← Back to context

Comment by tonymet

2 days ago

It's a good point on password usability. Signal app periodically prompts you for the encryption PIN to make sure you don't forget it.

I think this should be handled out of band of the login process. Similar to "is xxx still your phone number?" -- companies could do periodic password hygiene and freshness checks.

Context matters. Companies forget that people are trying to get something important done, and blocking them for other attention is a huge frustration.

> Signal app periodically prompts you for the encryption PIN to make sure you don't forget it.

At least Signal does not block the app until you enter the PIN. WhatsApp forces you to enter it before you can reach your messages, which not only is annoying when you're in a hurry, but also forces you to type the PIN even when you're in a place where it might be seen by someone else.

On the other hand, on Signal it's possible to leave the warning forever at the bottom of the screen without acknowledging it and typing the PIN, which kind of defeats its purpose.

  • Apps need to treat these experiences more critically. I had a similar forced re-auth with Gaia when i was offline, losing my maps.

    So here I am, lost, trying to find my way using a downloaded map, and the app won't let me in.

    These are no longer casual entertainment experiences we are dealing with. Many of these apps are central to carrying on with life. And they are introducing new and unanticipated failure modes.