Post B51MmirltD74bZBbe4 by portaloffreedom@social.linux.pizza
(DIR) More posts by portaloffreedom@social.linux.pizza
(DIR) Post #B51LRd1CKxQQQryO3s by gardiner_bryant@mastodon.online
0 likes, 0 repeats
How the hell do you build a user experience for people who are 100% truly and completely ignorant about computers?I have a client with an employee who *refuses to remember his username and password.* I get emails at least once a month saying "he can no longer access the portal.""Why not?" I ask."Not sure," with a screenshot saying they input the wrong username/password.So I have to log in, reset their password and send it to them. I've tried forcing them to set their own password...
(DIR) Post #B51LahW8yk6qzam2K0 by gardiner_bryant@mastodon.online
0 likes, 0 repeats
...after they log in... but that *also* doesn't work.It seems like they *will not* remember their password no matter what I do. I'm at a loss and I'm tired of dealing with this.Any suggestions?
(DIR) Post #B51LqLd67o1rk3UHpY by gardiner_bryant@mastodon.online
0 likes, 0 repeats
It's probably worth noting I have modest password requirements. Must be at least 8 characters long, alphanumeric with upper and lower case, and at least one special character.
(DIR) Post #B51M191LLRvnoyyb0C by christopherbrown@mastodon.social
0 likes, 0 repeats
@gardiner_bryant This is sexy.
(DIR) Post #B51M4Wc65GVzrUmOo4 by ysaeldev@mastodon.social
0 likes, 0 repeats
@gardiner_bryant survive
(DIR) Post #B51M8ONscdkLUtyQy0 by unboundcelestial@mastodon.social
0 likes, 0 repeats
@gardiner_bryant I'm just a random kid who managed to get a mastodon account, so feel free not to take this too seriously, but is there a way to make it so your client is able to reset the employee's password?
(DIR) Post #B51MAPaz5bV9pk4AFM by richarddegenne@mastodon.online
0 likes, 0 repeats
@gardiner_bryant Have them set up a password manager?
(DIR) Post #B51MAnhtRZHwc7U1Lc by portaloffreedom@social.linux.pizza
0 likes, 0 repeats
@gardiner_bryant either a password manager on the browser that remembers the login or a passwordless auth using those fancy new technolgies that websites beg me to try, passkeys they are called?
(DIR) Post #B51MBGoHEucssJh1pA by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@ysaeldev I mean, yes. But this guy's inability to remember his password is reflecting poorly on me. He is blaming me for it not working when *nobody else* in their org has this issue.
(DIR) Post #B51MImLgNSdsiZtlx2 by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@portaloffreedom I've thought about passkey auth but, unfortunately, the client won't pay me to implement this and... even if I did... there are limitations to this that would prevent it from working. Especially considering the user needs to be logged in on the office PC and on their phone.
(DIR) Post #B51MNi1NtUE2kEksnQ by xandowsk@mastodon.social
0 likes, 0 repeats
@gardiner_bryant Yes. Not working with direct user support. My life improved a lot after that some years ago š
(DIR) Post #B51MRXK1cExQigIcFs by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@unboundcelestial oh man. They totally can. And I've showed the boss and the office manager how to do this for them. They would just rather send me an emial.
(DIR) Post #B51MVwzy5pihVp1T28 by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@richarddegenne this guy wouldn't be able to use a password manager. Either he would forget the *one password* for the manager or he would not keep it updated... or he'd only have it on his phone and get totally lost on the office PC.
(DIR) Post #B51MmirltD74bZBbe4 by portaloffreedom@social.linux.pizza
0 likes, 0 repeats
@gardiner_bryant another line of thought could be to improve the password reset flow so that you are not needed for it. "Click here if you forgot your password" flow.Finally using the browser storage for a password hint or the password itself; like a session cookie with no expiration date.One could also use a technique like JWT tokens in apps, which continuously renew themselves without a need for a password.
(DIR) Post #B51N4urQ294L17hFhY by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@portaloffreedom Thank you for your input! Self-service password resets already exist.Sessions last over 60 days but he seems to log out all the time.
(DIR) Post #B51NWJYiJWcfR70nvU by hazematman@mastodon.social
0 likes, 0 repeats
@gardiner_bryant maybe something like passkey? I don't know the details of how it works but from what I understand assuming he's using the same computer the credential will just be stored there.In terms of covering your own ass maybe just gathe data about invalid with attempts and try to pitch your customer on having some internal IT training. Also if they're that bad remember you can "fire" customers :p
(DIR) Post #B51O64I2YpaWVPGIEa by m_star@mastodon.social
0 likes, 0 repeats
@gardiner_bryant I don't quite see how the login on desktop and phone would pose an issue with passkeys since you can easily use (or even require) a physical one for both (or even use the phone as passkey manager for both) (would also get rid of the username requirement). The not being paid to implement them is a much bigger hurdle imo.I've got some (though not much) experience implementing them if there are questions
(DIR) Post #B51OR4ieA0UpuxivT6 by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@hobbs They log in through their phone *and* through a shared office PC unfortunately.
(DIR) Post #B51OX7LZIrr1nyoI3k by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@m_star Sorry. It's a shared office PC. I forgot about the ability to use a phone as a hardware key. I'll look into it.
(DIR) Post #B51OrErb4BQ4uQNybo by JeroenBaten@mastodon.nl
0 likes, 0 repeats
@gardiner_bryant do what other sites do, email a one time login url to the users email adres.
(DIR) Post #B51OrF40K3LPWuBswq by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@JeroenBaten this is an interesting idea. This might actually work for the guy.
(DIR) Post #B51Ou8zdLgnjZTWw7s by Betterthanlast@mstdn.social
0 likes, 0 repeats
@gardiner_bryant @unboundcelestial Machiavellian, but at work sometimes we have to āmake them feel the painā in situations like these. Iād set up an autoresponder for their domain specifically saying youāre away on-site and wait to get back to them to try to force them to use their admin privileges to reset it. Iād respond but make it take longer to make the option of resetting it themselves more attractive and maybe make it annoying enough for them to correct the employee.
(DIR) Post #B51PBdG64k42MRZOHg by gardiner_bryant@mastodon.online
0 likes, 0 repeats
@Betterthanlast @unboundcelestial the problem is, they think the issue is with my code. No matter how many times I explain that *this means he's typing in his password wrong*, they still think "any error message that appears on screen means Gardiner's code is f'ed up*.And the error message is "Wrong username or password. Try again."
(DIR) Post #B51PIY39q7cOEXocAy by portaloffreedom@social.linux.pizza
0 likes, 0 repeats
@gardiner_bryant hopefully that gave enough ideas. But, I do have a couple of other suggestions after giving it more brain power.No logout solution: the logout button brings you to the login screen but does not invalidate the token, so login is possible again with no password input. This will make you support the person once every 2 months.Automated support: give him a robocall center to call to reset his password via phone.And than that got me thinking, if the person is more comfortable with phones rather than computers, why not a login with the phone? Input SMS code to complete the login (I know I know SMS are not the best, but it might be a good compromise here). Or something else like scan a QR code.In the end the password is just a mechanism to "prove the identity". If you can prove that a connection is from the authorized person with another method that is not memory, or memory of a different kind (pattern memory? Probably too simple for a web exposed endpoint) that will probably work too.Alas, if you don't have a budget for implementing passkeys I'm afraid these are more thought exercises than practical solutions....Anyway, cheers :)
(DIR) Post #B51S7nYM9tMozcyRkG by jsbilsbrough@mastodon.me.uk
0 likes, 0 repeats
@gardiner_bryant is this a portal you manage ? If so, passkeys so they can use Windows Hello or equivalent ?
(DIR) Post #B51UrieIvKpz0pmS8m by Bene@fosstodon.org
0 likes, 0 repeats
@gardiner_bryant sounds like every ticket needs a bill associated to it
(DIR) Post #B51c2WKJmHDPeyWtm4 by Betterthanlast@mstdn.social
0 likes, 0 repeats
@gardiner_bryant @unboundcelestial it might be worth getting them on a call if thatās the case (and if you think they might be receptive to that).āIām too lazy to reset the passwordā is an annoyance but a relatively benign issue when compared to āI think your code breaks all the timeā.It may be worth having a friendly, non-confrontational call to explain and safeguard future contracts and your overall reputation with potential future clients.
(DIR) Post #B51ctwUREZF89SjkMy by ysaeldev@mastodon.social
0 likes, 0 repeats
@gardiner_bryant Iām fairly new to working with clients. I think itās best to be as courteous as possible: let him know you can send a password reset link (I donāt know your system; Iām just assuming) and that they are responsible for their credentials. If they want to avoid future hassle, recommend they keep the password on a sticky note or use a password manager. Best of luck Bryant.
(DIR) Post #B52td40PvigAuwBy9Q by andrewmacleod@librem.one
0 likes, 0 repeats
@gardiner_bryant tell them to to make their password 'P@55w0rd' or something similarš
(DIR) Post #B530fHPLltHyk2rGIi by joshfowler@toot.io
0 likes, 0 repeats
@gardiner_bryant The only really effective way I found for situations like this is using fingerprints to login. If they lose those, we have bigger problems.