My car, I don’t know or care how it works. It gets from point A to B, and works for me. I take it to the shop and they tell me it needs a new dilithium crystal and shabam-kapow drive, so I just shrug my shoulders and have the mechanic install what they tell me.

But most of us know enough to get around. That big block is the engine, that smaller block is the battery, and so forth. I pop the hood and stare at it from time to time, and know just enough to be informed, but not cause damage.

Even better yet is that everything inside of the car is so dummied down so that practically anyone can drive an automatic transmission car, use the turn signals, or roll down the window.

We (yes, WE) in the industry need to make this shift too. In general, make applications, operating systems, and of course security, essentially dummy proof. The things that we encounter most (like turning on headlights, or starting the car, or in this context understanding SSL or security in general…) those things, simply NEED to be made as straightforward and stupid proof as possible. And I mean reeeally simple

The other stuff “under the hood,” like certificates and encryption algorithms and whatnot, can be dummied up a bit, so a casually interested user can kinda-sorta understand what the little lock, or AES means…and if a “pro” needs to examine other stuff, they can look deeper and be able to.

The current state of technology – take SSL for example – is like asking the average Joe to hotwire their car every time they want to start it.

What if, instead of a yellow “Maintenance Required” light, you got only the error code when something broke down or needed service – and could push a button to get rid of it?

You’ve got a problem with 4593052-OBX32, Click OK to continue, or “No” to stop in the middle of the road until you can research and figure out what is wrong. If you click “Ok,” you might break down and be carjacked or experience other problems, but clicking “Ok” does guarantee that you’ll keep driving.

What would you do?
Click

Put this post under the “rant” category, but other industries adapt to their customers, but we don’t so much.

I call it geekisistance, we all suffer from it to an extent, but why?

One thought on “Users Just Don’t Get It…or Don’t We?”

  1. Walt says:

    The analogy breaks down in that there aren’t too many people setting up traps to try to break or steal your car. Also, the purposes of a car are very narrow and well defined – you need it to move, preferably in the direction you point it. In fact, pretty much anyone can learn how to make a car move, in a very short time. However, it’s another thing entirely to learn how to make the car move when there are other cars moving around you. Our whole user base knows how to make the web browser point to a web site. Not many of them have learned, or care to learn how to make sure it’s the right one.

    If you oversimplify the user interface aspects of security, you also create the problem that software components simply won’t work (e.g. if you make the security rules rigid and inflexible, such as not allowing SSL certs with a subject DN that doesn’t match the domain name of the site), or the interfaces ask questions that are so simple the user asks himself “well, what harm could this do?”. And even if you could manage to pull off making security very, very idiot-proof, people still won’t care. It doesn’t matter if the dialog box says “Error creating certificate path – subject CN does not match domain name” or if it says “This site isn’t secure. You should probably not do this.”, the average user’s response is going to be “Great. Now can I get to my bank statement please? I have to mow the yard and put the meat loaf in the oven.” It’s akin to someone in a car ignoring the “check engine” light and then demanding to know why there wasn’t any warning that there was going to be black smoke billowing out of the hood, or thinking that a red light is just a suggestion. Most reasonable people wouldn’t do that, but they don’t hesitate to throw out their credit card information to any web site on the Internet.

    Sometimes I think that trying to throw a technological solution at a problem of education and apathy will never work. Even though the inner workings of a car are hidden from view, and it’s easy to learn how to make the car move, you still have to learn certain things before you’re allowed on the road with the other drivers. It isn’t possible to do something to the car to make it safe for use by a 13 year old with narcolepsy…much like it isn’t possible to make a computer system secure for a user that just doesn’t care.

Comments are closed.