Myself, Sam & Matt went out to Sheffield city centre yesterday afternoon for a spot of user testing. It’s the first user test I’ve run in the wild, previous times have been with friends & family or work colleagues. It was an interesting afternoon and we certainly learned a lot. More…
Last Friday, Google replaced their colourful upper-case ‘G’ icon with a more subtle lower-case ‘g’ icon. This has upset a lot of users who prefer the old one. Personally I don’t really mind but what I found interesting is that the change has really impacted my browsing. More…
I popped down to the Slug & Lettuce on Wardour St last night for the Chinwag panel discussion on “Real World Usability”. It was a good evening but ultimately the free bar and comfy sofas didn’t quite make up for the lack of direction in the discussion. More…
Clickpass has just launched a new OpenID offering which aims to make single sign-in easy enough for the masses. It takes a rather different approach to OpenID than other sites I have tried. The first obvious difference is that sites must, in addition to supporting OpenID, add a special Clickpass button to their sign-in screen. Behind the scenes it also generates a new, unique OpenID URL for each site you use. This is an interesting extra layer of privacy as it makes you completely unidetifiable to the relying party (i.e. the website you are signing in to). I gave it a whirl with Plaxo but was shocked to find that upon clicking the Clickpass button I was taken to a page on clickpass.com which asked me for my Plaxo username and password!
Carsten Pötter has a more in depth post on this bizarre behaviour of Clickpass. He ends with this thought:
There have to be better solutions for making the OpenID experience more comfortable for mainstream users. OpenID is here to overcome the password dilemma of many people, even trying to be more secure. Giving away passwords to third party sites is contradictory and is giving the wrong signal to users.
A comment on that post from Clickpass boss Peter Nixey goes some way to explaining why they chose to do it that way:
We spent a lot of time talking about the ‘asking users for passwords’ problem. In actuality we don’t even pass the credentials through our server – they are submitted directly to the relying party but nonetheless is would be better not to ask for them at all.
It’s true that the form goes direct to the server of the relying party (it is used to send them the randomly generated OpenID URL) but how is anyone to know that? Half the point of OpenID is avoiding sharing passwords between sites. Most users probably wouldn’t think twice about entering their private login details into a third-party site (especially when presented as part of a login process) but that is exactly the kind if blind trust that we, as conciencious web developers, should be educating against.
Ultimately though I think Clickpass’s biggest problem will be getting sites to implement their special button. There are few enough sites that accept standard OpenIDs.
Error messages are often a cause of frustration and yet it isn’t hard to create error messages that are helpful and even make the user feel good! More…
Here at Plusnet we're always trying to use clever open source things to make our lives easier. Sometimes we write our own and make other people's lives easier too!
We're a Yorkshire-based provider selling broadband and phone services to homes and businesses throughout the UK. Winner of the ISPA 2010 'Best Consumer Customer Service ISP' Award, we're proud to offer the UK's best value standalone broadband.
© Plusnet plc All Rights Reserved. E&OE
Community Site News.. is powered by WordPress