# When sites ask for your email address to register, and ask for your password

**URL:** <https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478>\
**Category:** Factual Questions\
**Created:** [April 10, 2020, 2:58am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478 "2020-04-10T02:58:25Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![drad\_dog](https://avatars.discourse-cdn.com/v4/letter/d/aeb1de/32.png) [@drad\_dog](https://boards.straightdope.com/u/drad_dog)\
**Post date:** [April 10, 2020, 2:58am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/1 "2020-04-10T02:58:25Z")

</div>

How secure could this be?

I’ve refused to engage this way before. Don’t they have access to my email?

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [April 10, 2020, 3:03am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/2 "2020-04-10T03:03:26Z")

</div>

I think these websites are using your email address for the login username for their website, and then are asking you to create a password to access the site. Generally, one would create a password different from one’s email account password.

---

<div class="post-metadata">

**Author:** ![Palooka](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/palooka/32/2902_2.png) [@Palooka](https://boards.straightdope.com/u/Palooka)\
**Post date:** [April 10, 2020, 3:06am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/3 "2020-04-10T03:06:34Z")

</div>

You might be confused. You’re not supposed to enter the password to access your email to the site or use the same password when setting up an account at that site. Using the same password for different things isn’t very secure because if one site is compromised, hackers will use the credentials stolen in that breach to access other sites.

How secure any particular site is depends on how they are setup on their backend. Some are extremely secure and some are not secure at all. Some sites store user passwords as plain text. That’s bad.

---

<div class="post-metadata">

**Author:** ![purplehorseshoe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/purplehorseshoe/32/2996_2.png) [@purplehorseshoe](https://boards.straightdope.com/u/purplehorseshoe)\
**Post date:** [April 10, 2020, 6:02am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/4 "2020-04-10T06:02:24Z")

</div>

Even if you used the same password as your email program, that does not grant access to your emails themselves. The company cannot read your emails directly, if that’s what you mean?

---

<div class="post-metadata">

**Author:** ![Cugel](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cugel/32/1199_2.png) [@Cugel](https://boards.straightdope.com/u/Cugel)\
**Post date:** [April 10, 2020, 10:54am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/5 "2020-04-10T10:54:43Z")

</div>

Many years ago (2006?) my sister asked me to setup a Facebook account. It also wanted my email password. I laughed in its face, and it has never darkened my door again.

---

<div class="post-metadata">

**Author:** ![susan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/susan/32/17537_2.png) [@susan](https://boards.straightdope.com/u/susan)\
**Post date:** [April 10, 2020, 11:36am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/6 "2020-04-10T11:36:14Z")

</div>

Yes, if you give anyone your email address and your email password, they can open your email.

No, Facebook doesn’t want your email password. It wants your email address and a novel Facebook password.

---

<div class="post-metadata">

**Author:** ![scr4](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@scr4](https://boards.straightdope.com/u/scr4)\
**Post date:** [April 10, 2020, 11:50am UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/7 "2020-04-10T11:50:02Z")

</div>

> [@susan](#):
>
> No, Facebook doesn’t want your email password. It wants your email address and a novel Facebook password.

Actually Facebook _does_ ask if you’d like Facebook to access your e-mail account and copy your contact info, so it can suggest them as your Facebook friends. Of course this is strictly optional.

---

<div class="post-metadata">

**Author:** ![susan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/susan/32/17537_2.png) [@susan](https://boards.straightdope.com/u/susan)\
**Post date:** [April 10, 2020, 12:25pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/8 "2020-04-10T12:25:57Z")

</div>

Yes, it’s not a requirement.

---

<div class="post-metadata">

**Author:** ![TriPolar](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tripolar/32/3008_2.png) [@TriPolar](https://boards.straightdope.com/u/TriPolar)\
**Post date:** [April 10, 2020, 1:50pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/9 "2020-04-10T13:50:16Z")

</div>

You are not supposed to use your email password (or any other you have), you should make up a unique password for that site. But this technique is ripe for a scam because so many people will just enter their email password. Now, if you will excuse me, I have to design a website that sends free holiday gifts to your grandchildren if you sign up today.

---

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [April 10, 2020, 2:23pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/10 "2020-04-10T14:23:50Z")

</div>

I had a credit card company ask me for my Bank password so they could set up online bill pay.  
I canceled the card for having the gall to ask such a thing. I pay pretty much everything online. Not once have I ever been asked for my bank’s password. WTF?

---

<div class="post-metadata">

**Author:** ![ZipperJJ](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zipperjj/32/211_2.png) [@ZipperJJ](https://boards.straightdope.com/u/ZipperJJ)\
**Post date:** [April 10, 2020, 2:26pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/11 "2020-04-10T14:26:13Z")

</div>

There’s also [social login](https://www.webfx.com/blog/web-design/social-logins/) which allows you to log in to a site using authentication from another place where you’ve already got a login, such as Google, Facebook, Twitter, etc. In that case you are not sharing your password with the site, you are indeed logging in via the other site. The other site sends back a token to the original site letting them know you’re authenticated. There’s no local storage of passwords and the original site doesn’t know your third party site’s login info. There is some sharing of other data, though (like, your Facebook email address for example) which should be outlined when you choose the third-party login.

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [April 10, 2020, 2:36pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/12 "2020-04-10T14:36:12Z")

</div>

> [@Grrr](#):
>
> I had a credit card company ask me for my Bank password so they could set up online bill pay.  
> I canceled the card for having the gall to ask such a thing. I pay pretty much everything online. Not once have I ever been asked for my bank’s password. WTF?

You could have just ignored the request; there was no need to cancel the credit card. If you want the credit card company to initiate the payment from your bank, they _may_ need access to your account to do so.

(I have email from Chase asking me to provide my annual salary, as doing so “may qualify me for a credit limit increase.” I’ve ignored that request and never considered cancelling my credit card account over the request.)

---

<div class="post-metadata">

**Author:** ![ThelmaLou](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thelmalou/32/390_2.png) [@ThelmaLou](https://boards.straightdope.com/u/ThelmaLou)\
**Post date:** [April 10, 2020, 2:38pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/13 "2020-04-10T14:38:43Z")

</div>

I have a yahoo address that I use for sites like this. When you go to a store and they want your email to send you promotional stuff, etc. I’m very careful about giving out my main email address. As a result, I get virtually NO spam at my main address and nothing but spam at my yahoo address.

And no, they don’t want your email password (why on earth would they??), they want you to CREATE a password to use on that particular site.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 10, 2020, 3:08pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/14 "2020-04-10T15:08:51Z")

</div>

While **Grrr!** could have just ignored that request, I’d assume that any credit card company doing something as security-blind as asking for banking passwords is probably doing other stupid things with their security, too, and that it’s thus safest to have nothing at all to do with them.

---

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [April 10, 2020, 3:17pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/15 "2020-04-10T15:17:36Z")

</div>

> [@Dewey\_Finn](#):
>
> You could have just ignored the request; there was no need to cancel the credit card. If you want the credit card company to initiate the payment from your bank, they _may_ need access to your account to do so.
> 
> (I have email from Chase asking me to provide my annual salary, as doing so “may qualify me for a credit limit increase.” I’ve ignored that request and never considered cancelling my credit card account over the request.)

They don’t need my password. They could use my debit card or account number like every other company does.

> [@Chronos](#):
>
> While **Grrr!** could have just ignored that request, I’d assume that any credit card company doing something as security-blind as asking for banking passwords is probably doing other stupid things with their security, too, and that it’s thus safest to have nothing at all to do with them.

Exactly.

---

<div class="post-metadata">

**Author:** ![drad\_dog](https://avatars.discourse-cdn.com/v4/letter/d/aeb1de/32.png) [@drad\_dog](https://boards.straightdope.com/u/drad_dog)\
**Post date:** [April 10, 2020, 4:54pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/16 "2020-04-10T16:54:30Z")

</div>

OP here. To clarify: My experience was that it wanted my email address to use for my name, to ID me, for the purpose of registering me to purchase on their site. If I enter a newpassword I get the message that it is wrong, and to enter a “correct” password. To me this means they want my actual password, and I can’t make one up.

Maybe I’m wrong and I just need to put dummy entries in in a way I haven’t seen.

---

<div class="post-metadata">

**Author:** ![drad\_dog](https://avatars.discourse-cdn.com/v4/letter/d/aeb1de/32.png) [@drad\_dog](https://boards.straightdope.com/u/drad_dog)\
**Post date:** [April 10, 2020, 4:57pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/17 "2020-04-10T16:57:08Z")

</div>

> [@ThelmaLou](#):
>
> I have a yahoo address that I use for sites like this. When you go to a store and they want your email to send you promotional stuff, etc. I’m very careful about giving out my main email address. As a result, I get virtually NO spam at my main address and nothing but spam at my yahoo address.
> 
> And no, they don’t want your email password (why on earth would they??), they want you to CREATE a password to use on that particular site.

See above. They wouldn’t accept a “new” password.

I used to have a system of mulit email addresses but after a while “viruses” got into my system. Life caught up with it.

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [April 10, 2020, 4:58pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/18 "2020-04-10T16:58:13Z")

</div>

Is the message saying that the password does not meet their security requirements? Some sites have restrictions; the password must be at least eight characters, must have some uppercase letters and some lowercase letters, must have numbers, must have a special character, etc.

---

<div class="post-metadata">

**Author:** ![puzzlegal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/puzzlegal/32/3827_2.png) [@puzzlegal](https://boards.straightdope.com/u/puzzlegal)\
**Post date:** [April 10, 2020, 5:05pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/19 "2020-04-10T17:05:56Z")

</div>

> [@drad\_dog](#):
>
> OP here. To clarify: My experience was that it wanted my email address to use for my name, to ID me, for the purpose of registering me to purchase on their site. If I enter a newpassword I get the message that it is wrong, and to enter a “correct” password. To me this means they want my actual password, and I can’t make one up.
> 
> Maybe I’m wrong and I just need to put dummy entries in in a way I haven’t seen.

I think they are asking you to log in with the password you previously created for THAT site. There’s usually a separate button for setting up an account on the site.

I can’t recall ever being asked for my email password. I mean, maybe Facebook did (I would have said “no”) but it’s super-rare. I’m pretty sure you are misunderstanding.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 10, 2020, 5:09pm UTC](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478/20 "2020-04-10T17:09:53Z")

</div>

Yeah, it sounds to me like the OP doesn’t yet have an account on the site, and is clicking a link to “Log In”, instead of the link to “Sign Up”.

[Next page](https://boards.straightdope.com/t/when-sites-ask-for-your-email-address-to-register-and-ask-for-your-password/851478.md?page=2)
