Security design: Stop trying to fix the user

On the tendency of security approaches to rely on somehow educating users on this complex problem.

I’ve read dozens of studies about how to get people to pay attention to security warnings. We can tweak their wording, highlight them in red, and jiggle them on the screen, but nothing works because users know the warnings are invariably meaningless. They don’t see “the certificate has expired; are you sure you want to go to this webpage?” They see, “I’m an annoying message preventing you from reading a webpage. Click here to get rid of me.”…

We must stop trying to fix the user to achieve security. We’ll never get there, and research toward those goals just obscures the real problems. Usable security does not mean “getting people to do what we want.” It means creating security that works, given (or despite) what people do.

The same could be said for usability of any kind — but it seems especially vital in this case.

Via Khürt Williams.

Somehow we missed it

More on the hard work designers need to do to ensure they have a positive impact on society.

To create a platform designed to connect millions of people and not imagine its potential misuses is wilful blindness. When we imagine and design and build tools and technologies and platforms and services it’s as important, perhaps more important to ask ‘how might this be misused’ as it is to ask ‘how might this be used’.

How computer software can make policy, explained by family separation at the border

How bad software design decisions can have a more devastating impact than bad policies.

At a time when Silicon Valley and the larger public are waking up to the government’s reliance on software to carry out its agenda, it’s more important than ever for tech workers to be thoughtful about how they can be a force for good.

6 mistakes that prevent UX teams from having boardroom influence

A good list of don’ts when you’re trying to set up an effective user experience function.

In particular, the pitfalls of “cargo cult usability” could do with being more widely understood. But I also enjoyed this point about being too insular.

Newly formed UX teams have a tendency to quickly turn inwards and focus heavily on their own practices, tools and methods: heads down, working in a vacuum, doing great work that doesn’t actually influence anything. As a result, we hear frustrated stakeholders say things like: “I don’t involve the UX team because they always seem too busy”. We’ve even heard UX team members themselves complain that, “We’re so busy and so mired in the day-to-day that we don’t have time to work alongside the development team.”

This reminds me of the (hilarious but true) story of the Staffordshire UK bus company. In 1976 it was reported that the buses on the Hanley to Bagnall route were not stopping to pick up passengers. People complained that buses would drive right by long lines of waiting passengers. The complaints prompted Councillor Arthur Cholerton to make transport history by stating that if the buses stopped to pick up passengers it would disrupt the timetable!

The hunt for missing expectations

Jared Spool tells the story of a bookkeeper who became frustrated using Google Sheets because it didn’t have a double underline function.

To keep [usability] testing simple and under control, we often define the outcomes we want. For example, in testing Google Spreadsheet, we might have a profit and loss statement we’d want participants to make. To make it clear what we were expecting, we might show the final report we’d like them to make.

Since we never thought about the importance of double underlines, our sample final report wouldn’t have them. Our participant, wanting to do what we’ve asked of her, would unlikely add double underlines in. Our bias is reflected in the test results and we won’t uncover the missing expectation.

He suggests interview-based task design as a way of finding these missing expectations. Start a session with an interview to discover these expectations. Then construct a usability test task based on that.

I recently ran hybrid interviews and usability tests. That was for expediency. I didn’t base tasks on what I’d found in the interview. But it’s good to know I wasn’t completely barking up the wrong tree. I plan to use this approach in future.

These classic BBC Two idents designed by Lambie-Nairn have now been retired — but not for the first time.

They were first replaced in 2001 by the Personality idents, which (despite the name) were actually rather insipid by comparison. Then came the downright dull Window on the World idents.

Lambie-Nairn’s idents returned in 2014. But they were originally developed in 1991. At the time, they were credited with transforming wider perceptions of the channel. It had been seen as dull and worthy, but became arty and exciting.

27 years is a hell of a long time for these idents to last, especially considering the subsequent shift to widescreen, then HD broadcasting. They have pretty much stood the test of time.

Later idents in the set became more complex and less focused. But I am especially fond of the very original idents from 1991, which were particularly pure and striking. The use of the Gill Sans 2, coloured with viridian, and backed with ethereal music, is such a simple idea, yet it was employed with remarkable versatility.

The web I want

Why developers’ obsession with using complicated JavaScript to deliver some text to users needs to stop.

I made my first website about 20 years ago and it delivered as much content as most websites today. It was more accessible, ran faster and easier to develop then 90% of the stuff you’ll read on here.

20 years later I browse the Internet with a few tabs open and I have somehow downloaded many megabytes of data, my laptop is on fire and yet in terms of actual content delivery nothing has really changed.

Smart voice assistants and smart homes — from the past

A really enjoyable piece on the history of smart home devices, and how Google Home and Alexa aren’t such new ideas. The video is well worth a watch, particularly because it demonstrates 1970s technology from Pico Electronics in Glenrothes! It’s amazing to see it work so well.

The point of Thomas Baekdal’s piece here is to demonstrate how trends aren’t new, but they emerge over a long period of time. It reminds me a bit of Gartner’s hype cycle, and a recent Nile webinar about how to employ foresight to understand emerging trends. Not to forget the Nielsen Norman Group research demonstrating that intelligent assistants still have horrible usability problems.

Stop building for San Francisco

Realising that forcing websites to go HTTPS makes them more inaccessible for people with poorer connections was a penny dropping moment for me.

But this article takes the argument a bit broader.

First of all, you need to understand who your audience is, as people. If they’re genuinely wealthy people in a first world city, then you do you. But for people in rural areas, or countries with less of a solid internet infrastructure, failing to take these restrictions into account will limit your potential to grow. If you’re not building something that is accessible to your audience, you’re not building a solution for them at all.

You ≠ user.

Trying to use the new F1 timing app

The new Formula 1 timing app is comically bad. Even on quite a large screen, it only shows 10 drivers — at a gigantic font size. Meanwhile, the live driver tracker is juddery and completely unusable.

But hey, I guess it uses Sean Bratches’ new fonts.

The old app wasn’t perfect, but at least it gave you all the information you needed to follow a session, and the driver tracker was usable.

It’s difficult to believe Liberty Media did any usability testing with any F1 fans before unleashing this style-over-substance atrocity.