Live data from Hacker News

Establishing secure connection

wellsoffice.wellsfargo.com

51–60 of 161 posts

Re: Establishing secure connection

#51

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

I worked for a company that implemented a similar technique and it had positive results. The main features of one of their web based software products was a report generator. The report was quite complex and included a lot of calculations based hierarchical relationships of entities in the system. To build this report by hand would probably take hours, but the queries and calculations were all highly optimized and co…

I suppose it's the same mentality behind: "He's a manager..it doesn't seem like he's doing anything! His job is so easy!". You can replace "manager" with any management/leadership role.

Re: Establishing secure connection

#52

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

This is a totally a marketing technique to make users feel more secure. It's no different than plastering the "hacker safe" (now McAfee Secure) seal on the top of your website. (Which by the way, in tests I've seen split-testing proved the old "hacker safe" seal works better than the new one, or at least it did when the new one was first released).

Most of users don't know what SSL is, but they sure as hell feel more secure if you have a big lock or a nice green checkmark in the top corner, especially if they're thinking about putting in their personal info or credit card number.

Full disclosure: I'm a founder of an online marketing company. :-)

Re: Establishing secure connection

#53

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

Paypal (even with a two-factor fob) has a similar spinning page when logging in.

Once I fell for a phishing link, and the first thing to tip me off was the loading indicator was gone/too fast. In that instance it saved my neck as I changed my password asap.

Maybe users who realize due to a missing indicator should be smart enough to avoid such a trap in the first place, but I was definitely glad then and can see how this could be an active UX decision with positive implications.

Re: Establishing secure connection

#54

TurboTax has something that struck me today as similar (in spirit) to this, though TurboTax's is a skeuomorphic thing. It's the "Save & Exit" button TurboTax has. I'm sure that they are saving all info as it is entered, but users of QuickBooks, Excel, etc., I'm sure are used to having to save their data manually then exit. I think all the guffawing at this progress bar is a little overblown. If a question or concern…

I think it is a terrible idea to put fake security symbols on the screen. It makes people trust those fake symbols instead of learning what they should look for. Since the symbols are just fake it is very easy to stage a MITM attack.

A much better security indicator would be something saying "This site is secure if there's a green area in the address bar [picture of what it should look like]. Click it to verify our identity.".

Re: Establishing secure connection

#55

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

I worked for a company that implemented a similar technique and it had positive results. The main features of one of their web based software products was a report generator. The report was quite complex and included a lot of calculations based hierarchical relationships of entities in the system. To build this report by hand would probably take hours, but the queries and calculations were all highly optimized and co…

We implemented a similar thing a few years ago at a company I worked at. We designed a very fast system zero-knowledge matching over zillion entries. It was way faster than the "competition" (which arguably were slow because they just never cared). It took a few hours instead of a few days to run, basically.

While the results were 99.99% the same as from the slower solution, customers would think "it can't be right" or other things like that, and wouldn't trust the product.

We'd just give the result a day later. Fighting with customers expectations is sometimes very hard.

Re: Establishing secure connection

#56

So, it's actually possible to update a dynamically served gif to provide real progress updates. If that's what they were doing, I'd wonder why they did that rather than use js hooks. But this is just a silly static image. What if the server takes longer than the image to load?

The Adobe Flash installer has this issue. The progress bar is just an animation, so you the installer usually finishes way before the bar does.

Re: Establishing secure connection

#57

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

My $0.02: Banks will get hacked, your identity will get stolen but banks and their insurance companies see that as part of doing business. So far it has been quantifiable. But they want you to feel secure so you do everything online, it saves them in real estate and employees--even as fees skyrocket year after year.

Re: Establishing secure connection

#58

Earlier quoted context omitted.

I worked for a company that implemented a similar technique and it had positive results. The main features of one of their web based software products was a report generator. The report was quite complex and included a lot of calculations based hierarchical relationships of entities in the system. To build this report by hand would probably take hours, but the queries and calculations were all highly optimized and co…

I suppose it's the same mentality behind: "He's a manager..it doesn't seem like he's doing anything! His job is so easy!". You can replace "manager" with any management/leadership role.

Well, playing golf is hard!

Re: Establishing secure connection

#59

This is one of those things that is done by people going "We need our customers to 'feel secure'". I get the rationale, but is there actually any data that suggests this gives that actual feeling? That users "feel" more secure? Or are more trusting of the site? Or is this just cargo-cult UX? edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (T…

I know there is data showing that adding meaningless security badges and icons to checkout designs increases users' perception of security, so I wouldn't be surprised if the fake progress bar was effective.

I'm not sure if there is a better solution that doesn't misrepresent what's actually happening. Users sometimes have heuristics about the way that systems work which might be inaccurate. In this case, the heuristic is something like "doing work correctly takes time; failure happens quickly", where work is keeping your credentials secure. The fundamental problem is that it is difficult for users to differentiate between work done poorly from heavily optimized work done well.

Re: Establishing secure connection

#60
I use this tool everyday and it has always made me laugh. The security of the CEO portal is actually legit though. In order to do anything you must login with: company name, username & password. Once inside in order to do anything important you must use your pin number + a random number from a security dongle like this: http://en.wikipedia.org/wiki/Security_token

Then someone else from within your company must repeat a similar process to approve your action. So you always need at least two people within your company to perform any action.

Typically the CEO portal is used for wire transfers where security is pretty damn important--once the money is gone--its really, really gone.

Post reply on HN