Well when even we, the cogniscenti, get tripped up cos the Passphrase input box was where we expected the Password input box, I think we have to make it as simple as possible- and .keep coming back to it, everybody knows what a lock and key is.
And don’t forget this IS different to your standrd username and password combo, very different, so we need to treat it differently
It’s the SAFE Network, not a bank account or a bitcoin wallet. You need to create a lock and key to access the SAFE Network. The visuals and uix cannot get any more simple and easy than that. My 94 year old grandmother would understand it just fine, and so do my 5 and 8 year old kids.
When I suggested safe above I had in mind ye olde treasure chest. Why tell someone where your treasure is buried; why lead them to your door. Security through obscurity doesn’t work but it helps.
The lock is half the puzzle; the key is the other; keep both safe.
This is not rocket science and the point has to be to keep it simple and ensure that everyone understands that they are in control - the bigger risk here as with bitcoin is giving power to people requires they act responsibly.
That is easy to test and probably should be tested with a focus group of 20 or so people , different ages, gender and so on.
I don’t believe it is important for people to know what things do or what it is in a technical way, I believe a user just wants to understand what the page want the user to do in the most simplest way possible. Just use something most people are familiar with and write a description, define the minimum requirements and so.
I don’t think a user should need to interpret what the input fields mean, it would be good if it just tells the user what kind of imputs it wants and then specified what is the minimum requirements necessary.
Absolutely, As I see it, we are just putting our collective suggestions in front of @JimCollinson to test with focus groups - when that becomes possible again
The key ;p is not to think… the lock is relatable as security; etc.
Introducing anything new, and beyond the bleeding obvious, has to be added to the collection of all else that is new… and new is difficult because it requires thinking. People are lazy; cater for everyone … provide something that is simple.
Lock and key, is simple.
You can argue if there are better names for two elements of input… but as above that resolves to skins. I would hope some iteration of snapp and browser and all that is SAFE, could have skinable UIs… that’s one way to engage the creative younger crowd.
How to create an account? Just use your imagination!
Doesn’t that sound like a winner.
I believe the key to create something good is to “think” as much as possible.
We are not responsible or could be hold accountable, there of we should not make any important decisions. It is up to the people who is responsible for the results to make decisions, we can provide suggestions but should never call the shots. Jim is very professional and makes amazing UX, he have my full confidence and should have our full confidence to make decisions
Haven’t read all of the thread yet so forgive me if this has been said. When I login to my bank online I have to put in my account number via the keyboard and then put in my account pin via the mouse selecting numbers from a grid that is randomized each time. The pin is sent via the snail mail upon creation of online access. I know thats technically the same as login and password. But that could easily be changed by making it:
Username
Account key / number or - SAFEkey / SAFEcode
Password / Pin or - SAFEpin
I do like the change from keyboard to mouse as it feels more secure. Like when we generate a random bitcoin address by quickly clicking all over the screen and typing random letters at the same time.
I am not a big fan of everything being via the keyboard, esp on mobile android using the “gboard”. Maybe paranoia on my part but I blocked “gboard” and installed an open source one from fdroid that supposedly doesn’t have internet access. For mobile users login could be via keyboard then touch, not completely secure but maybe moreso.
“Please keep your SAFEkey and SAFEpin private!”
Edit: Added a new option, which personally I like, SAFEcode and then SAFEpin…
With the thought of who wants to be doing long passwords on mobile… I wonder that truecrypt ; pgp; and the like, have options for a file you own that holds the long string. I’m no security expert and would be wary of doing that on a valuable account… hardware is a risk and phones are perhaps designed broken like windows… but for usability, perhaps a file you possess is one half of the problem??
The pin above perhaps local for securing the password file.
Totally agree. Haven’t read to the end of this thread yet but just thinking in the same vein as passphrase, what about “secret memory”? It’s what I think of when considering what a passphrase or even account secret should be. Everyone has a secret memory and a secret memory is not only unique to each person but usually highly secret. On top of that I feel the fields title explains very clearly what it is.
Admittedly it gets back into secret territory which was possibly an element in the account secret confusion. I had similar thoughts on how people would approach account secret, the main one being, where do I get one? Whereas secret memory or perhaps enter secret memory seems more terrestrial and personal therefore more self explanatory. The main problem I see with entering a secret memory would be remembering how it was phrased. Is it easy to distill a secret memory into a short and memorable phrase?? I’m not so sure but maybe a step in the right direction. Maybe others could try it, I will give it a go myself. Beyond that perhaps people would feel apprehensive about entering something so personal, especially if it was in any way incriminating? Would be fun to bounce ideas or see what you think.