’re a good motivator to choose a 
strong password. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
The meter on the left tells me at a glance that 
this short password isn’t going to cut it. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Find out what users think 
about your site or app’s 
password requirements! 
Watch over the shoulder of a real 
person as they create a password 
for the very first time, or attempt to 
navigate your password reset process. 
Give UserTesting a Try 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #2: 
Overly complex requirements 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
A lot of websites require passwords to contain 
a certain level of complexity to increase 
security. 
Complexity alone doesn’t always make a 
password secure. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
For example, “Orange1!” is a pretty weak 
password. It would be easy for a computer 
to crack, even though it could be difficult to 
remember. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Plus, complex passwords 
are especially irritating 
and difficult to type on 
mobile devices. 
Mobile keyboards make 
numbers and capital 
letters prone to error. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
Rather than enforcing strict complexity parameters, 
consider using length requirements. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
A Carnegie Mellon University study shows 
that 16-character, simple passwords perform 
better against brute force attacks than 
8-character, complex passwords. 
The effectiveness of long passwords is also 
illustrated by this popular cartoon. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #3: 
What happens when the user 
doesn’t follow instructions 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Even if you specify the password requirements up 
front, some users will try to choose a password 
that doesn’t fit the parameters you set. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
When this happens, make it easy for the 
user to understand and fix the error. Clearly 
explain which requirement was missed and 
what the user should do to correct it. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
This error message 
isn’t very helpful. 
How do I know 
what I did wrong? 
With this message, 
I know exactly 
what to fix. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Finally, if the password doesn’t meet 
requirements, don’t allow your signup form 
to erase all of the information the user 
entered! 
It’s bad enough to get an error message for 
creating a weak password; it’s much worse 
to have to fill out every field on the form to 
make a second attempt. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #4: 
Typos in the password 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
If a user types in a password incorrectly, 
then they won’t be able to sign in with the 
password they thought they created. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
To prevent this problem, many sites require 
the user to enter their chosen password 
twice. While this catches typos, it’s not the 
most pleasant user experience. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Alternatively, you can unmask the password 
(or at least give the user the option to do so). 
It’s relatively rare for users to have their 
secure information stolen by a person 
looking over their shoulder at the moment of 
password creation. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
With an unmasked password, users can 
double-check to ensure they’ve entered 
everything correctly. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
This signup form allows users to unmask the password, and 
it clearly shows which requirements have been met. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Password Recovery 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #5: 
No clues about the original 
password requirements 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Some websites have very specific password 
parameters that users won’t necessarily 
remember when they go to sign in. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
This error message doesn’t give me any 
specific clues about what I did wrong. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
Except on sites with very high security 
concerns, it’s a good idea to display the 
password requirements after the first failed 
attempt at sign-in. 
It’s also helpful to indicate whether the 
username or the password was the culprit for 
the failed sign-in. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #6: 
Unclear retrieval steps 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
If the user doesn’t understand what to do 
next, or where the password retrieval link will 
be sent, they’re not as likely to return to your 
site. 
Either they’ll become irritated and avoid it on 
purpose, or they’ll simply give up and forget 
about it. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Solution: 
Be clear from the beginning about which email 
address is associated with the account. 
For added security, you can mask portions of 
the email address, as in the following example: 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Frustration #7: 
Emailing the forgotten 
password in plain text 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
It’s never a good idea to include a password 
in an email, which can easily be intercepted. 
It’s much more secure to send a link to reset 
the password. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
If your site has fewer security concerns 
(say, a recipe sharing community) it may be 
tempting to think this rule shouldn’t apply. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Always consider the fact that users are 
especially likely to reuse weak passwords on 
sites like this. 
A hacker who intercepted the email would 
likely gain the credentials for many other sites. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Besides, it’s always best to hash and salt 
passwords, which prevents website owners 
— or hackers — from “looking up” a lost 
password. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Other Considerations 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
It may come as no surprise that the best 
way to find out how users will feel about 
your password creation and retrieval process 
is—that’s right—to test it! 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Users have different expectations about 
password requirements and usage depending 
on the type of website: for example, a bank vs. 
a social network. 
To find the right balance of security and ease 
of use, ask users directly through surveys and 
user tests. 
@UserTesting | 800-903-9493 | sales@usertesting.com
7 Password Frustrations 
Find out what users think 
about your site or app’s 
password requirements! 
Watch over the shoulder of a real 
person as they create a password 
for the very first time, or attempt to 
navigate your password reset process. 
Give UserTesting a Try 
@UserTesting | 800-903-9493 | sales@usertesting.com
www.usertesting.com 
@UserTesting | 800-903-9493 | sales@usertesting.com

More Related Content

More from UserTesting

Actionable Results from UX Research
Actionable Results from UX ResearchActionable Results from UX Research
Actionable Results from UX ResearchUserTesting
 
A Webinar with UserTesting: Orchestrating Experiences
A Webinar with UserTesting: Orchestrating Experiences A Webinar with UserTesting: Orchestrating Experiences
A Webinar with UserTesting: Orchestrating Experiences UserTesting
 
Creating great customer journeys through customer interviews: Real-world advi...
Creating great customer journeys through customer interviews: Real-world advi...Creating great customer journeys through customer interviews: Real-world advi...
Creating great customer journeys through customer interviews: Real-world advi...UserTesting
 
The Streaming Media CX Index: What customers expect from SVOD experiences
The Streaming Media CX Index: What customers expect from SVOD experiencesThe Streaming Media CX Index: What customers expect from SVOD experiences
The Streaming Media CX Index: What customers expect from SVOD experiencesUserTesting
 
Three Ways Fast Human Insight is Revolutionizing Marketing
Three Ways Fast Human Insight is Revolutionizing Marketing Three Ways Fast Human Insight is Revolutionizing Marketing
Three Ways Fast Human Insight is Revolutionizing Marketing UserTesting
 
3 Digital Transformation Strategies Driving CX
3 Digital Transformation Strategies Driving CX3 Digital Transformation Strategies Driving CX
3 Digital Transformation Strategies Driving CXUserTesting
 
CX goes mainstream: Five trends driving the future of CX
CX goes mainstream: Five trends driving the future of CX CX goes mainstream: Five trends driving the future of CX
CX goes mainstream: Five trends driving the future of CX UserTesting
 
How human insights focused organizations become CX leaders
How human insights focused organizations become CX leaders How human insights focused organizations become CX leaders
How human insights focused organizations become CX leaders UserTesting
 
The Banking Mobile CX Index: Insights to improve the mobile banking experience
The Banking Mobile CX Index: Insights to improve the mobile banking experienceThe Banking Mobile CX Index: Insights to improve the mobile banking experience
The Banking Mobile CX Index: Insights to improve the mobile banking experienceUserTesting
 
Nordstrom Rack | Hautelook: Building a Customer-Centered Culture
Nordstrom Rack | Hautelook: Building a Customer-Centered CultureNordstrom Rack | Hautelook: Building a Customer-Centered Culture
Nordstrom Rack | Hautelook: Building a Customer-Centered CultureUserTesting
 
Insights on 2017 cx trends and 2018 predictions webinar
Insights on 2017 cx trends and 2018 predictions webinarInsights on 2017 cx trends and 2018 predictions webinar
Insights on 2017 cx trends and 2018 predictions webinarUserTesting
 
Live Conversation: Cut your customer interview costs by up to 90%
Live Conversation: Cut your customer interview costs by up to 90%Live Conversation: Cut your customer interview costs by up to 90%
Live Conversation: Cut your customer interview costs by up to 90%UserTesting
 
Introducing Live Conversation | Human Insight on Demand
Introducing Live Conversation | Human Insight on DemandIntroducing Live Conversation | Human Insight on Demand
Introducing Live Conversation | Human Insight on DemandUserTesting
 
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskey
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskeyUncovering Need and Validating Ideas with UserTesting by Marieke McCloskey
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskeyUserTesting
 
Customer Insights at Scale: Uncovering the "Why" with Walmart.ca
Customer Insights at Scale: Uncovering the "Why" with Walmart.caCustomer Insights at Scale: Uncovering the "Why" with Walmart.ca
Customer Insights at Scale: Uncovering the "Why" with Walmart.caUserTesting
 
The Evolution of UX at Redfin
The Evolution of UX at RedfinThe Evolution of UX at Redfin
The Evolution of UX at RedfinUserTesting
 
My recruit webinar user testing
My recruit webinar   user testingMy recruit webinar   user testing
My recruit webinar user testingUserTesting
 
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...UserTesting
 
UX at Canadian Tire: Baking empathy into projects
UX at Canadian Tire: Baking empathy into projectsUX at Canadian Tire: Baking empathy into projects
UX at Canadian Tire: Baking empathy into projectsUserTesting
 
[UserTesting Webinar] Design Thinking & Design Research at Credit Karma
[UserTesting Webinar] Design Thinking & Design Research at Credit Karma[UserTesting Webinar] Design Thinking & Design Research at Credit Karma
[UserTesting Webinar] Design Thinking & Design Research at Credit KarmaUserTesting
 

More from UserTesting (20)

Actionable Results from UX Research
Actionable Results from UX ResearchActionable Results from UX Research
Actionable Results from UX Research
 
A Webinar with UserTesting: Orchestrating Experiences
A Webinar with UserTesting: Orchestrating Experiences A Webinar with UserTesting: Orchestrating Experiences
A Webinar with UserTesting: Orchestrating Experiences
 
Creating great customer journeys through customer interviews: Real-world advi...
Creating great customer journeys through customer interviews: Real-world advi...Creating great customer journeys through customer interviews: Real-world advi...
Creating great customer journeys through customer interviews: Real-world advi...
 
The Streaming Media CX Index: What customers expect from SVOD experiences
The Streaming Media CX Index: What customers expect from SVOD experiencesThe Streaming Media CX Index: What customers expect from SVOD experiences
The Streaming Media CX Index: What customers expect from SVOD experiences
 
Three Ways Fast Human Insight is Revolutionizing Marketing
Three Ways Fast Human Insight is Revolutionizing Marketing Three Ways Fast Human Insight is Revolutionizing Marketing
Three Ways Fast Human Insight is Revolutionizing Marketing
 
3 Digital Transformation Strategies Driving CX
3 Digital Transformation Strategies Driving CX3 Digital Transformation Strategies Driving CX
3 Digital Transformation Strategies Driving CX
 
CX goes mainstream: Five trends driving the future of CX
CX goes mainstream: Five trends driving the future of CX CX goes mainstream: Five trends driving the future of CX
CX goes mainstream: Five trends driving the future of CX
 
How human insights focused organizations become CX leaders
How human insights focused organizations become CX leaders How human insights focused organizations become CX leaders
How human insights focused organizations become CX leaders
 
The Banking Mobile CX Index: Insights to improve the mobile banking experience
The Banking Mobile CX Index: Insights to improve the mobile banking experienceThe Banking Mobile CX Index: Insights to improve the mobile banking experience
The Banking Mobile CX Index: Insights to improve the mobile banking experience
 
Nordstrom Rack | Hautelook: Building a Customer-Centered Culture
Nordstrom Rack | Hautelook: Building a Customer-Centered CultureNordstrom Rack | Hautelook: Building a Customer-Centered Culture
Nordstrom Rack | Hautelook: Building a Customer-Centered Culture
 
Insights on 2017 cx trends and 2018 predictions webinar
Insights on 2017 cx trends and 2018 predictions webinarInsights on 2017 cx trends and 2018 predictions webinar
Insights on 2017 cx trends and 2018 predictions webinar
 
Live Conversation: Cut your customer interview costs by up to 90%
Live Conversation: Cut your customer interview costs by up to 90%Live Conversation: Cut your customer interview costs by up to 90%
Live Conversation: Cut your customer interview costs by up to 90%
 
Introducing Live Conversation | Human Insight on Demand
Introducing Live Conversation | Human Insight on DemandIntroducing Live Conversation | Human Insight on Demand
Introducing Live Conversation | Human Insight on Demand
 
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskey
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskeyUncovering Need and Validating Ideas with UserTesting by Marieke McCloskey
Uncovering Need and Validating Ideas with UserTesting by Marieke McCloskey
 
Customer Insights at Scale: Uncovering the "Why" with Walmart.ca
Customer Insights at Scale: Uncovering the "Why" with Walmart.caCustomer Insights at Scale: Uncovering the "Why" with Walmart.ca
Customer Insights at Scale: Uncovering the "Why" with Walmart.ca
 
The Evolution of UX at Redfin
The Evolution of UX at RedfinThe Evolution of UX at Redfin
The Evolution of UX at Redfin
 
My recruit webinar user testing
My recruit webinar   user testingMy recruit webinar   user testing
My recruit webinar user testing
 
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...
[UserTesting Webinar] Tackling B2B and B2C challenges: User Research at HomeA...
 
UX at Canadian Tire: Baking empathy into projects
UX at Canadian Tire: Baking empathy into projectsUX at Canadian Tire: Baking empathy into projects
UX at Canadian Tire: Baking empathy into projects
 
[UserTesting Webinar] Design Thinking & Design Research at Credit Karma
[UserTesting Webinar] Design Thinking & Design Research at Credit Karma[UserTesting Webinar] Design Thinking & Design Research at Credit Karma
[UserTesting Webinar] Design Thinking & Design Research at Credit Karma
 

Recently uploaded

Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...panagenda
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 
Manual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditManual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditSkynet Technologies
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rick Flair
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 

Recently uploaded (20)

Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 
Manual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditManual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance Audit
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 

7 user experience password frustrations and how to fix them

  • 1. 7 Password Creation & Recovery Frustrations Every Designer Should Know About @UserTesting | 800-903-9493 | sales@usertesting.com
  • 2. 7 Password Frustrations Password creation and retrieval can be a painful activity. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 3. 7 Password Frustrations What’s more, a frustrating sign-in experience can prevent users from returning to your site. To make it easy for users to sign up and keep signing in to your site, take a look at these common user frustrations and their solutions. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 4. 7 Password Frustrations Password Creation @UserTesting | 800-903-9493 | sales@usertesting.com
  • 5. 7 Password Frustrations Frustration #1: Missing instructions @UserTesting | 800-903-9493 | sales@usertesting.com
  • 6. 7 Password Frustrations It’s no fun for users to enter the password of their choice, only to receive an error message stating that the password didn’t meet the requirements, which were never described in the first place. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 7. 7 Password Frustrations Solution: Make all password requirements clear from the beginning. Be sure the requirements aren’t in the form field itself, where they will disappear when the user starts typing. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 8. 7 Password Frustrations Clearly stating the requirements saves time and sanity for your users. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 9. 7 Password Frustrations Password strength meters indicate whether a user has successfully met all the requirements, and they’re a good motivator to choose a strong password. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 10. 7 Password Frustrations The meter on the left tells me at a glance that this short password isn’t going to cut it. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 11. 7 Password Frustrations Find out what users think about your site or app’s password requirements! Watch over the shoulder of a real person as they create a password for the very first time, or attempt to navigate your password reset process. Give UserTesting a Try @UserTesting | 800-903-9493 | sales@usertesting.com
  • 12. 7 Password Frustrations Frustration #2: Overly complex requirements @UserTesting | 800-903-9493 | sales@usertesting.com
  • 13. 7 Password Frustrations A lot of websites require passwords to contain a certain level of complexity to increase security. Complexity alone doesn’t always make a password secure. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 14. 7 Password Frustrations For example, “Orange1!” is a pretty weak password. It would be easy for a computer to crack, even though it could be difficult to remember. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 15. 7 Password Frustrations Plus, complex passwords are especially irritating and difficult to type on mobile devices. Mobile keyboards make numbers and capital letters prone to error. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 16. 7 Password Frustrations Solution: Rather than enforcing strict complexity parameters, consider using length requirements. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 17. 7 Password Frustrations A Carnegie Mellon University study shows that 16-character, simple passwords perform better against brute force attacks than 8-character, complex passwords. The effectiveness of long passwords is also illustrated by this popular cartoon. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 18. 7 Password Frustrations Frustration #3: What happens when the user doesn’t follow instructions @UserTesting | 800-903-9493 | sales@usertesting.com
  • 19. 7 Password Frustrations Even if you specify the password requirements up front, some users will try to choose a password that doesn’t fit the parameters you set. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 20. 7 Password Frustrations Solution: When this happens, make it easy for the user to understand and fix the error. Clearly explain which requirement was missed and what the user should do to correct it. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 21. 7 Password Frustrations This error message isn’t very helpful. How do I know what I did wrong? With this message, I know exactly what to fix. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 22. 7 Password Frustrations Finally, if the password doesn’t meet requirements, don’t allow your signup form to erase all of the information the user entered! It’s bad enough to get an error message for creating a weak password; it’s much worse to have to fill out every field on the form to make a second attempt. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 23. 7 Password Frustrations Frustration #4: Typos in the password @UserTesting | 800-903-9493 | sales@usertesting.com
  • 24. 7 Password Frustrations If a user types in a password incorrectly, then they won’t be able to sign in with the password they thought they created. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 25. 7 Password Frustrations Solution: To prevent this problem, many sites require the user to enter their chosen password twice. While this catches typos, it’s not the most pleasant user experience. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 26. 7 Password Frustrations Alternatively, you can unmask the password (or at least give the user the option to do so). It’s relatively rare for users to have their secure information stolen by a person looking over their shoulder at the moment of password creation. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 27. 7 Password Frustrations With an unmasked password, users can double-check to ensure they’ve entered everything correctly. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 28. 7 Password Frustrations This signup form allows users to unmask the password, and it clearly shows which requirements have been met. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 29. 7 Password Frustrations Password Recovery @UserTesting | 800-903-9493 | sales@usertesting.com
  • 30. 7 Password Frustrations Frustration #5: No clues about the original password requirements @UserTesting | 800-903-9493 | sales@usertesting.com
  • 31. 7 Password Frustrations Some websites have very specific password parameters that users won’t necessarily remember when they go to sign in. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 32. 7 Password Frustrations This error message doesn’t give me any specific clues about what I did wrong. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 33. 7 Password Frustrations Solution: Except on sites with very high security concerns, it’s a good idea to display the password requirements after the first failed attempt at sign-in. It’s also helpful to indicate whether the username or the password was the culprit for the failed sign-in. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 34. 7 Password Frustrations Frustration #6: Unclear retrieval steps @UserTesting | 800-903-9493 | sales@usertesting.com
  • 35. 7 Password Frustrations If the user doesn’t understand what to do next, or where the password retrieval link will be sent, they’re not as likely to return to your site. Either they’ll become irritated and avoid it on purpose, or they’ll simply give up and forget about it. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 36. 7 Password Frustrations Solution: Be clear from the beginning about which email address is associated with the account. For added security, you can mask portions of the email address, as in the following example: @UserTesting | 800-903-9493 | sales@usertesting.com
  • 37. 7 Password Frustrations Frustration #7: Emailing the forgotten password in plain text @UserTesting | 800-903-9493 | sales@usertesting.com
  • 38. 7 Password Frustrations It’s never a good idea to include a password in an email, which can easily be intercepted. It’s much more secure to send a link to reset the password. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 39. 7 Password Frustrations If your site has fewer security concerns (say, a recipe sharing community) it may be tempting to think this rule shouldn’t apply. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 40. 7 Password Frustrations Always consider the fact that users are especially likely to reuse weak passwords on sites like this. A hacker who intercepted the email would likely gain the credentials for many other sites. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 41. 7 Password Frustrations Besides, it’s always best to hash and salt passwords, which prevents website owners — or hackers — from “looking up” a lost password. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 42. 7 Password Frustrations Other Considerations @UserTesting | 800-903-9493 | sales@usertesting.com
  • 43. 7 Password Frustrations It may come as no surprise that the best way to find out how users will feel about your password creation and retrieval process is—that’s right—to test it! @UserTesting | 800-903-9493 | sales@usertesting.com
  • 44. 7 Password Frustrations Users have different expectations about password requirements and usage depending on the type of website: for example, a bank vs. a social network. To find the right balance of security and ease of use, ask users directly through surveys and user tests. @UserTesting | 800-903-9493 | sales@usertesting.com
  • 45. 7 Password Frustrations Find out what users think about your site or app’s password requirements! Watch over the shoulder of a real person as they create a password for the very first time, or attempt to navigate your password reset process. Give UserTesting a Try @UserTesting | 800-903-9493 | sales@usertesting.com
  • 46. www.usertesting.com @UserTesting | 800-903-9493 | sales@usertesting.com