Re: best practices for user friendly and secure forgotten password resolution

Brian Krause <[email protected]>
Newsgroups gmane.org.user-groups.bay-area
Message-ID <[email protected]>
Ultimately, it is a whole system being designed and built, and it  
doesn't help when user interface designers think of "security" as an  
enemy imposed on us by others who we don't have to try to understand.   
Conversely, it doesn't help when security experts are so motivated by  
keeping the bad guys out that they keep everybody out, but we can only  
change that by setting a good example as the kind of people who want  
to learn as much as possible about the real world that our designs  
become a part of.

If I may continue to channel the late Jef Raskin who I am sure would  
have chimed in a while back in this discussion, what are "best  
practices"?  Whenever I hear that, I think someone is looking for a  
$10 word for "just copy Facebook," without any critical thought about  
what is best for the problem at hand.  (And I wish Jef were around to  
lend his authority to that objection.)  As other posters have pointed  
out, security is a relative concept, quite different for a game site  
than for a banking application.  Besides that, many UI elements that  
are common, or used by popular websites, are not particularly  
effective--it's just that the big websites have a lot of inertia to  
overcome even when they bother to evaluate their UI's.  I strongly  
recommend against teaching your team that the way to choose a design  
approach is by measuring its popularity.

And to be picky, since a known User ID is not terribly useful, the  
original poster was really asking about privacy--the system's current  
implementation exposes its customer list to any hacker with patience.   
This could be of use to spammers, at least in theory.  More seriously,  
the site answers the question of who is and who isn't a customer when  
it says whether the e-mail address is on file.  All you need is  
someone's e-mail address to know if they use the site.  That could  
easily be a privacy problem--imagine a website that deals with medical  
products, social issues, job searching, personal finances, etc.  An  
application that embarrasses a user most emphatically does NOT have a  
well-designed user interface, and it really shouldn't take the  
"security department" to point that out.

What would Jef do?

--Brian

On Aug 25, 2009, at 5:29 PM, Raoul Duke wrote:

>>> Regardless, security should not get in the way of user-centered
>>> design, or in any way building the app, as a car is not built around
>>> the ignition key.
>>
>> I'm not sure that I can consider it to be good user-centred design  
>> if my
>> application's poor security means that their identity gets stolen.
>
> i think this is very true; i find the "Regardless" statement to be
> rather horribly head-in-the-sand. for those who disagree, pretty
> please read http://catless.ncl.ac.uk/risks for a little while.
>
> sincerely,
> -A Curmudgeon.
> _______________________________________________
> This is the BayCHI Discussions mailing list, [email protected]
> To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
_______________________________________________
This is the BayCHI Discussions mailing list, [email protected]
To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.