Re: My usability experience - Asa Dotzler should be fired

SmoothPorcupine <[email protected]> Sun, 21 Aug 2011 23:58:28 -0700 (PDT)
Newsgroups gmane.comp.mozilla.ui
Organization http://groups.google.com
Message-ID <5332b40f-2a09-466b-a84b-e1e71372b649@e20g2000prn.googlegroups.com>
On Aug 20, 5:46 pm, Asa Dotzler <[email protected]> wrote:
> SmoothPorcupine wrote:
> > I'm afraid I'm going to have to correct you here. I don't expect
> > you'll want to hear it. I honestly expect it's one of those things you
> > reaffirm for yourself to keep yourself sane and moving forward. It's
> > the lie that keeps the UX team (which I personally see as the source
> > of all that is "bad" in Firefox) from being torn apart by the "power
> > users" that made Mozilla a thing.
>
> Protip: If you want the UX team (and me) to listen and respond to your
> comments, may I humbly suggest that you not open your comments by
> insulting us.

That was my mistake. In, "I personally see as the source of all that
is "bad" in Firefox," I meant "bad for me." I guess if these changes
weren't positive for the majority of users, they wouldn't have taken
place. It's just not my cup of tea, really. Not being a Firefox user,
I don't care about the UX team listening to me per se, just as long as
it doesn't affect SeaMonkey /too/ much. :P

> Mozilla Mission is to empower these users. That is why we're here. I
> don't agree with your characterizations, but even if I did, that's the
> challenge we would face.

If I may be blunt, I think it has failed pretty miserably in doing
that where it really matters. Nobody can be empowered unless they
understand what's going on. There are myriad social engineering
attacks waiting to be set off because of the way that web technology
is changing. As the technology gets ever more complex, it gets ever
harder to understand, and ever more people are left unharmed by
nothing short of good grace on the behalf of hackers everywhere.

How do you expect people to understand URLs when half the thing can be
rewritten by any script on the page?
How do you expect people to know whether they're truly encrypted or
not when you say that legitimate sites don't self-sign their SSL
certificates?
How do you expect people to avoid being phished or pharmed when they
don't even know what a domain is? When the DNS lookup isn't subject to
auditing?
How are you going to explain to a frustrated user that a snippet of
JavaScript compromised their webmail account, and therefore *all*
their accounts across the web? Shouldn't there have been some cross-
origin policy that stopped that? Shouldn't there have been a
confirmation dialog provided *by the browser,* that the request the
page was able to preform automatically would alter state? Couldn't
scripts be restricted to only non-state-altering GET requests?

> That challenge may not be interesting to you,

Oh no, it interests me greatly. The main issue is figuring out how to
get them to understand why they need to learn this stuff. How do I get
them to read the critical security warning dialog when the web page
instructed them to ignore the dialog and just click through? /When/
that fails, how do I, by design, minimize the damage that can be done
by such corrosive ignorance and aversion to learning?

HTML elements is pretty much where I draw the line. Every
"advancement" in HyperText since XMLHttpRequest has done nothing but
to make the web a more complex and unnavigable soup of
incomprehension. I have my own ideas for how to restore at least
security, if not usability, to the pulverized web, but I can't divulge
them for fear that someone, somewhere, might just get an idea that,
when implemented, removes all hope from the algorithm.

> I'm glad that you have SeaMonkey. I put a lot of blood sweat and tears
> into making that possible, you know :-)

No, I did not, in fact, know. :V

All the contributions you have made over the years should really be
documented somewhere. Not to toot your own horn or anything, but when
people are advocating your castration and replacement while comparing
you to Hitler, they deserve some context, you know?