UX and security aren't that contradictory

User experience is often described as being diametrically opposed to the objectives of security. Designers want a frictionless authentication experience, security specialists want to ensure a level of security commensurate with the risk of disclosure of secured information and capabilities.

To some extent that's true but not in every aspect and the contradiction probably comes down to opposing goals even within UX between actual UX or interaction (IxD) designers, usability "engineers", and user interface designers.

As a designer I want to reconcile the desire to make authentication and security of private or confidential information not be burdensome or onerous with over-the-top two-factor authentication or excessively complex (and unnecessary) password rules.

But security is a UX issue too, and I thought of what I hope is a good analogy:

The relationship between UX and security is like seeing a psychologist. You expect confidentiality and want assurance that your attendance and notes will remain private and not disclosed to third parties. You want to know their room is physically secure and hard to break into to steal notes. That's the "security" aspect.

But there's also a UX aspect. By having those assurances of confidentially and privacy you are then more likely to be frank and open with you therapist, to disclose thoughts and be more vulnerable than you might if you had concerns about their professionalism or privacy (for example if you were meeting your psychologist in a coffee shop).

Likewise in ICT there's the actual security of hardened systems, authentication, encryption, SSL, salting and hashing passwords, session destruction, secure deletion etc. But also a UX component:

Assuring users of the security and privacy of personal information and access to capabilities like Internet Banking, electronic tax and health records etc will discourage or encourage behaviours, and shape what people are willing to do and provide.

It's not just about slapping on the old SSL Secured padlock graphic (though that is effective and still used today, though often more subtlety in browser address bars) or explicitly telling users "This site is secure" but about making software feel secure, which is much harder, more involved, and sometimes requires decisions and meeting levels of quality outside the designer's direct control.

For example system outages raise concerns about system reliability and robustness. Broken images and links raise concerns about quality control. Just like a friend who says "Don't worry I'll handle it" and then fails to follow through, you want to maintain people's trust and not give them a reason to doubt you.

On the flip side, you may also want to take a broader view and train people to be more skeptical in protecting their private information and less naively trusting, like Australia Post's recent internal ransomware exercise.

So in conclusion, while UX does want to minimise obstacles and frustration for users having to run and grab their phone to get an SMS code, or force re-authentication every session ... there are also some common goals: Security wants to ensure security, UX want products and services to be perceived as secure.

要查看或添加评论,请登录

Nathanael B.的更多文章

  • Stop the daily status report

    Stop the daily status report

    Some other questions you might ask in the Scrum daily stand-up: What prevented us from finishing this yesterday? What…

  • It's not you, it's them

    It's not you, it's them

    User research is a crucial aspect of product design and development as it helps ensure that the products and services…

  • Objective and subjective design critique

    Objective and subjective design critique

    I was inspired by Laura Klein and Kate Rutter's excellent podcast What's Wrong with UX? and their discussion on…

    3 条评论
  • Thickening your design arguments

    Thickening your design arguments

    Replace "researcher" with "designer" and think how to apply this advice to how you support design recommendations and…

  • Change is always something

    Change is always something

    Change and disruption efforts never fail, they might have less impact than was expected or needed to meet an objective.…

  • On agile purists

    On agile purists

    Waterfall ensures productive use of people's time through detailed scheduling and resource management; Agile replaces…

    13 条评论
  • What could a UX'er do for you?

    What could a UX'er do for you?

    I have been the first UX hire for three-quarters of Australian organisations I've worked for in the past five years…

  • User stories as a three-way conversation

    User stories as a three-way conversation

    While teams often use the user story format as a wrapper for functional requirements, the idea was never to throw away…

  • Isn't UX just wireframes?

    Isn't UX just wireframes?

    Every designer has their own preferences and specialisation and must tailor their approach for their client and team…

    2 条评论
  • Response to "Five Habits That Could Get You Fired"

    Response to "Five Habits That Could Get You Fired"

    James Caan's recent blog post Five Habits That Could Get You Fired! popped up in my LinkedIn feed and after talking…

社区洞察

其他会员也浏览了