8 ms·
"No Dashes Or Spaces" Hall of Shame
- ilkhd2 17y agoGreat page - many of criticized resource are very useful.
- pg 17y agoBack in our Viaweb days this was my quick test for whether a competitor was worth taking seriously.
- GavinB 17y agoDid that actually bear out in which companies went on to be successful? It's an appealing notion, but I question it every time I run across a successful company that can't get it right.
- lkozma 17y agoLet me play devil's advocate here. Users who are not tech-savvy or those who are new to using credit cards online might be afraid at each step that they do something wrong. -Enter credit card! -Uhm, I wonder if it means with spaces or with dashes or just the numbers, I hope the money won't go to the wrong place If it says 'no dashes or spaces' at least it's clear and might be reassuring to the user that the designers have thought of the same thing as him/her, which sort of indicates that he/she is on the right track and hasn't screwed up yet. I'm not saying this is good usability practice, but it would be interesting to test different versions for user reactions.
- blahedo 17y agoIf that were the only issue, the instructions could always say "spaces are optional".
- lkozma 17y agoIn that case there would still be different possible ways to enter it. "without dashes and spaces" makes it unambiguous. Again, I'm not claiming it's usable, but sometimes interface design can be counter-intuitive.
- treeform 17y agoDo you think it is a still good test today?
- pchristensen 17y agoProbably - it's a good indication of thoroughness, user-orientation, consistent interface design, etc. All of these are crucial to new and growing businesses.
- prodigal_erik 17y ago"No spaces or characters", I'll have to remember that next time I make a form that shouldn't be used. I used to have a fifteen-digit number on a visa or mastercard (not amex), which was a little weird, but I was amazed how many vendors couldn't handle it. Aren't there standards for this stuff?
- benologist 17y agoI'm so glad there was like 100 examples, I wasn't quite certain what the guy was on about till the last few.
- chrisbolt 17y agoIt's a hall of shame, the point is that their presence on the list makes them want to fix it.
- ajuc 17y agoAlso - why do people disallow characters such as ,./:;'"[{]}\|-_=+ in passwords on theirs sites. I can't understand this. I would understand banning non-ascii, but normal ascii characters should be allowed everywhere. Now every site allows different subset ot such characters, so every site forces user to have different password to it, if user wants non-alphanumerics in password. I would like to have 3 passwords - trash password for social sites, etc; better password for e-mail; and good password for important things. It would be managable. Thanks to arbitrary restrictions I have to remember many more passwords. Which is bad for security.
- nazgulnarsil 17y agopassword advice: come up with a system known only to you that generates passwords based on what sort of site you're one. you can base it on the web address, the company name, general category, whatever. now feed that through your algorithm and you have a unique password for each website you visit. if you forget a password you can re-derive it, since there will only be a handful of possibilities. since you'll certainly have your algorithm memorized you never need to write anything down.
- ableal 17y agoThis is much better advice than the "3 categories of password" the GP mentioned. Actually, 3 categories plus derivation is good ;-) The other day I was glad of that. I bought a game, was asked to create an account, typed in a password at the site; then received a confirmation email with the password in plain text - which probably means they are stored in plain text, not to mention left lying around in mail archives. Just a matter of time until one of those sites gets hacked and their DBs circulated. (P.S. I did write them a polite note suggesting not doing it, and they seem to at least have stopped sending passwords in email; I don't have much hope about their storing hashes. Probably plenty of others less blatant but just as insecure ...)
- ableal 17y ago> why do people disallow characters such as ,./:;'"[{]}\|-_=+ Because there are keyboards other than the U.S. PC keyboard. The one I'm using right now, for instance, has '=' as shift-0. With characters echoed as asterisks, if there is any sort of problem with key mapping, the user will be locked out. And giving up or calling support.
- elblanco 17y agoAnd the truth of it is that it's like a 1 or 2 line data sanitization fix in most languages nowadays to normalize the data value to the expected one. 1) strip whitespace off the front and backend. 2) eliminate unexpected characters in the middle of the string like - or spaces.
- cliveholloway 17y agoWhy just stop at dashes and spaces? s/\D//g
- jerf 17y agoThank you, beat me to posting it. Never "filter out the badness", always "filter for only the goodness" then use the good value. Exhaustively enumerating the goodness is easier than exhaustively enumerating the badness. (I'd combine this with a check for length, too.)
- pwk 17y agoYou also don't need to ask for the card type (Visa, MasterCard, etc); it can be automatically determined based on the number.
- gommm 17y agoThat's true, but I think that users would probably be confused if they can't chose the card type...
- jamesbritt 17y agoI would want to know that my card type will be accepted before entering the digits. You don't need a drop-down for that, but the list needs to be someplace, and if it's part of the form it can be a sort of a CRC for user intent if the CC number doesn't pan out. Might make it easier to prompt the user to make a correction.
- jrockway 17y agoI have seen some Javascript that adds the logo as soon as you've typed enough digits. I thought it was a nice visual cue that the card type was auto-recognized. I think the logical improvement to this interface would be to put the credit card type after the number, and then have it be auto-selected. That way the user can select if he wants, but it will be correct by the time he goes to select it.
- Manfred 17y agoShowing a logo or a message is really easy, ie. http://github.com/madrobby/creditcard_js http://github.com/madrobby/creditcard_js
- uggedal 17y agoPaypal shows icons of all major credit card companies below the credit card number field. When you start typing the non-matching card types gets grayed out.
- 17y ago
- patio11 17y agoRelatedly: telephone numbers. (555) 555-5555 is understood by every American above the age of like six. Why can't your website figure it out? phone_number.gsub!(/[^0-9]/, "") prior to processing, pretty_print_phone_number(phone_number) in the view, and you're freaking done. Relatedly but of less obvious salience to most Americans: if you tell me to write my name in hankaku kana and I write it in zenkaku kana then rather than telling me to rewrite it, call your zenkakuToHankaku function on my input, see if it contains anything other than kana, and if not just coerce the input over. I have been on a crusade to do this at my day job.
- ars 17y agoTwo reasons: Force people to enter their area code. What do you do about international numbers? It's a bit more complicated, and the grouping is less obvious.
- nandemo 17y agoThe kana part is a pet peeve of mine. It also happens for the address part. The only site I recall that does the conversion automatically is Google Adsense.
- imd 17y agoWho else thought this would be a hall of shame for Unix apps that don't work with files that have spaces in their names?
- jrockway 17y agoAll of them. In Cygwin, my home directory is /cygdrive/c/Documents and Settings/myusername. This breaks fucking everything. I have to re-export $HOME as /cygdrive/c/DOCUME~1/myusername. Yes, Windows also sucks.
- jrockway 17y agoI am not sure that this is a hall of shame for implementors, it is more of a hall of shame for users. The first web app I ever wrote did reporting on NMR machine usage; the users were scientists with advanced degrees and years of teaching (and computing) experience. The way you specified the date range for reports was via two text fields; the start date and the end date. Originally, I used a date parser that would accept pretty much any input. You could say "yesterday" to "today" or "4-2000" to "9-2005", etc. I listed examples in the description text, but I had several users ask me exactly what the date format could be. When I showed them "anything", they were amazed, but claimed it was confusing. I changed the text to read "specify all dates in YYYYMMDD format, no spaces or slashes" and everyone loved it afterwards. I kept the intelligent parsing as an easter egg.
- nandemo 17y agoYeah, I wouldn't assume all those companies' programmers are simply incompetent. For all I know it might be a business rule and the programmers are specifically asked to do that kind of validation. I'd rather ask some of those programmers before writing a web page about it.
- Retric 17y agoIt's the company's job to get this right, not any one programmer.
- ableal 17y ago> the users were scientists with advanced degrees They were expecting to have to retype the date, after the program rejected their first attempt. That's the way it usually goes ...
- jrockway 17y agoI did try to measure this. It seemed like most people were entering perfectly reasonable dates; even things like "March" and "November" I have a feeling it's a case of not caring how to enter the date, and not caring to try a few and find out. Much easier if you're told exactly what to do, so you have to think, because apparently checking who used the NMR machines last week is not something people want to think about. (Fair enough.)
- deleted 17y ago[deleted]
- raganwald 17y agoMy beef is with credit card fields that won't allow dashes IN THE NAME FIELD (and yes, I am shouting). The irony of a web application that refuses to allow Tim Berners-Lee to use his credit card to make a purchase is mind-boggling. http://weblog.raganwald.com/2007/09/you-suck.html http://weblog.raganwald.com/2007/09/you-suck.html
- joeyo 17y agoThey frequently don't allow apostrophes either.
- joshwa 17y agoI used to have this problem (I have a hyphenated last name) when booking airline tickets up until very recently-- but it appears that SABRE and the airlines have finally fixed it! This probably has something to do with the new TSA regs that state that the name on the ticket has to match EXACTLY with the name on your ID. Unfortunately, my wife's full name still doesn't fit on her NY driver's license, meaning she can only travel using her passport as ID. I wonder how it must feel to have a reeeeeally long name (like some Indian/Thai/Indonesian 20+ character names), and how the airlines, TSA, and other ID-issuing authorities deal with this? (to say nothing of non-romanized names!) What does Seetharaman Narayanan's name (Photoshop engineer) look like on an airline ticket?