Tuesday, May 15, 2007

Norton Internet Security Doesn't Just Work, and It Should

Norton Internet Security is sold as a turnkey system for novice users. They certainly need something of the sort (although a case can be made that security is now so important that it should be the operating system vendor's responsibility). Users need something that keeps the bad guys from hurting them, without requiring a whole lot of fiddling with, because they don't know how to do it. That's why they buying that product, right?

Unfortunately, Norton Security is written by geeks, who are unable to shed their geek mindsets and produce something that Just Works, as their users need it to. Here's an example of their doing it wrong.

Carbonite, as I've shown you on this blog, is an automatic Internet backup system that not only Just Works, but is my poster application for the Its Just Works movement. Carbonite, like many other applications, periodically updates itself with bug fixes and (we hope) improvements. When Carbonite communicates back to its Internet home site after an update, Norton security detects it and pops up the following box, which caused my wife to come running to me in panic:



If the ultra-smart geeks at Norton, who do nothing but eat, sleep, drink, and live security, can't figure out whether allowing Carbonite to access the Internet is safe or not, how the heck is my poor wife supposed to know? In fact, I MYSELF do not know whether this box is crying wolf, or whether it actually has detected something bad, such as Carbonite being hijacked by bad guys. Take that one step further, and I MYSELF don't know how I would even go about figuring out whether this communication is safe or not.

Norton seems to THINK that this situation is probably benign, as you can see by the "Low Risk" label and the recommendation of "Allow Always". And I think, or at least I HOPE, that they're right. But if that's true and the action really is benign, why is Norton bothering to ask me? It's the same confirmation mindset that I've decried over and over again on this blog. Rather than put themselves in their users shoes, Norton is forcing the user to put on security programmer shoes, and there's not a chance in hell that any user on God's good earth, and I mean NOT ONE SINGLE PERSON, can possibly do it properly. Instead, by crying wolf when no lupine creature is in sight, Norton is conditioning users to click "Yes" every time they see a security warning. They're making all users less secure. Bad idea.

Maybe Norton's lawyers made them do this so that they can disclaim responsibility if they actually do make a mistake. In that case, it wouldn't be the designer's fault, and I will hereby transfer my annoyance and scorn to the lawyers. But Norton messed up here, because they did not put themselves in their users' shoes, as they should have.

Wednesday, March 14, 2007

From a Reader, About Just Working

A reader named David (no relation) wrote thusly about stuff just working:

"I'm in the United Red Carpet Room as I often am. I just spent 45 mintues (of the 90 I had to spare) trying to log in to purchase a one day pass to the TMobile hotspot. These guys should be flogged in public in front of their families. Every time I didn't get the exact sequence right it would clear out all fields and make me pull out my wallet to enter my Amex details and much more information; over and over and over. I state again, I'm a Technology Manager...it should not be so difficult that I can't spend my money with these people. I buy stuff online all the time. It makes me hostile and makes me want to go back to Continental where intenet access is free in their club in the first place. Shame on Tmobile (I'll cancel my cell phone contract next week) and shame on United. Is their goal to make it so hard to use people will want to subscribe to their outrageous 20 per month access fee or just make it so difficult that no one will want to try so they won't have ! bandwidth problems? Please consider adding this to your suckbusters as this is a defcon 5 suckfest"

In addition, he writes, "I read your fine novel [not sure I intended it as a novel, but OK, I'll take what I can get], and as a development and project manager I made it required reading for my entire team. It's part of our mantra now, thank you for so deftly identifying what we all have known all along. We are in the process of reengineering an applictation (internal proprietary) which is a full on 11 on a 1 to 10 scale of sucking.

You may consider it added, David. Thank you for writing.

Monday, February 5, 2007

Another Application that Just Works, At Least To A Point


I said in my book that this blog would contain a Hall of Shame for bad applications. After further reflection, I think that it's more useful to praise good applications rather than only slam bad ones. At the very least, I'll make sure to show a good application alongside every bad application. And today I'll show a good app without a bad one for contrast.

Microsoft's Movie Maker application, which comes with Windows XP, gets lambasted in critical circles for its inability to do this or that complex but (to the reviewer) necessary task in piecing together a movie. Without considering its ability to do large and complex things, I am going to pat its designers on the head for making the simple operation of getting video from a camera onto your computer about as quick and easy as it can be.

Like every proud daddy in the world, I've been recording my two daughters' milestone events on video, such as Annabelle singing in her Kindermusik chorus or Lucy ice skating by herself for the first time. (Don't worry, I won't inflict them on you.) But my parents live a few hundred miles away from me, and naturally they love to watch their only two grandchildren growing up. I'd like to send them the video electronically which means first capturing it onto a PC.

I sat down one Saturday morning to do this for the first time, cringing mentally at the pain I expected to suffer from bad applications. I don't get to say this very often, but I was pleasantly surprised by how quick and easy it was, because Microsoft Movie Maker more or less Just Worked for this particular application, figuring out about what I wanted to do and doing it for me.

I plugged my camcorder into the PC using a USB cable, wondering which of the dozens of applications on my PC would get this done. XP's plug-and-play mechanism detected the camcorder, realized that plugging one in meant that the user almost certainly wanted to download video, knew which application worked with it, and popped up the following box, which saved me any amount of poking around:


A hard-core developer would no doubt say, "Platt, you dimwit, if you don't know which application you want to use, go back to playing Solitaire, if you can remember it, or better yet use your PC for a boat anchor before you hurt someone." But that's 100% ass backwards. It's not the user's job to know about the developer's application; it's the developer's job to know about the user's needs and wants. It's very hard for a developer to get that through his head, since he spends all day every day working on his application. But the user doesn't care whether his electric drill comes from Makita or Sears or Black and Decker. He only cares how fast and how well and how easily it makes holes, which are the true object of his efforts. I used my computer not because I wanted to capture video, and neither does one single person in the entire world. I wanted to HAVE CAPTURED video. And the sooner I get to that state, with the least amount of effort, the happier I and any user will be.

OK, video capture is what I want. Click OK. Next it asked me which camera, because it also saw the tiny webcam that I use for instant messenger, which sits on my PC all the time. This question was probably unnecessary, seeing as I had just plugged one of them in, the detection of which caused the wizard to start. But the new one was selected as the default option, so one click got me past it.

Next the wizard offered me the choice of where to put the captured video. A good default folder was selected, and decent default title provided. The title's text was even selected so that all I had to do was to start typing to change the name, I didn't have to click on the text box and select the text. That's about as easy as it gets.


The video settings page was next. This could get tricky, if the user had to think about technical options, but again, the wizard designers had abstracted the choices away. The options were clearly explained in non-technical language for users who had never seen them before (as I had not), and the correct choice for most users was selected as a default. Specifically, the explanation was written in terms of what the USER wanted to do, keep it on a computer or copy it back to a tape. Links to additional information were available to an advanced user, or one of the few who was interested in the capture process, but it didn't get in the way of the vast majority of us who just wanted to get the damn thing done so we could get on with something we really cared about, like watching Mighty Mouse ("Heeere I come, to save the d-a-a-y!"). A simple click on Next gave me the right settings.


The next wizard page asked which parts of the tape did I want, all or some? Again, no problem understanding what they were asking. Since I only wanted a part, I selected that.




Finally, up came the capture box. Then there was the box saying start, stop, with video controls. Again, the choices were well laid out. Step 1, click Start. Step 2, click Stop. Step 3, repeat steps 1 and 2 until finished. Easy. (OK, I'll inflict just one snapshot on you. Aren't they cute?)


The only piece that I didn't care for was the "Create clips when Wizard finishes" box. I didn't want to do anything else with the video, just email it. So this sent me into an editor which I had to cancel out of. (I think that's the editor that the critics don't like). All I cared about was the file that it wrote on the disk up to this point.

Lessons for designers from this simple interaction:

1. Your user doesn’t care about your application, often to the point of not even knowing the name of it. Never has, never will. It's your job to care about him anyway.

2. The items on the wizard pages were logically grouped, for example, information about the input device was on one page and information about the output file was on a separate one, even though that wasted space. The user had to deal with just one thought on any given page, he never had too many things to juggle.

3. The default options were logical. They picked what most users wanted most of the times. The meanings of the selections were clearly explained.

Lessons for users from this simple interaction: good, simple, easy-to-use software is possible, and at least sometimes does exist. Demand it. Use it when you find it. Don't settle for less.

I do not know how good or how bad a job Movie Maker does at the rest of its tasks. But at this simple task, it did an excellent job of Just Working. As Donald Norman wrote in The Design of Everyday Things: "… the next time you pick up an unfamiliar object and use it smoothly and effortlessly on the first try, stop and examine it: the ease of use did not come about by accident. Someone designed the object carefully and well." That's right. They made it Just Work.

Tuesday, January 23, 2007

No More Confirmation, pt 2: To Confirm Is Useless; to Undo, Divine

The common technique of confirmation, popping a dialog box into the user's face and asking, "Are you really Really REALLY sure you want to do that?" is evil. It's unfriendly, it's distracting, and it's completely ineffective. Have you ever, even once, said, "Whoa! I didn't want to do that. Thanks," and clicked No? Have you seen anyone do that? Have you even heard of anyone doing it? I haven't. It shouldn't exist. Anywhere. Ever.

Confirmation is so vastly overused that it has become completely useless. Because the box constantly cries "wolf!" like the shepherd boy in Aesop's fable, no one pays attention to it, even when it's warning you of something you really don't want to do. You cruise through it on auto-pilot, clicking Yes without thinking, an action the cognitive scientists call "chaining".

We might just tolerate the annoyance of confirmation if it actually made us safe, but research has shown again and again that it does not. On the contrary, mistakenly believing that a confirmation box will prevent users from making mistakes gives programmers a false sense of security. It keeps programmers from having to clearly explain to the user what he's doing, and providing a way to recover when he does something that he later regrets, despite having originally confirmed it.

No human being is ever 100% certain about anything; just ask anyone who's married. An application with undo capability recognizes and honors a user's humanity. One that lacks Undo is insisting that a user become something other than human to use that application successfully. Which would you rather buy?

Other operations in life don't require confirmation. Your car does not ask, "Do you really want to start the engine?" when you turn the key. The supermarket clerk does not ask, "Do you really want to buy these?" when you place groceries on the register belt. Programmers constantly ask for confirmation because they think users don't understand the consequences of their commands. That may be true, given the poor quality of the user interface. But confirmation doesn't solve this problem. If the user was confused when he first gave whatever command triggered the confirmation box, he'll be even more confused when he sees it.

But what if the user really has made a mistake? If you put a flashlight on the register belt with a package of the wrong size batteries, wouldn't an attentive clerk ask, "Are you sure you want this size and not the one that fits the flashlight you're buying?" A good user interface should and can save us from mistakes like that, but it won't happen by blindly and stupidly asking, "Are you sure?". Instead, a good user interface prevents the problem initially by Just Working. Perhaps the Web page selling flashlights would contain a check box saying "include batteries," checked by default. Better still, the flashlight would come with batteries already inside it, so it'd work the instant you unwrapped it and no one would ever have to worry about buying the correct size. Now that's a design that Just Works.

Another reason that you aren't asked to confirm starting your car or buying groceries is that these operations are easy to undo. You just turn off the key or return the unwanted item. Programmers often put "undo" capability in their programs, where it's the greatest design advance since the mouse. It takes an enormous amount of effort to make this feature work so that users don't even have to think about it ("easy is hard, the saying goes"), but the programmers who implement it are any user's best friends. I buy them beer whenever I meet them.

The worst confirmations are those of undoable actions, such as moving a file to the Recycle Bin, shown below:


It's much more efficient to fix the relatively small number of errors that actually do occur (for example, a slip of the mouse deleting the wrong file) than attempt to prevent them by annoying the user with a confirmation box every time (which are usually ignored out of habit). An ounce of cure is not worth five pounds of prevention, especially when what the programmer THINKS is prevention does not prevent anything.

The beauty of undo is that it allows users to explore a program. It's not always easy to understand a new program's operation from menu items and toolbar pictures. With undo, a user can try different commands, knowing that he won't damage something that can't be repaired with a few keystrokes. Programmers often regard incorrect user input as the act of an idiot who should have read the %*$#% instruction manual. It isn't. It is the primary mechanism by which the human species learns.

If undo is implemented correctly, then there's only one destructive operation in the entire system: emptying the Recycle Bin. Some would say that this operation should have a confirmation box, as it currently does. But even here, the confirmation dialog exists only to guard against another bad design, placing the "Explore" context menu item next to "Empty Recycle Bin." One slip of the mouse, sliding down three spaces instead of two, and you get the latter instead of the former. That's bad. Emptying the Recycle Bin should have a special action used for no other purpose, perhaps clicking on it while holding down some key. Better still, the Recycle Bin should automatically delete files after some configurable period of time so you'd seldom have to empty it manually. Don't you wish that your real trash cans Just Worked like that?

A good application should never ask permission. Programmers should provide undo capability, and not ask for confirmation. That's the way to write an applicatin that Just Works