Bad UI is causing people to get scammed
ashlan.com
ashlan.com
I had to go help my 70yo neighbour deal with Microsoft scammers after she clicked the "continue" button for her time scheduling form: https://ibb.co/CKCbRpf
Guess where the actual continue button is?
Computers are hell for normal people. There needs to be some sort of standards both on the appearance of ads ("can't look like the flow of a page, must be ""clearly"" an ad") and the positioning of ads (must be in margins, can't use absolute positioning).
After clicking this, it takes you to a Microsoft security product page looking website, forces itself to full screen, robotic voice blaring " your computer is insecure, please step away from computer" and a pop-up telling you what number to call to sort it out.
She came knocking on my door with the Microsoft tech support on the phone. Thankfully she had problems with the run prompt, and wanted me to help. I just hung up, closed the site. And installed an ad blocker.
And then people out there who support ads on the internet as they are right now
Some things that stop her in her tracks:
- any control that requires a touch to activate and then disappears on a timeout - like all the controls for video apps. She takes 3-4 seconds to realize something changed and then 5 more more to start orienting herself. The controls usually disappear within 5-7 seconds.
- any surprising prompt from the os throws her into helplessness and panic - updates that need a restart, etc.
- anything that switches the focus away from the current activity. Why would android interrupt a live call with some BS, ever, is beyond me.
- communications apps show a screen with names but that's often the log of past calls or a chat. She wants to just click a name and make a call. On zoom, going to her contacts required 2 or 3 clicks which were not intuitive for her, and so she can never initiate a call.
- zoom audio needed active confirmation to connect to audio. On a tablet, where no options are available but the over-wifi audio.
- her having to slide a control in order to answer a call.
- anything that requires a reaction within 10-15 seconds
- anything that uses (even widely accepted) technical jargon.
She is not deaf or disabled nor visually impaired and yet the complexity of using this device presents serious obstacles.
These are just from the top of my head. She doesn't browse or use a computer and I'm happy for her. TV and newspaper are enough and I just don't feel good about having her navigate a world of malicious predatory dark patterns.
This makes me realize how used I am to not trusting anything online and presuming the worst by default - in order to protect myself.
I remember how about a decade ago my dad wanted me to help him with an important email. Someone had emailed him to tell him he won a lottery in Britain. It took me a lot of effort to explain to him that it is a scam, that they've emailed everyone, automatically, (to him a simple email takes half an hour so he can't imagine so much effort going into a scam) and that despite them knowing his name... they don't really know him.
The asymmetrical nature of malicious activity online is so... dishartening.
I'm an experienced developer in the software industry and some of the stuff you mention still catches me off-guard --- especially the whole "disappearing controls" thing. https://news.ycombinator.com/item?id=24965293
She uses an iPad, but progressively Apple has complicated the interface to fit in more and more features, which has made it harder and harder for her to use the device simply.
---
One recent example is the Notes app, which today includes folders, tags, and many other fancy features. I only discovered recently that she had still been using the app as though she did the day she started using Notes, which must've been c. iOS 6. She didn't even notice the top-left "< Folders" button.
Apple's design language is "Clean" and "Modern", but often fails to convey to non-technical users that a even a button is...a button, since iOS/iPadOS use colored text with no background to convey that something is a button.
---
One other example was a mistake I made while configuring a web browser for her. I absent-mindedly turned on "Hide panels automatically", and it wasn't until I figured out what my mother meant when she complained "SOMETHING POPS OUT AND THEN JUST VANISHES" of what I had done wrong.
As I understand it, imagery is (ideally supposed to be) language agnostic, like the "icons" for events at the Olympics, though it doesn't always work out as intended.
Somehow this has all gone wrong through: no text so the first time you use it you've no idea what the icons mean, they are all the same color and pretty much the same shape so you don't even get the speed of recognition.
So either the design team is ignoring 20 plus years of research or they just don’t know what they are doing.
My go to design manifesto is making any screen idiot proof. Mistakes can always be made, but you can safely back out from it and you always understand the consequences (aka you learn)
The design team has been ignoring Apple’s own HCI guidelines for years now
Guidelines for thee, but not for me, I guess.
Then Apple changed the UI a little bit. I can't begin to explain it to her over the phone in my second language, because for starters, I don't have a non-updated device to be able to compare and find the exact difference. I felt a bit of a jar and was able to roll with it, but couldn't tell you what the difference is exactly.
LTS (guaranteed non-change for existing features, at the cost of possibly not getting all new features) for UI would be amazing.
And do not get me started on the drama involved in an iOS major version update and the requisite iCloud password entry to even start the phone. She has the password written down, but since it's helpfully hidden as she types, she can't see that she was a letter off or missed a shift. I ended up sending her to the Vodafone corporate store with her password and 3 reset answers to have one of them type it in for her, as we're on the other side of the country, and she kind of needed to be able to make and take phone calls.
I just got a new Android phone that iterated 1 version in the operating system and product. The old phone had a persistent triangle symbol to press for "back". Now that symbol is gone and I'm supposed to swipe from the edge of the screen for the same "back" function. Except, lots of apps use a similar motion for other functions, including Firefox for closing tabs. So, now I'm constantly swiping a few milimeters too close to the screen edge and going "back" when I want to close a tab, with few clear visual clues as to what is going wrong. This is just 1 of many UI fails on the new phone, very frustrating for me and I would guess extremely and unnecessarily confusing for "normal" people.
I suppose outdated features like good grip and removable battery are a bit much to ask for.
People don't have time to dig into usability details, instead they get an app because it gives a nice looking first impression? Could "rewards" in a company work in similar ways -- impressing managers with sth nice looking?
On multiple occasions when explaining computer stuff, I explicitely said something like "don't write anything down, but try to understand the metaphor", because the software is a moving target. I've been also asked about "a manual for this computer", when they actually wanted a printed manual that explains all the software on the computer.
Modern day electronics aren't really made for most people who are born before about 1960. Understanding all metaphors intuitively probably requires having been exposed early in life.
If someone had to design a process to mock and torture the elderly trying to use modern devices, that's the one. Along with messages that time out and unexpected events that steal focus.
The UI on most mobile devices are terrible in one way or another. There are zero discoverability, things will hide, lock, block or disappear with no clear way of getting back.
Often I feel it’s easier to go to the computer. As an example: I cannot use the banking app on the phone anymore. In an attempt to make it easier to use, they hid/removed the features I used, such as “how much is in my account right now?” or “pay a bill”. That stuff is now hidden in a complex menu system. I can manage the MasterCard I don’t have though.
Designing good UI is an incredible skill, one that few people gave, and one even fewer are willing to pay for.
I don't think it's even just that. If any of these companies did usability tests they'd discover quickly enough that their designs don't work. I guess they just don't bother.
I have worked in software development since the mid 90s, often freelance so I've probably been at 20-30 companies in total. All of these companies produced software that had some sort of UI. I think only a single time was any usability testing done, i.e. get a normal person sat in front of the software and get them to perform a task and see if they can figure it out on their own. Normally the process is that the designer asserts that this particular way is best, and that's the way it gets implemented and that's what the customer gets to use.
Part of the problem imo is that everyone thinks "how hard can it be?" and that they have good ideas for UI design. They therefore aren't interested in reading Cooper or submitting their brainwaves to even peer scrutiny.
What does that mean? (Not a native speaker)
Don't Make Me Think is another good book I think :-)
The question is should there be a middle ground between keeping the product trivially simple, or cramming an increasing amount of features to satisfy power users. Either extreme works well for a specific subset of Apple's user base; a middle ground is more prone to leaving everybody confused and/or unsatisfied.
I have zero UI design experience so can't really chime in. Maybe a toggle option inside a menu that swaps app modes? Leave it off and you have a very basic Notes app; toggle it and you get all the bells and whistles, tags, folders, parsing... But this totally causes the problem you describe in your last paragraph.
Many UIs today are objectively bad and unintuitive (like the Gmail example in the article). UIs should always strive to eliminate the "don't know what you don't know" quadrant: common sense should be enough to navigate the system safely. Perfect examples are the Gmail example in the article, or the "hanging up the phone doesn't hang up the phone" problem of landlines[0] where you can do "everything right" and still get scammed. The judgment metric here is whether a decently intelligent people could fall victims to these; they can, so they're objectively bad UIs. They violate common sense.
Then there's another group, that severely struggles with computing abstractions. (These can be perfectly smart people in other areas). They can have slightly degraded motor skills and end up swiping or tapping inadvertently and getting lost. The kind of people that thinks a locked phone is "turned off". That get confused when Control Center or Notification Center show up, because the swipe was inadvertent and they don't understand the abstraction ("where did my video go?").
It is utterly impossible to design the same UI for this group of people and for everyone else. For them, you'd ideally permanently dedicate a fifth of the screen to a never-changing menu, with common operations (copy, paste, switch app, see notifications, check email, find app). For most people, menu bars would be terrible on phones and tablets since they'd need to be always visible, and big enough to be tappable, and would waste collosal screen space; but some people would prefer that.
The UI would need to have a permanent banner that explicitly labels the UI context, essentially a "permanent tutorial mode" that explains computing abstractions, for example with a banner that says "YOU ARE CURRENTLY VIEWING RECENT NOTIFICATIONS. [GO BACK]" (otherwise, you get inadvertent swipes, and "hey, where'd my video go!").
Designing "one UI for everybody" is hopeless. This is an obvious accessibility issue; and I don't understand why no company is building optional "tutorial modes" into their UIs since I'd assume the amount of people struggling with computers is a lot higher than the amount of blind or paralyzed people.
[0]: https://bc.ctvnews.ca/beware-of-the-delayed-disconnect-phone...
It is annoying they ask it every time but there is, in fact, a different option: option to call your phone (which most people have) which could have lower latency and higher reliability. I have succesfully used it in places where internet is spotty but adding an extra step to join a call is too much.
No ads (just checked with an adblocker turned off), and the same link always dumps you in the same always-active room. As a bonus the whole thing is open source.
No, I don't work for them or have any interest whatsoever other than being a happy user.
Finally I used a little relay board connected to a couple of GPIO pins on the Pi and programmed that to turn off and on the Pi. The relay board was remote controlled (infrared, worked fine). I used a small, but not too small, remote control with one single big red button. When a scheduled or agreed (maybe by a phone call) meeting was due, my father pressed the button and the TV switched to the Pi HDMI (turning on the TV if it wasn't already on), showing the Jitsi room. With maybe grandchildren and great-grandchildren, and my parents could just sit in their chairs and watch and talk via the TV. When finished my father pressed the button again, and I had programmed the Pi, as part of its shutdown sequence, to switch the TV to the other, normal HDMI port. It's possible to command the TV to switch inputs, via commands to HDMI, unfortunately it's not possible to switch to antenna input but my parents were on cable and used an HDMI port for that. So with this setup they would go from the Jitsi room to whatever they were watching before. Though the TV would be left on even if it was off before they connected - I didn't find a way to control the TV that detailed.
This worked well, as far as it went, the issue I had was that it wasn't practically possible to set up a power supply for that little relay board so I used a couple of 9V batteries instead. But it turned out that the board would suck the batteries empty in no time. So, as a prototype, it worked, but I would have to make a proper power supply for that to be fully useful. After a few months my parents had to move to a care home so the project was put on a shelf.
Even as a software delveloper, I would be delighted to use that, for the elegance of the concept and not having to dig through menues, toolbars and whatever else.
In my opinion, it's practically an insult to provide software or a "service" that essentially demands the person interacting with it slog through countless arcane or obtuse interfaces which could have been totally simple, concise and straightforward. There have been literal decades of prior art on subtly nudging a user through the most obvious and "least surprising" ways to complete their intended task.
I don't know if it's just me, but even as an "IT person", I never understood this "connect to audio" phrase, I just learnt that it is required for calls...
If it's a private meeting, you're going to listen only, but
you're at a public place and didn't yet plug in your headphones?
Also Zoom on PC is usable, Zoom on phones is awful
But for minor stuff/fixes it's easy to slip something that's awkward or not very usable.
Or a legacy interface is still being used (because the developer thought it out - since the company was smaller, or a specific screen was overlooked) and that's not a great interface
All using the same old over dubbed Musk videos from years ago to sell me trading software which they could easily detect with their own Content ID but they choose not to.
So I gave away the goods thinking everything was good to go.
When it bounced, I rang up and complained and they did nothing, just shrugged it off.
Story ends like this though: caught the thief with the Stripe IP audit log, police raided his house, found hundreds of other items but I never managed to recoup the loss, because mine was gone. I still think that it was Stripes fault because the UX on the email (even the green banner) made it seem like everything was good to go.
(I routinely tell everyone to avoid Stripe now and go with PayPal, someone from Stripe feel free to reach out and change my mind ..)
Ended up switching to these guys in Melbourne, never looked back: https://pinpayments.com
If you were selling high dollar electronic items or similar online, in my opinion it would be reckless to not implement that as a firm policy, which is fairly standard with high fraud risk vendors such as for photography equipment.
As a purchaser, I know that I've been on the customer side of this many times, ensuring that whatever small, high value electronic thing that I was purchasing from a certain vendor was being shipped to the address which is also set up for my bank and credit card bill.
Payment providers generally have heuristics to mark transactions as successful when there’s a high chance they’ve been finalized, but unfortunately this sometimes fails. In theory the final arbiter is the court system, but obviously that also has its limitations, as you encountered.
TLDR: It’s annoying, but I’m not sure any other provider would have actually done any better here.
Porn is legal, and should not be discriminated against, but that's beside the point. The business in question was providing 100% legal services for adults, but nothing to do with either porn or prostitution.
Are you saying it is ok to discriminate against a business just because their services are oriented towards adults and not children? If that is the case, then Stripe should also discriminate against "straight" bars and pubs, which is not the case.
When I lodged the report (in person at the police station), I was able to find the courier job on Airtasker and provide the police with the phone number of an exec at Airtasker that I reached out to, and with the job ID and the IP address of the organiser who was using card fraud (from Stripe). They took the case straight away because there was a strong witness (the courier) and a strong lead on the organiser due to building IP trace from the telco (a young kid living in their parents basement).
It took them only about 2 weeks to get a permit to raid. The IP trace was essential because they had the courier deliver it to a fake address in a nearby suburb, where they impersonated the householder.
(Oh my, has it really been that long?)
I think the whole principle of "anyone who knows your email address / phone number can contact you" was already obsolete over 20 years ago. Access to my inbox and ringer should be by revocable invitation only.
But this is what I hate most about Slack specifically and Electron in general. It’s so obviously a web app shoved into what kinda looks like a native window. But all the behavior is webpagey, except not in my browser, which I already know how to use.
Here’s a fun one:
Click in the conversation history panel. Use your “select all” shortcut. Despair.
Arguably, email addresses are (much) simpler to parse than postal addresses (including thing's like c/o, post boxes, etc.)
Both are equally easy to fake. The difference is sending fake bulk postal mail is much more expensive than email.
Detecting scams like this is a skill and some people - like elderly or disabled people - just aren't good at it. It doesn't help that some legit businesses are officially using gmail/hotmail/whatever addresses.
Email campaigns from companies are a mess. Even the company I work for sends official emails out from addresses at numerous 3rd party domains each using different mail servers. They often go out with verbiage nearly identical to what I see in phishing emails. They've contained links that point to URL shorteners or some other random 3rd party site that we don't own with URLs full of unintelligible tracking info.
I deal with phishing issues almost every day. Most of the time phishing emails are pretty obvious, but I've had customers ask me if an email claiming to come from the company I work for was legitimate and even after looking over the message and the headers I couldn't give a clear answer. I've had several talks with marketing about it, and I've managed to catch a few horrific communications before they went out, but they aren't willing to stop sending from or linking to third parties.
Developer: Does anyone know why helpdesk@company.com is being flagged as a spam address? All of our customers are saying our support emails are ending up in their spam folder.
Marketing guy: Yeah does anyone know why our support and advertising emails are being marked as spam?
Developer: …never mind.
It still doesn't justify companymarketing.com and companyhelpdesk.com though.
In many cases, no. They simply see that it has Venmo (or whatever) in it and assume it must be legit.
I've tried to explain this exact thing a few times. Not even sure I managed to get them to understand that a big company wouldn't use Gmail, but rather their own domain.
I mean, you don't. You stop using their company, and you let them and everyone else know why. Vote with your dollars or with your feet.
(It's actually quite the opposite of what is going on with URLs, where everything is suppressed but the core domain name. Here, the originating domain and user is suppressed. It's more like showing the document title in the location field.)
I agree the email situation isn’t great but it is also more complicated: lots of legitimate companies send emails via third parties or otherwise want to put a name quite different from the email (e.g. mail chimp but also google docs comments appear to come from the commenter rather than some big id email address), so it isn‘t as simple as showing the full address only and users may learn to ignore the full address if it is fully of random-looking letters/digits. And email protocols complicate it further because there are ways in which the from field may not even match the actual sender, though that isn’t such a problem with gmail. I definitely do hope things will improve, however.
"com.google" is what you need to see since it tells you who's really in charge of the content.
Particularly on mobile where I'm writing this I currently can see at most "news.ycombinator.co..." in the address bar. Could be a lot after that, how would I know at a glance?
Google and Mozilla could make substantial progress on this today by just showing an extra bit with the start of a domain name in right-to-left reading order.
If I add more subdomains, it still displays the label and the extension in priority, the additional subdomains are faded and hidden on the left.
This seems sane to me.
What we really should be doing is automating what I do when I get an email from a new domain that might be legit. Look up the DNS info so I can confirm it's the company they say they are.
Yes. They're obfuscating the mechanisms that can be used to assess trustworthiness so they can sell it back to us as some kind of reputation or verification product.
Email is a perfect example. If the from address wasn't moved around, hidden, and obfuscated, it would be easy to tell people "make sure Venmo emails are from @venmo.com" and that's the thing everyone would look for. Instead, there's an entire generation of people that don't know how to identify a from address and it opens the door to a paid verification platform instead.
In this case, the top priority should be display name, (verified) source address and time of reception. The To and BCC line is not that important, thus can be folded under description such as "To you and another...".
I hear that product design in Google is data driven, I'm not really sure what UX data Gmail team has been consuming.
bcc in inbound mails?
I agree that more information is generally better, except that people often learn to ignore extraneous information in UIs, and in most cases the full address of the sender is not important.
And what makes these scams successful may not be lack of information in the UI, but something else. For example, users not recognizing the significance of the sender's address, or not paying attention to it at all. People have never been good at recognizing email scams, which is why detecting them before they get into the user's inbox is the best solution I know of.
The author may be right, but I would not take it for granted, and would want to see some research done to support this.
...or at least that's my theory, but there's plenty of evidence.
We are so focused on "simplifying" everything... to what end? Maybe it's actually good for people to learn the thing they're using to some degree rather than hiding the functionality away because it "looks cleaner".
It’s email. They hide the forward and reply all behind multiple clicks. Where is the Subject? CC? BCC?
I get that grandpa and grandma benefit from removing some extra functionality for usability.
The worst is that my Google Workspace account works the same. How can you ship this to serious enterprise users?
Without that Venmo logo the whole scam is rather obvious. But hey, anything for clicks I guess.
Edit: Also obvious from the times of the screenshots. The email was received at 9:47am, the screenshot not showing the logo was taken at 9:49am. The screenshots showing the venmo logo however weren't taken until 2:23pm and 2:50pm.
The platforms hide behind an EULA, the police are both disinterested and powerless. I've reverted back to good ol' "Meet me at $place, bring cash." Preferably picking a place like the police station lobby.
https://duo.com/decipher/chrome-and-firefox-removing-ev-cert...
Better to teach people not to trust email and to check the source of truth themselves. In this case they should check their bank account and verify they received a transfer (or their venmo/zelle account etc).
It is fair to criticize some of the obvious misses though - these algorithms and heuristics are clearly pretty bad.
(I don't know whether there is a standard behind it or if it is some kind of manual certificate pinning.)
Weather it's green or red, it's often not even labelled what green means or what red means. Like when you see these COOKIE screens. If you don't click Accept All you click "Adjust Choices" And then you see a bunch of toggles that look either all on or all off. But they are simply labelled with "Targeted Cookies", "Personal Cookies"... But if it's ON does that mean YES Block such cookies. Or is ON mean "Allow these cookies".
Really confusing.
It's not like they're going to try to fix that either.
I still do not understand why designers don't like checkboxes.
Internet makes a lot of things easier, losing money included.
Though sadly, on some (most? all?) platforms, even that isn’t a guarantee, as some forms of payment can be rescinded. Or, the notice is communicated as “received” when it’s really more like “requested and processing” (much like banks crediting you for a deposited check, even though it takes weeks for a check to fully clear).
And then there's the challenging of displaying the actual email address rather than just the label, which is usually a name. It's ridiculously bad UI and any program manager that tries to hide the simple and necessary email addresses, that we type and use, and are the closest thing to "security" that is possible with an incredibly secure system... well those program managers are not doing their jobs and are causing great pain in the world.
Software UI design is a legal frontier waiting to be cracked, and many corporations-as-people are going to jail and/or be shut down when this train gets rolling. Back when Prohibition had bathtub gin making people blind is the same type of crap taking place today with fraudulent and simply stupidly designed user interfaces.
People notice things if you give them the chance to, and they will learn from it too. Removing things so they don't notice will only keep them ignorant. Here's an interesting comment tree related to that, around the similar subject of hiding URLs: https://news.ycombinator.com/item?id=23516774
3. calendar. i hate this app. from the bottom of my heart. its impossible to delete all the instances of a recurring event, doesn't have a decent monthly view. clicking on an event in the view doesn't open it (why?), changing the time never works on all the instances of a recurring task, some reminders just appear twice? it's unusable. alternative-install an open source calendar from fdroid. those are better. and you can export your data easily.
4. calculator. it seems to think in stupid. big bold buttons (okay, should be optional tho) taking up most of the screen, can't do anything remotely complex. no way to plot stuff, theres lag on the UI. its just freaking dumb and no one asked for it.
5. photos. welp, promised me free storage forever. used all my data to train some AI models. then took back the storage. this one's on me I guess.
6. drive. slow and filled with needless animations no one asked for. really basic things are missing or hand to find. can't open a terminal to edit files. alternative sync thing, a self hosted server.
Has anyone considered the real scam is using people like monkeys pushing UI buttons for carrot sticks?