Re: best practices for user friendly and secure forgotten password resolution
Hanhwe Kim <[email protected]>
| Newsgroups | gmane.org.user-groups.bay-area |
|---|---|
| Message-ID | <[email protected]> |
I had the joy of working closely with Jef until he passed away. I was his business partner and worked on Jef's THE(The Humane Environment)/Archy technology demonstrator systems and setting up the RCHI(Raskin Center for Humane Interfaces). Jef had an unorthodox approach to sign-on systems. He talks about them in his book "The Humane Interface". He believed that asking for username + password was redundant for identifying a user to a system. If each user had a unique password the same length as username + password, it would be equivalent in terms of difficulty for a intruder to guess. The idea he had for making such passwords easier to remember is to make up phrases consisting of adjective adjective noun phrases such as "old free papaya". The system would generate and assign them to a user to ensure that they two users did not choose the same password. I am not sure having a whole bunch of such odd colorful phrases to remember would be easy for the user if each web service assigned different ones, and we never talked about this in detail. But it did seem like one of those ideas that would be worth investigating. Han Kim On Tue, Aug 25, 2009 at 6:09 PM, Brian Krause<[email protected]> wrote: > Ultimately, it is a whole system being designed and built, and it doesn't > help when user interface designers think of "security" as an enemy imposed > on us by others who we don't have to try to understand. Conversely, it > doesn't help when security experts are so motivated by keeping the bad guys > out that they keep everybody out, but we can only change that by setting a > good example as the kind of people who want to learn as much as possible > about the real world that our designs become a part of. > > If I may continue to channel the late Jef Raskin who I am sure would have > chimed in a while back in this discussion, what are "best practices"? > Whenever I hear that, I think someone is looking for a $10 word for "just > copy Facebook," without any critical thought about what is best for the > problem at hand. (And I wish Jef were around to lend his authority to that > objection.) As other posters have pointed out, security is a relative > concept, quite different for a game site than for a banking application. > Besides that, many UI elements that are common, or used by popular > websites, are not particularly effective--it's just that the big websites > have a lot of inertia to overcome even when they bother to evaluate their > UI's. I strongly recommend against teaching your team that the way to > choose a design approach is by measuring its popularity. > > And to be picky, since a known User ID is not terribly useful, the original > poster was really asking about privacy--the system's current implementation > exposes its customer list to any hacker with patience. This could be of use > to spammers, at least in theory. More seriously, the site answers the > question of who is and who isn't a customer when it says whether the e-mail > address is on file. All you need is someone's e-mail address to know if > they use the site. That could easily be a privacy problem--imagine a > website that deals with medical products, social issues, job searching, > personal finances, etc. An application that embarrasses a user most > emphatically does NOT have a well-designed user interface, and it really > shouldn't take the "security department" to point that out. > > What would Jef do? > > --Brian > > On Aug 25, 2009, at 5:29 PM, Raoul Duke wrote: > >>>> Regardless, security should not get in the way of user-centered >>>> design, or in any way building the app, as a car is not built around >>>> the ignition key. >>> >>> I'm not sure that I can consider it to be good user-centred design if my >>> application's poor security means that their identity gets stolen. >> >> i think this is very true; i find the "Regardless" statement to be >> rather horribly head-in-the-sand. for those who disagree, pretty >> please read http://catless.ncl.ac.uk/risks for a little while. >> >> sincerely, >> -A Curmudgeon. >> _______________________________________________ >> This is the BayCHI Discussions mailing list, [email protected] >> To change your subscription options, or to unsubscribe, visit >> http://baychi.org/mailman/listinfo/discussions > > _______________________________________________ > This is the BayCHI Discussions mailing list, [email protected] > To change your subscription options, or to unsubscribe, visit > http://baychi.org/mailman/listinfo/discussions _______________________________________________ This is the BayCHI Discussions mailing list, [email protected] To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions