Live data from Hacker News

The Line of Death

textslashplain.com

71–80 of 108 posts

Re: The Line of Death

#71

Speaking of zones of death, I was recently the (unsuccessful) target of a credit card gathering scam—on a Twitter ad, pretending to be Twitter . https://twitter.com/bcjordan/status/819894043870105602 Multiple users actually entered their CC #s, two canceled them after they saw my reply to the tweet warning users. Incredibly, Twitter has still not notified the scammed users about it despite removing the ad after my re…

That's actually quite well done

Re: The Line of Death

#72
post #2

From a few weeks ago: https://twitter.com/tomscott/status/812265182646927361 This is a neat blog post that goes to show the extents of faking that can be done in the browser. More talks about this will hopefully lead to better "security UI" as the author puts it.

That was one of the most clever phishing attack that I've ever seen. I'm quite sure that if I wasn't aware of such attacks, I'd fall for it myself.

Re: The Line of Death

#73

Can someone explain the risk of something like Mac OS Mail asking for your gmail password? There's no address bar so I've wondered if I can really trust that I'm not handing my password to a MITM.

Google usually suggests that users create app specific passwords for anything that requires you to enter your Google credentials inside another app. If we follow this religiously, then the risk will be quite low

Re: The Line of Death

#74

Speaking of zones of death, I was recently the (unsuccessful) target of a credit card gathering scam—on a Twitter ad, pretending to be Twitter . https://twitter.com/bcjordan/status/819894043870105602 Multiple users actually entered their CC #s, two canceled them after they saw my reply to the tweet warning users. Incredibly, Twitter has still not notified the scammed users about it despite removing the ad after my re…

I don't know why you'd need to scam people on Twitter. There are plenty of people who just post photos of their cards: https://twitter.com/needadebitcard

That is excellent. My colleagues in ecommerce will have kittens over that. Sometimes we wonder if such and such country or such and such bank uses chip and pin. We can just test our online checkout to find out!!!

Re: The Line of Death

#76
post #18
post #10

Earlier quoted context omitted.

http://schubiserv.de/images/opera-benutzerauthentifizierung....

I still disagree with both lucideer's original and improved wording, but I agree with their message, which praises Opera's basic auth UI as making it clear with the borders and 3D foreground overlay effect that it's a part of the browser-produced "trusted zone", and not the pool of untrusted content behind. Moreover, these kinds of UIs are still possible with the 'flat' look that's in vogue today, so there's little e…

> one reason is that basic auth lost out early on to site-supplied login forms, so people got used to entering usernames and passwords into the page content anyway, instead of the browser UI

To be fair, basic auth is not particularly user-friendly. If you want to add anything else to the login form, such as a "Remember Me" checkbox or a captcha, you can't put that in the browser chrome, you need to add an additional step in the login flow. If you want an "Did you forget your password? Click here to reset it." error message, the user has to cancel out of the auth dialog in frustration before they can see it (or you have to redirect them to an error page after failed auth, with another link/button to Try Logging In Again.

And even if you solve those problems, the user still needs to enter their username/password when creating their account, and I have never seen Basic Auth used for this scenario.

Re: The Line of Death

#77
post #15

I think the real issue is that everybody cares about usability but nobody actually cares about the users. Browsers, web apps, etc. try hard to make it easy to browse the web, but they don't try very hard to make it clear exactly what you're doing and what the risks are - in fact, everyone tries rather hard to downplay the risks and to hide how things actually work. How many users understand "the line of death", or th…

Here's a test; find a six year old, get the six year old to look for stuff on the web. See how confused they are when the search box jumps to the url bar. See how they react to the clickbait and ads that get in the way of every interaction that they have. See how they struggle with dozens of peoples ideas about page layouts and responsiveness.

Now, you will say : kids are good at using tech, look they are on x,y & z. They know how to do things I don't! But the thing is that they are using services learned one at a time - not access to the library of babel that we all hoped for !

I agree with your post up to the end. The Very happy to stay uninformed too is like "the soviet people love communism". User don't know what is out there that they could get. Especially users don't know what it is that could be made and put out there. This is because tech people don't actually give a toss about HCI and information retrieval, just selling ads and raising rounds of funding.

Don't be evil.

Re: The Line of Death

#78
post #77
post #15

I think the real issue is that everybody cares about usability but nobody actually cares about the users. Browsers, web apps, etc. try hard to make it easy to browse the web, but they don't try very hard to make it clear exactly what you're doing and what the risks are - in fact, everyone tries rather hard to downplay the risks and to hide how things actually work. How many users understand "the line of death", or th…

Here's a test; find a six year old, get the six year old to look for stuff on the web. See how confused they are when the search box jumps to the url bar. See how they react to the clickbait and ads that get in the way of every interaction that they have. See how they struggle with dozens of peoples ideas about page layouts and responsiveness. Now, you will say : kids are good at using tech, look they are on x,y & z.…

I believe that "kids these days are good with technology" is a phrase uttered by older people who are actually seeing the kids' willingness to experiment without fear, and assume that it must mean proficiency.

Not quite the same thing in the end, though.

Re: The Line of Death

#79
post #15

I think the real issue is that everybody cares about usability but nobody actually cares about the users. Browsers, web apps, etc. try hard to make it easy to browse the web, but they don't try very hard to make it clear exactly what you're doing and what the risks are - in fact, everyone tries rather hard to downplay the risks and to hide how things actually work. How many users understand "the line of death", or th…

> in fact, everyone tries rather hard to downplay the risks and to hide how things actually work.

And why is that?

It's because doing the opposite is in the way of maximizing your ROI (return on investment).

Put simply, it reduces the company's (investor's/owner's) money. It's always about the money.

Re: The Line of Death

#80
Put the tab strip below the URL bar. This used to be the case in the past.

That'll leave plenty of room to have things drop down from the URL bar without much ambiguity.

Post reply on HN