How not to manage user accounts

Opinion
Jun 9, 20083 mins

* If you haven't reviewed how your organization manages user accounts and notification services you might want to go and take a look

I recently moved my e-mail services from one provider to another (a saga that I’ll relate some other time) and in the process reorganized my e-mail accounts. One of the key things that happened in the migration was that my list of aliases was lost (thanks to my now ex-mail service provider), so I instituted a “catchall” account. I figured I could just examine the target e-mail addresses to recreate my rather lengthy list of pseudonyms that I’d built up over the last few years.

What I discovered was interesting. First, scores of people every week sign up for services claiming to be in my domain and a handful of people persist in sending messages to non-existent users that I don’t have even after I reply and tell them so!

What’s even more remarkable are the scores of sites that still, after years of discussion of best practices and techniques, accept users without requiring double opt-in. And if that were only the extent of their poor thinking about user interaction …

An example of this depressing kind of ill-conceived, naïve architecture can be found at the New York City Metropolitan Transportation Authority.

First, even allowing for the fact that it’s a public service and most likely cash-strapped, its Web site is still pretty badly laid out – ugly, dense (actually downright stodgy), and poorly organized.

But it’s the Transit Service Advisory services that have really attracted my ire.

In the river of messaging junk was a message for a numb-nut who thought he was in my domain and the TSA Advisory service believed him and hadn’t bothered to double opt him in. So having received his alert I followed the link in the message to unsubscribe him only to be greeted with a form that allowed me to either subscribe as a new user or edit my account, but required me to first log in.

The illogic of the latter is remarkable. How can you establish a password protected account without verifying the user’s e-mail address and without a CAPCHA to confirm they are human? The potential for someone to create accounts in bulk to harass other Internet users is enormous and the waste of the MTA’s obviously scarce resources would be huge. The problems for the MTA are not only in the waste of its storage and processing, but also the bandwidth to send the advisories they generate.

To get into the account I had to use the password recovery feature, get the message with the password, go to the site, log in and then I found I couldn’t actually unsubscribe, I had to change the e-mail address to something that won’t route to my server.

Now you might say that this poor design might be pretty much what you’d expect from a public service, but in my fun with my catchall account I’ve found many organizations including retailers and financial institutions that have similar poor thinking behind their notification systems.

The point here is that if you haven’t reviewed how your organization manages user accounts and notification services you might want to go and take a look. You don’t want wind up as an object lesson here in the Network World Web Applications Alert.