3 ms·
I don't think they're even remotely right at all. There is no possible way to make a decent security system in a GUI that doesn't involve dialogs popping up in
by BrightGlow 5y ago
I don't think they're even remotely right at all. There is no possible way to make a decent security system in a GUI that doesn't involve dialogs popping up in some way. That's the essence of what a GUI is, if you don't like dialogs then you should probably not be using a GUI at all. Just to be clear here, the alternative suggested to showing a dialog seems to be to present the user some kind of MAC system, which are notorious for being confusing, complex, and really difficult to present to the user in a meaningful way. The way those usually work is that your application just quits immediately and the system pops up another dialog telling you to change the permissions elsewhere. In the best possible case, that's equivalent to asking "are you sure you want to actually use the application". If there is a way this interaction can be improved, neither you or the article really explained it well. That's why I can't really get behind these statements, but I'm open to changing my mind if it's explained well. It would be best to avoid the inflammatory and accusatory tone of the article, it weakens the argument.
Don't get me wrong, dialog spam is a real problem, but the solution with that is to improve the dialogs, make them more meaningful and cut out the unnecessary ones. Not remove dialogs entirely. If I'm having a private conversation and I accidentally open an audio chat application then I'll say no, I don't want to use the application now. That's about as meaningful of a dialog as you can get. I used to be in denial about this myself because I'm a geek used to messing around with manually configuring SELinux and such, but the mobile model of security is actually really good. It works for the majority of users for the cases they're interested in without being too intrusive. That's the sweet spot you want to hit with security models. Remember these are single user systems as are most laptops in use today.
I can't really agree with your second paragraph, I tried to use Arcan and didn't find it simple, easy to use, or convenient, nor did it have any remarkable ideas. It seems to be a re-spin of some really old failed ideas from the late 80s. But don't take it just from me, you should definitely try it out if you haven't yet. I'll agree that Linux in general is not simple or convenient, I also suggest trying to do all of your items with the latest MacOS if you haven't done it recently.
- AnIdiotOnTheNet 5y ago> There is no possible way to make a decent security system in a GUI that doesn't involve dialogs popping up in some way. That's the essence of what a GUI is, if you don't like dialogs then you should probably not be using a GUI at all. Really? A GUI to you is just constant dialog boxes? That sounds like some kind of hell. There are a lot of mechanisms of interaction in a GUI that aren't "OK/Cancel" prompts. Let's take file permissions as an example. I have a text editor, or a paint program, or an audio editor, and I want to open a file and work on it. One way to ask for permission is the mobile model "give this application access to your documents?", which is garbage. Another way is to open a file dialog that is controlled by the OS and have it pass in a file of your choosing[0] thus granting permission to that one file by active choice, and yet another way would be to have the user drag and drop a file from a file browser into the application window (or onto its icon), again granting permission via explicit user action. As I mentioned in one of my original links, RiscOS even used drag and drop saving, whereby an application desiring to save a file gave you an icon to drag to wherever you want to store it, which again could be handled by the OS and this the application needs no write permissions granted to arbitrary locations. Let's try something other than files. How about cameras? You could go the mobile route "let this application use any and all cameras on your system now and forever?", or you could have a mechanism where by pressing a hotkey (or something) you get access to a devices panel where you can put a check mark on an individual camera you'd like to use, or you could do something more like Arcan where instead of selecting a device you instead pipe a video stream into the application which may or may not be originated by a camera, perhaps by using some kind of GUI composition method similar to a what you see in DAWs. Sadly this space is relatively unexplored as far as I can tell, with developers mostly preferring "Ok/Cancel" prompts, possibly because they require a minimum of effort on their part. > I can't really agree with your second paragraph, I tried to use Arcan and didn't find it simple, easy to use, or convenient, nor did it have any remarkable ideas. I have never used it and have not even have a Linux Desktop installed on any of my machines for about a year, so I can't say. I'm intrigued, but not yet enough to bother screwing with Linux Desktop again. I would generally agree that none of its ideas are remarkable, or rather that the only thing remarkable about them is how none of them are really new, yet they're still practically magic compared to the current paradigms. > It seems to be a re-spin of some really old failed ideas from the late 80s Some things fail not because they are bad ideas, but because they were before their time, had bad luck, bad marketing, or other difficulties unrelated to their worth. [0] I believe the Flatpak project engineered something like this [1] Maybe that's a dialog to you, to which I say that kind of dialog isn't the problem.
- BrightGlow 5y ago>A GUI to you is just constant dialog boxes? No not quite. Usually a dialog is good to use when there is some unavoidable transition that needs input, or when you need confirmation for an operation that is irreversible. There are plenty of GUI programs which those apply to. If the operation is truly irreversible then you actually can't do much beyond OK/Cancel, think of some operation like "Empty The Trash". I agree that designers should avoid modal dialogs if at all possible, but in some cases a dialog actually is the best thing to do. The rest of your criticism is referring to outdated or unrelated concepts, or doesn't make sense to me. Drag and drop isn't done on mobile, and the concept of "load and save" is also obsolete there. If you want to load a file you just browse to it in the file browser, and save is supposed to happen transparently and automatically without any user input. Requiring a user to press an unknown hotkey or open some other application to pipe sound into it in order to access the camera is even worse than a dialog, that will guarantee you get bug reports from users saying that the application is broken because they get no sound by default. Even if you had that, you would still want to pop open a dialog informing the user of the hotkey and the need to press it, or you would want to pop open the "GUI composition tool" automatically within a dialog. So it's unavoidable in any case. This is an operation that requires some additional input before the application is going to work. That's exactly what purpose dialogs are supposed to fulfill. Does that explain it better? From my perspective, this space has actually been extensively explored, and dialogs still persist because they are actually useful and convey the information in the most relevant way. If you think the older X11 GUIs are cool, or you like visual programming languages, you might like Arcan, but it's mostly a spin on those concepts built in Lua. That was my experience anyway. I don't think there are any other Lua-based systems like that, that's its uniqueness.
- AnIdiotOnTheNet 5y ago> If the operation is truly irreversible then you actually can't do much beyond OK/Cancel, think of some operation like "Empty The Trash". I disagree, you can make the operation difficult to perform accidentally. Imagine you had nuclear missile silo, but instead of requiring a code and two people to turn keys at opposite ends of the room, you just had a "really end the world?" prompt. You even see this in UIs pretty frequently now, for instance having to enter the name of the thing you're deleting to confirm. > The rest of your criticism is referring to outdated or unrelated concepts, or doesn't make sense to me. Drag and drop isn't done on mobile, and the concept of "load and save" is also obsolete there. I can see why if you think I was talking about mobile. I'm not, I'm talking about desktop personal computing. > If you want to load a file you just browse to it in the file browser I am not aware of a single mobile OS that comes with a file browser. Instead all applications are siloed and storage is an abstracted black box. Is it on my device? On the SD card? In the cloud? > Requiring a user to press an unknown hotkey or open some other application to pipe sound into it in order to access the camera is even worse than a dialog, that will guarantee you get bug reports from users saying that the application is broken because they get no sound by default. Le sigh... only because that's the expectation they've been trained to have. It doesn't mean it isn't better to do things differently. It's the equivalent of saying "no, we can't make mobile OSs because people will file bug reports when they can't run IE and play Flash games". > Even if you had that, you would still want to pop open a dialog informing the user of the hotkey, or you would want to pop open the "GUI composition tool" automatically within a dialog. Dear god why would I want to do that automatically? Does Office throw up a dialog telling users how to save a file when they first start it up? Or how to copy and paste? No, they're expected to understand some basic concepts of how to use the computing environment they're working in already. Treating all users like illiterate idiots is a practice that continues to prevent us from having nice things.