Comment 0 for bug 890473

Revision history for this message
Stephen Brandwood (sbrandwoo) wrote :

I now accidentally have 3, possibly 4 logins to Launchpad due to it's eagerness to sign up new users without telling them what's happening.

1) Select an email address not used for launchpad (we all have more than 1)
2) Enter the email on login and guess what you'd have set your password to
3) Screen will say passwords don't match
4) Click forgotten password
5) Launchpad now makes it sound like you have an account and sends you a confirmation code
6) Fill in the code from your email and you have a new account.

You now have two OpenID accounts. You now have your bug reports fragmented over two separate accounts. Come back in a years time with a new bug and you may end up with three accounts.

I think the site needs to make it clear that it is creating a new account to warn people that they have entered the wrong email address. If I'm saying I have forgotten my password then it is likely that I know I have an account but I don't know my exact username/password combination.

I know that you don't want to give away any information on whether an account exists to attackers, but I think that shouldn't overtake the user experience. I don't know any other website that operates like this.

Steve

P.S If anyone with the power can find out how many duplicate accounts there are with my name, I'd be fascinated to know. A recent account was given a suffix of -6, making me wonder who the other 5 mes were.