Hello, Mr Website. Would you like my password?
http://jivlain.wordpress.com/2007/04/30/hello-mr-website-would-you-like-my-password/
Hello, Mr Website. Would you like my password?
http://jivlain.wordpress.com/2007/04/30/hello-mr-website-would-you-like-my-password/
I feel I should point out some of the work Angus Logan ( http://blogs.msdn.com/angus_logan/ ) has been doing in the way of creating awareness about the Windows Live Contacts API and really pushing for organisations to start adopting it.
This particular issue is one that really really frustrates me about far too many sites - these APIs (WL/Goog/Y!) are seriously easy to use, and increases the user’s security immensely.
(To be clear, I’m not affiliated with MS or Angus in anyway - I just read his blog)
Jeff:
Thank you for posting this. Another problem with this is that it desensitizes people to giving out their password. Even if Yelp is reputable, it makes the practice seem legit, and people let their guard down making them easier targets for phishing.
I was asked to code this for a website a few months ago, and I refused. At the time, my clients didn’t understand why it was such a big deal to collect email passwords from our users (or give out their own email passwords to anyone that asked).
Thank you - your article will provide even more weight to my arguments against this practise.

What I find much more disturbing is the conclusion - good, experienced developers know that it’s NEVER ok to ask for your password like this, so in turn, that means that whoever worked on that idea in Yelp is unexperienced and clueless. Exactly the kind of people you would trust LAST with security (which is a really tricky thing).
While asking for email passwords is definitely a failure on the part of websites like Yelp, I wonder if Google, MSN, Yahoo, and other email providers are being clear enough when they warn people:
"and you should not share your account name or password with anyone.“
and
"If you are sharing a computer with anyone you should always choose to log out before leaving a site or service to protect access to your information from subsequent users.”
I know people who may not associate typing an email address and password into a form with “sharing it with others” or “giving it away”. They didn’t tell that information to another person. All they’re doing is filling out a registration form. And to understand what the website is going to do with it, they have to read some long privacy policy somewhere else on the website.
People are already used to typing email addresses into web forms (the point of an email address is to give it to others), and every site you go to asks you to enter a password to create an account. And for people who use the same password for everything, they may not even realize the difference.
There will continue to be untrustworthy websites who ask for this information. We need to discourage the type of behavior from trustworthy sites, but we really need to limit the need to enter private information, such as passwords, on a regular basis. Of course, that creates challenges with authentication. Maybe OpenID can help with this.
@Tim, it is in “Gmail, Yahoo! Mail, and MSN/Live/Hotmail/whatever-the-hell-it-is-now-I-lost-track”
They (the big guys) all have contact API’s, you just have to read some of the comments or become informed before coming to your conclusion.
I’m amazed Jeff wasn’t aware of all th efforts being made in this area. Great discussion otherwise. I guess I didn’t realize how many people aren’t aware…OpenID, OAUTH, and Data Portability are pushing almost all large sites to adopt similar methods. Too bad they are choosing slightly different methods.
Even facebook has 'facebook connect’
and myspace has ‘data availability’
(do a google search)
Nobody in OpenID (seems to have the most penetration; maybe Vidoop will do it?) is offering granular data access configuration abilities, this is sorely missing. Credentica. recently acquired by M$ has the best solution, IMO.
I had a website up for a while, and to sign up, I had a form that asked for email address, email password, credit card number, ATM passcode, Swiss bank account number, birth date, blood type, social security number, retinal scan, and then on the bottom had a check box that said “I agree with the terms of service for this site even though it might result in involuntary servitude.”
Of course, the form was a joke, in fact, you couldn’t even enter most of this information or click on the check box. But, I always wonder how many people would have filled in this form just because I asked.
Amen, and thanks, Jeff. Huge red flags should go up anytime you’re asked for this type of info. LinkedIn was the first place I remember seeing this. In this privacy-conscious (yeah, right) world, if you insist on giving some unknown bunch of knuckleheads a list of everyone you email, an exported address book should not be too onerous to use.
(Only Google should have our email and passwords. And search history. And chats. And shopping history. And credit card info. And documents. And contact lists. And stock portfolios. And spreadsheets. And calendars. And notes and photos and videos. And cellular and GPS track data. And medical history. I mean, we can trust them, right? /sarcasm)
I’m actually more surprised by the first two form fields. Isn’t it redundant (not to mention lazy) to ask for your email provider, and then also ask for your e-mail address?
If I tell you my email address is scott@gmail.com (which its not), the website should be smart enough to see @gmail.com, and think… oh, he’s using Gmail! Same with yahoo, etc. Its not difficult and I’m really thinking that this, along with your original problem of asking for login details is just stupid ignorance.
Which is incredibly dangerous if you’re going to be handling email passwords.
No thanks, I’ll pass!
Yeah, I would never have the bad manners either to spam my friends with unsolicited offers. I actually like Yelp - it was helpful when I moved recently. In general, however, I loathe “social networking”. I’m not twelve years old. I go there to read and write a couple reviews - not to hook up.
A web game I played for a very long time had for like four years “You agree to sell your first born son into slavery for no less than USD $100” in their registration form. Tens of thousands of users didn’t seem to mind, in fact, it was only brought up on the forums like two years after it was added.
Yelp are unfortunately not the only ones who come up with that nonsense. Linkedin also allows you to import your stuff from GMail.
I wonder if companies like Yahoo or Google have a legal approach that would allow them to force such sites to drop that nonsense as it violates their TOU or something, but then again, they might believe that it might be better for their business if their customer can just conveniently bring their data into the site. I think that they may fear “Oh no, our customers will think ‘why can I import from Google but not from Yahoo? Is GMail better than Yahoo Mail?’” or whatever.
What makes me wonder: This problem is not new, so why did the smart guys at Yahoo or Google (who usually always have 5 different solutions to every problem) not offer some sort of “external” API yet? as in “Here is a second password that only allows access to the adress book for sites like this”?
It is truly insane for a web site claiming to be legitimate to ask for such a password. Are they kidding? How did this survive even 30 seconds of thought or discussion in product management or development at Yelp.
“I know, we’ll have this cool feature where we find others in Yelp based on their GMail contacts.”
“How will we know their contacts?”
“We’ll just get their password and log in as them, no problem.”
(What happened next)
“Great idea. Let’s do it.”
(What should have happened)
“That is the dumbest thing anyone has ever suggested. That is so dangerous and stupid we should probably fire you on the spot for even imagining that could fly. We will absolutely never want to get someone’s password for another account of theirs. End of discussion.”
why point out yelp when you can flip the finger at facebook. they do the exact same thing. come to think about it, probably 80% of “social networking” sites do it.
this is why i’m anti-social
Well really it’s only a matter of time before Microsoft and Google own everything, and then they’ll all know your password anyways, right? 
I want to mention an experience like this I had recently which was actually good (shock/ horror/). If you use LinkedIn with Yahoo Mail (I think only with Yahoo), they will take you to Yahoo’s site to log in and there is a message explaining that you are giving them limited time access to certain information. It’s clear what’s happening and how it is limited. You log in to Yahoo only on Yahoo’s site. Personally, I found this ok as opposed to the horrifying examples like the one above (Twitter is equally bad).
Jeff, you really need to forward this to your local news channels. They usually do stories at the other end of this: “Well, the web site asked for my password so I gave it to them. Now I can’t log into any of my bank, investment, mortgage, car loan, etc. web sites and Visa just called to see if I was buying something in Hong Kong.”
I’m going to forward this to my local news and see what they do.
“Tonight, on Larry King Live, Jeff Atwood discusses the dangers of giving out your email password…”
In Yelp’s defense - the “Skip this step” is right there. So perhaps they should re-word this like “If you want to enhance your experience but risk losing the password to your bank account”