Re: best practices for user friendly and secure forgotten password resolution
Brian Krause <[email protected]>
| Newsgroups | gmane.org.user-groups.bay-area |
|---|---|
| Message-ID | <[email protected]> |
Ultimately, it is a whole system being designed and built, and it doesn't help when user interface designers think of "security" as an enemy imposed on us by others who we don't have to try to understand. Conversely, it doesn't help when security experts are so motivated by keeping the bad guys out that they keep everybody out, but we can only change that by setting a good example as the kind of people who want to learn as much as possible about the real world that our designs become a part of. If I may continue to channel the late Jef Raskin who I am sure would have chimed in a while back in this discussion, what are "best practices"? Whenever I hear that, I think someone is looking for a $10 word for "just copy Facebook," without any critical thought about what is best for the problem at hand. (And I wish Jef were around to lend his authority to that objection.) As other posters have pointed out, security is a relative concept, quite different for a game site than for a banking application. Besides that, many UI elements that are common, or used by popular websites, are not particularly effective--it's just that the big websites have a lot of inertia to overcome even when they bother to evaluate their UI's. I strongly recommend against teaching your team that the way to choose a design approach is by measuring its popularity. And to be picky, since a known User ID is not terribly useful, the original poster was really asking about privacy--the system's current implementation exposes its customer list to any hacker with patience. This could be of use to spammers, at least in theory. More seriously, the site answers the question of who is and who isn't a customer when it says whether the e-mail address is on file. All you need is someone's e-mail address to know if they use the site. That could easily be a privacy problem--imagine a website that deals with medical products, social issues, job searching, personal finances, etc. An application that embarrasses a user most emphatically does NOT have a well-designed user interface, and it really shouldn't take the "security department" to point that out. What would Jef do? --Brian On Aug 25, 2009, at 5:29 PM, Raoul Duke wrote: >>> Regardless, security should not get in the way of user-centered >>> design, or in any way building the app, as a car is not built around >>> the ignition key. >> >> I'm not sure that I can consider it to be good user-centred design >> if my >> application's poor security means that their identity gets stolen. > > i think this is very true; i find the "Regardless" statement to be > rather horribly head-in-the-sand. for those who disagree, pretty > please read http://catless.ncl.ac.uk/risks for a little while. > > sincerely, > -A Curmudgeon. > _______________________________________________ > This is the BayCHI Discussions mailing list, [email protected] > To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions _______________________________________________ This is the BayCHI Discussions mailing list, [email protected] To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions