Establishing secure connection
wellsoffice.wellsfargo.com
wellsoffice.wellsfargo.com
So we wrote a perl script that printed out a bunch of platitudes like these, while printing out an ASCII "progress bar." It had some randomly determined sleep() calls in there to make it seem like it was doing something.
Optimizing priority queues...
Recalculating scheduler lookup tables...
Terminating unused system processes...
Recovering memory leaks...
Flushing network buffers...
Then it'd randomly pick a number X and report to the user "System reports X% faster."We called it "speed" and deployed it to the app server. Some folks started getting into the habit of running it every morning and swore by it.
- Like a documentary: http://www.youtube.com/watch?v=XZlWmYe8HM4
- Extremely dramatically: http://www.youtube.com/watch?v=bT2gfHU6yCU
There were clients that would always insist on making audio adjustments, for no good reason at all. They were paying to have their music professionally mixed, yet still insisted on making adjustments and changes. Finally my dad and his friend came up with a great solution.
Mind you this was prior to everything being digital, so what they did was they had a massive 24 track. (a really big machine where you can individually adjust the sound of each track) Well what they did was installed a knob that looked just like the other ones in the track, but placed it a bit lower and near to where the client would be sitting.
The client was then told they can adjust the "openness", or the "richness" by adjusting this rotating knob to a particular setting (remember, the knob does nothing, and isn't connected anywhere). My dad said clients would spend hours adjusting this knob until they got it "just right", and would make sure to let everyone know in the studio that knob was dialed in and to not touch it.
It's amazing how many silly things people have to do in all walks of life to placate the ignorant.
The solution he had was to leave one obvious minor flaw in the final design – a color which doesn't quite match, odd font choice, etc. It was a lighting rod for unnecessary fiddling and was quite successful for keeping the changes quick and low-impact.
edit found it: http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/...
http://www.codinghorror.com/blog/2012/07/new-programming-jar...
:)
- A theater director was putting on a new show about some workers in a factory. In the background he put a wagon wheel. Before the premiere the communist representative came to evaluate the show. It was usual that some random scenes would be adjudicated unacceptable and cut from the show. When discussion started the communist rep asked what the wheel, which was used in agriculture, was doing in a show about factory workers. The director argued that it shows the connection between proletariat and agriculture workers. A vigorous discussion followed at the end of which it was decided that the wheel should be removed. The director ended up being the first ever to not have any scene cut.
- A painter visited France and desperately wanted to bring back some modern art reproductions so that his colleagues, who where not allowed to leave the country, would get a chance to see them. But modern art was forbidden and there would be no way customs would let the reproductions in if they knew what they were. So the painter got also some nude reproductions. The customs people confiscated the nudes as soon as they saw them and let the modern art go through.
Audio really attracts crystal-power wackos, somehow more than others. I've had to dodge all sorts of completely idiotic thinking both in the digital and analog world. Hell, it's the whole business model for Monster Cable, as one example.
Video encoding is a close second.
He sleeps happy. I waste time happy.
Every time I meet my colleague in the kitchen what we talk about is how phase shift of 0.5 and has reversed the polarity which serialised the hyperplane clustering by 1.1
edit: I've seen this on too many financial apps to think it's an isolated incident. It's clearly a "thing" in financial apps (TurboTax.com does it all the time; I see it on my Bank app, lots of mobile apps, etc.)
There's gotta be a reason, even if it's wrong.
I wouldn't be surprised if the authentication process was taking long enough that a decision was made to add some sort of "loader" like this to make it appear like the extra time was absolutely necessary from a security standpoint.
It's a bit of a lazy decision from a UX standpoint, but it isn't entirely uncommon either: when you notice some action is slow, slap an animation in front of it.
Seriously, users will resubmit forms if the next page doesn't respond in a 1000ms - 1500ms.
The level of contempt of some developers is amazing, too bad they don't know UX 101
On iOS it's different, the developer knows the best.
Many users complained that they didn't like paying so much for this feature because it didn't really seem to be doing very much. Instead of trying to educate each individual customer about all the intricacies of the report they just added a dialog box that would display for ~10 seconds and step through a few fake progress messages. People stopped complaining about paying for the report, and I would assume that is because the progress messages made them feel like something complicated was happening.
My guess: it's hard to consider adults are less curious than children, but more confident than children. In biology: maturity = stop of growth
There are many other words and phrases available for us to talk about this concept that are well understood and do not need to be redefined.
While the results were 99.99% the same as from the slower solution, customers would think "it can't be right" or other things like that, and wouldn't trust the product.
We'd just give the result a day later. Fighting with customers expectations is sometimes very hard.
I ran into this while doing phone and ticket support back in the day and tried to get my coworkers to join me in an experiment but they refused. We could have learned so much. I wrote about it: http://rachelbythebay.com/w/2012/07/14/difficulty/
* Is it because we as users have been conditioned, through years of faulty software, to assume crap crashes/hangs when there are unexpected delays?
* Or is the majority of computing so fast and instantaneous that we can't bring ourselves to wait on something that doesn't have an immediate end in sight?
Most of users don't know what SSL is, but they sure as hell feel more secure if you have a big lock or a nice green checkmark in the top corner, especially if they're thinking about putting in their personal info or credit card number.
Full disclosure: I'm a founder of an online marketing company. :-)
Once I fell for a phishing link, and the first thing to tip me off was the loading indicator was gone/too fast. In that instance it saved my neck as I changed my password asap.
Maybe users who realize due to a missing indicator should be smart enough to avoid such a trap in the first place, but I was definitely glad then and can see how this could be an active UX decision with positive implications.
I'm not sure if there is a better solution that doesn't misrepresent what's actually happening. Users sometimes have heuristics about the way that systems work which might be inaccurate. In this case, the heuristic is something like "doing work correctly takes time; failure happens quickly", where work is keeping your credentials secure. The fundamental problem is that it is difficult for users to differentiate between work done poorly from heavily optimized work done well.
I was sad when Sims 2 and Sims 3 didn't include this little gem. A cool bit a humor while you're loading the game? awesome.
http://cs.brown.edu/~sk/Publications/Papers/Published/emcahk...
Please Continue to Hold: An Empirical Study of User Tolerance of Security Delays
I've used a few of their services before, and they are all horrible abominations from signup on through.
If I had to guess, there's a login page. When you submit your login, this page pops up and displays while the login is processed.
source:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<title>Loading....</title>
</head>
<body>
<p align="center">
<img src="https://a248.e.akamai.net/6/248/3583/000/wellsoffice.wellsfargo.com/ceoportal/DocumentumRepository/content/images/signon/messaging.gif" width="300" height="30" border="0" alt="Loading Status" /><br />
<img src="https://a248.e.akamai.net/6/248/3583/000/wellsoffice.wellsfargo.com/ceoportal/DocumentumRepository/content/images/signon/statusbar.gif" width="300" height="30" border="0" alt="Loading Status Bar" />
</p>
<script type="text/javascript">
var selfClose = function() {
self.close();
};
window.onload = function() {
setTimeout(selfClose, 10000);
};
window.onblur = function() {
selfClose();
};
</script>
</body>
</html>To be fair, they do have windows in their office.
I worked with the dev who wrote this at Wells Fargo
You can't say that and not provide more details.... You are obligated now.Not all work we do can be enjoyable, unfortunately. I bet this is a fun jab to bring up with him at parties. "Remember that time Wells made you make that security gif?"
What would be bad is if this page would accept a parameter to redirect you to somewhere, but it appears it doesn't do that -- it just closes itself. Presumably this page appears in an overlay that then closes itself.
We all know banks aren't trustworthy, but that's what they should be, and their goal should be actual trustworthiness and not false, theatrical crap like this.
Banks are all about theatrics in the service of image. They depend upon it, in fact. A bank that loses trust is a bank in danger of a run.
A throbber is theatrics. Fake progress messages are (excluding joke examples like in video games) a lie.
The steps of the gif are: -Establishing secure connection -Sending Credentials -Authenticating -Building Secure Environment
That's not too far off of layman's terms of what is happening when they logon albeit just not as slow.
If it provides a layperson the same sense of trust that a technical person would feel if they listed the technical terms, isn't this an accurate demonstration?
One example of this is shown in a usability study by the Baymard Institute on top ecommerce checkout processes [1]. The goal of the study was to determine best practices for checkout usability by testing the top 15 ecommerce sites. One of the more fascinating finds they made was that during the checkout process, users perceived certain fields as being more secure than others. Even though the fields were all part of the same form and on the same page, users still believed fields with a little lock icon were more secure than the rest of the fields! It didn't matter if the entire page was encrypted. Users would abandon the checkout process because the credit card fields didn't "feel secure" compared to the rest of the page.
To most of us, this looks like a frivolous feature suggested by a "UX monkey" (as one commenter put it) but don't underestimate the power of making users feel safe. For all we know, this stupid gif could have cut support calls 20%.
Then someone else from within your company must repeat a similar process to approve your action. So you always need at least two people within your company to perform any action.
Typically the CEO portal is used for wire transfers where security is pretty damn important--once the money is gone--its really, really gone.
On the other hand, whatever algorithm they're using for the handwriting recognition on checks is pretty amazing. I've deposited 100's of checks and I've only had to type an amount once.
The USPS also has the additional challenge of matching what you think is your address with what is actually your address. Very, very few people know their address.
If that's not bad enough, if you've ever had something arrive successfully, you expect the address that was used to work forever.
What parts of their addresses do people typically get wrong? Where can one go to find one's actual address?
https://tools.usps.com/go/ZipLookupAction_input
There are, occasionally, errors in the database. I'm trying to get one corrected now. If you find one, go to your local Post Office, find a supervisor, and ask him or her to notify "Address Management".I've been so impressed before by things like wrong addresses -- hell, one time I saw a letter with no address only my name and zip code. And it's not like I lived in a place where my mail carrier knew me. They've built a hell of a technology there.
It's the "Save & Exit" button TurboTax has. I'm sure that they are saving all info as it is entered, but users of QuickBooks, Excel, etc., I'm sure are used to having to save their data manually then exit.
I think all the guffawing at this progress bar is a little overblown. If a question or concern comes up in user testing multiple times -- "How do I know my connection is secure?" -- then why not put something in there that makes the user feel safer? What's the problem with that? Sure maybe it's a little overblown graphically but, c'mon, when you're a bank you need your customers to feel secure, in addition to actually being secure.
A much better security indicator would be something saying "This site is secure if there's a green area in the address bar [picture of what it should look like]. Click it to verify our identity.".
https://a248.e.akamai.net/6/248/3583/000/wellsoffice.wellsfa... https://a248.e.akamai.net/6/248/3583/000/wellsoffice.wellsfa...
:-)
But as a Wells Fargo customer, I've never seen it while using their website, and I use the site to check my accounts and transfer money between accounts once or twice a week.
But this is just a silly static image. What if the server takes longer than the image to load?
It also happens if you load the page then open a new tab. The previous tab will lose focus and close itself.
If the issue was transient, like a dropped connection to the database or memcached or some obscure deadlock, the "automatic" fixes worked as expected from the user's perspective. We, of course, still got the full error report to diagnose the issue.
I even have a few gems in our user feedback system where the users outright praise the "automatic error fixer" and they wish every website/app had a tool like ours.
"The salesman had been selling hydrochloric acid, sometimes known as muriatic acid. The industrial grade usually had a green tint caused by contamination with iron. The company that the salesman worked for improved its equipment at considerable expense and proudly began putting out water-white muriatic acid. The salesman immediately began getting complaints from customers who did not want that weak white stuff. They insisted that they wanted that strong green stuff that they used to get. So, for those customers, the salesman arranged to have a small nail dissolved in each jug shipped to them. Result: happiness."
http://news.ycombinator.com/item?id=2007385 (807 days ago)
And the corresponding HN discussion that followed:
(Apple's iOS is "deceptively fast") http://news.ycombinator.com/item?id=4047032
In this case, we have security instead of speed. That's not to say it isn't secure anyway.
Fun aside this portal uses two factor authentication with RSA tokens (that were promptly replaced after RSA token vulnerability was found).
Sounds about right.