Live data from Hacker News

Ask HN: Easiest UX for Seniors

news.ycombinator.com

41–50 of 64 posts

Re: Ask HN: Easiest UX for Seniors

#41
post #2

Facebook must have optimized for this. Do whatever they do. And make it so they don't have to log back in frequently.

I think the key for Facebook (and Amazon) are your 2nd point. People login once, and likely never again.

I got my mom, who is in her 70s, a new TV and wanted to sign her into Prime Video. I asked for her Amazon account and she had no idea. I think she said something like, “I don’t have an Amazon account, I never have to login. I don’t even know what it would be.” She has been a Prime member for a decade and hasn’t had to login for so long that she forgot she had an account. It took both me and my sister telling her she must have an account, and listing the reasons why she must have an account, to jog her memory or simply convince her that this was a reality.

This creates a different problem. People forget passwords, lose account info, and when they do need it the recovery is that much harder. Apple Keychain has saved the day with my mom several times.

I was a 1Password user for about 18 years (recently migrated away), and it would ask for your master password every 2 weeks and this is why. If you only have one password, you better remember it. If people only have to login once, they’ll forget. There were a couple times over the years when I drew a blank on what it was and got kind of worried. I also always worried about what would happen if I had some kind of head injury, as I never wanted to actually write that password down anywhere.

Re: Ask HN: Easiest UX for Seniors

#42
I've spent a lot of time helping my 80 year old neighbor with life tech tasks. I've noticed that she seems to be okay with usernames/passwords as long as they're in her password book.

But the site layout can make entering the credentials near impossible. For example, on the login page of the California DMV https://www.dmv.ca.gov/portal/mydmv , the form submission button is below the fold on her 720p laptop. She has to scroll down the login page to log in. She often asks what she should do next because she can't see the button!

If the password isn't in the book we have to go through the forgot password flow. That's usually fine because her email works, but it's offensive to have to log in again after we've reset the password. It's painful to watch someone type these modern passwords, but it's cruel type it three times in a row: once to enter the new password, a second to confirm it, and then the third to actually log in. I'd much rather have the emailed magic link log me in rather than take me to the password reset page.

I often wish that companies would:

0. not actually require account creation (I can walk up to the DMV counter; why do I need to create a password to do it online?)

1. stick to a simple, well established authentication pattern

2. make the buttons large enough

3. make all of the relevant information visible without scrolling on a 720p laptop (with too many pixels taken up by Chrome's tab bar, Windows' task bar, etc.)

4. not have clickable things to sidetrack us (your survey? chatbot popup? an ad? all nightmares)

Re: Ask HN: Easiest UX for Seniors

#43
post #33

I wonder about a scheme using public key encryption where a scannable code is displayed on the log-in screen, where one has an app on a phone that can match it and send an authorization to the site for login. Moves the complexity to unlocking a phone and starting an app.

I assume this scannable code would be a QR code. I still regularly see QR codes throw older people for a loop, even if I know they’ve used them before. Opening the camera app to login is not a natural thing to do.

It also assumes everyone has a smart phone. Maybe this true, but it becomes less true the older someone gets.

Re: Ask HN: Easiest UX for Seniors

#44

Earlier quoted context omitted.

Passkeys are even better since you don't have to pull out your phone or switch to email to grab a code. It just logs you in. Also for old people, its impossible to fall for a phishing page using Passkeys. Unlike auth codes where you can type the code in to a fake login page.

I'm a fan of passkeys because I don't have to store sensitive info. It's just a public key and I don't need identifiable info from the user. That's a super nice option for some niche low stakes software. Unfortunately that breaks down when someone doesn't set multiple keys as backup and gets locked out. Then you're right back to password/backup code or some kind of recovery to email or phone. Chances are people just…

The sync situation is a bit of a mess but it's getting better. Personally I use 1password and everything is synced everywhere effortlessly. But if you are a windows user without a password manager then you are probably best off just using your phone and the QR code scan flow.

The UX issues of Passkeys can and are being fixed. The issues with passwords are unfixable.

Re: Ask HN: Easiest UX for Seniors

#45
post #34

I wonder about a scheme using public key encryption where a scannable code (public key of the pair) is displayed on the log-in screen, where one has an app on a phone that can match it and send an authorization to the site for login. Moves the complexity to unlocking a phone and starting an app.

In Denmark the official identification app does basically this. When you to officially verify yourself for e.g. the bank, government sites or whatever you type a “username” (identity string that officially should not be linkable to you but in practice often is). The site then displays a QR code that you scan with phone and then approve with a slider. It is not perfect but it is fairly easy for everybody.

Re: Ask HN: Easiest UX for Seniors

#46
post #12
post #6

Earlier quoted context omitted.

I really dislike these "magic links" as a login procedure as you always have to switch between apps instead of just filling login / 2FA with your password manager. SMS is even worse as it's also insecure. As an additional option, I can see the benefit for people who live in their Gmail app and don't have a password manager.

The other potential issue is the age of the users. Magic emails might work for general users, but for an 80yo who struggles using a mouse. Teaching them to click on links in emails is probably not the best practise.

Their age also makes them greater targets for social engineering, and asking for an SMS code probably sounds pretty harmless. I’m not sure how secure the original poster’s site needs to be, but I think this would be sketchy.

Re: Ask HN: Easiest UX for Seniors

#47
post #6

Earlier quoted context omitted.

I really dislike these "magic links" as a login procedure as you always have to switch between apps instead of just filling login / 2FA with your password manager. SMS is even worse as it's also insecure. As an additional option, I can see the benefit for people who live in their Gmail app and don't have a password manager.

On iOS, the code from Messages or email is auto populated. But just don’t do email. Too many things can go wrong. But I do love pass keys.

Apple Mail will also do it.

Re: Ask HN: Easiest UX for Seniors

#48
post #33

I wonder about a scheme using public key encryption where a scannable code is displayed on the log-in screen, where one has an app on a phone that can match it and send an authorization to the site for login. Moves the complexity to unlocking a phone and starting an app.

(Same reply as to another comment in this thread)

In Denmark the official identification app does basically this. When you to officially verify yourself for e.g. the bank, government sites or whatever you type a “username” (identity string that officially should not be linkable to you but in practice often is). The site then displays a QR code that you scan with phone and then approve with a slider. It is not perfect but it is fairly easy for everybody.

Re: Ask HN: Easiest UX for Seniors

#49
For people who struggle to understand authentication, surely they have no hope understanding the T&C that they promised every service they had read and understood. The honest thing to do is just not serve these people because they lied on the sign-up form.

But really, stop pretending users have agreed to your T&C when you know almost none of them did more than clicking enough buttons to enable the "I agree" checkbox.

Re: Ask HN: Easiest UX for Seniors

#50

Earlier quoted context omitted.

I'm a fan of passkeys because I don't have to store sensitive info. It's just a public key and I don't need identifiable info from the user. That's a super nice option for some niche low stakes software. Unfortunately that breaks down when someone doesn't set multiple keys as backup and gets locked out. Then you're right back to password/backup code or some kind of recovery to email or phone. Chances are people just…

The sync situation is a bit of a mess but it's getting better. Personally I use 1password and everything is synced everywhere effortlessly. But if you are a windows user without a password manager then you are probably best off just using your phone and the QR code scan flow. The UX issues of Passkeys can and are being fixed. The issues with passwords are unfixable.

> The UX issues of Passkeys can and are being fixed.

I don't see any solutions to the recovery problem that doesn't introduce another login mechanism. But as a primary method the UX is pretty good for the technically literate.

Post reply on HN