14 ms·
Bad UI is causing people to get scammed
- onelovetwo 4y agoBTW, its exactly the same in Apple's mail app.
- einpoklum 4y ago
- readingnews 4y agoI agree with this. The UI is moving more and more towards not showing URLs, emails, addresses, and other things that might clue a non-savvy user into being duped. But who do we complain to? They (FAANG, etc) are doing this to increase usage and profits, right?
- lynndotpy 4y agoThis reminds me of the baffling decision when Windows started hiding file extensions by default.
- Forge36 4y agoWhat year was that?
- jml7c5 4y agoI believe it changed with Windows XP, so 2001. (Oh my, has it really been that long?)
- timw4mail 4y agoIt was earlier, ME or 90 SE.
- jml7c5 4y agoYou're right! My mistake.
- userbinator 4y agoWindows 95.
- jwilk 4y agoOut of interest, do they still do that?
- userbinator 4y agoYes.
- svachalek 4y agoWould a non-savvy user realize "venmoforward@gmail.com" is not a reasonable source address for a message that otherwise looks like it comes from Venmo? I think the whole principle of "anyone who knows your email address / phone number can contact you" was already obsolete over 20 years ago. Access to my inbox and ringer should be by revocable invitation only.
- mulmen 4y agoI hate how hard Slack makes it to copy a damn username. I get messages from people and try to look them up in the corporate directory but at some point it is just easier to type it in.
- delecti 4y agoI don't know if there's an equivalent on other OSs, but in most browsers in Windows if you hold down Alt you can select text in an otherwise clickable link.
- mulmen 4y agoCtrl-click on a mac at least gives the option. But this is what I hate most about Slack specifically and Electron in general. It’s so obviously a web app shoved into what kinda looks like a native window. But all the behavior is webpagey, except not in my browser, which I already know how to use. Here’s a fun one: Click in the conversation history panel. Use your “select all” shortcut. Despair.
- 0xbadcafebee 4y ago> But who do we complain to? I mean, you don't. You stop using their company, and you let them and everyone else know why. Vote with your dollars or with your feet.
- masswerk 4y agoEspecially in email, the clear name is rather a comment. Showing just the comment instead of the real data is negligent, at best. (It's actually quite the opposite of what is going on with URLs, where everything is suppressed but the core domain name. Here, the originating domain and user is suppressed. It's more like showing the document title in the location field.)
- masswerk 4y agoThe preference for real names in email clients is actually quite annoying. E.g., some of my clients are using institutional email addresses, which are used and processed by multiple real-person users with associated clear names. Every time, I mail to one of these addresses (not addressing anyone in particular, but rather to whom these may concern, which is the expressed purpose of these addresses), I've to go back to the address and to discard the auto-filled, nonsensical clear name (which may be the person using that address, I received mail from last). In some email clients, this may involve multiple steps, as they really want to show a clear name and a clear name only.
- donmcronald 4y ago> They (FAANG, etc) are doing this to increase usage and profits, right? Yes. They're obfuscating the mechanisms that can be used to assess trustworthiness so they can sell it back to us as some kind of reputation or verification product. Email is a perfect example. If the from address wasn't moved around, hidden, and obfuscated, it would be easy to tell people "make sure Venmo emails are from @venmo.com" and that's the thing everyone would look for. Instead, there's an entire generation of people that don't know how to identify a from address and it opens the door to a paid verification platform instead.
- dan-robertson 4y agoThe URL move is more nuanced than that, no? If you look at how modern browsers decide what to show you in the address bar, they often try to show you the hard-to-fake bit instead of the whole url, so you see notreallygoogle.com instead of google.com.search.q.notreallygoogle.com or notreallygoogle.com/http://google.com http://google.com and similarly you’ll see the punycode if the browser thinks the domain name may be trying to look like another one with confusables. I agree the email situation isn’t great but it is also more complicated: lots of legitimate companies send emails via third parties or otherwise want to put a name quite different from the email (e.g. mail chimp but also google docs comments appear to come from the commenter rather than some big id email address), so it isn‘t as simple as showing the full address only and users may learn to ignore the full address if it is fully of random-looking letters/digits. And email protocols complicate it further because there are ways in which the from field may not even match the actual sender, though that isn’t such a problem with gmail. I definitely do hope things will improve, however.
- XorNot 4y agoDomain names are just fundamentally displayed wrong - the left to right reading order doesn't prioritise the right information. "com.google" is what you need to see since it tells you who's really in charge of the content. Particularly on mobile where I'm writing this I currently can see at most "news.ycombinator.co..." in the address bar. Could be a lot after that, how would I know at a glance? Google and Mozilla could make substantial progress on this today by just showing an extra bit with the start of a domain name in right-to-left reading order.
- navjack27 4y agoEdge seems to be doing things right in that department. On my phone I see the whole URL and the lock indicating https.
- thiht 4y agoSame on Safari. If I add more subdomains, it still displays the label and the extension in priority, the additional subdomains are faded and hidden on the left. This seems sane to me.
- nirui 4y agoTo me, Gmail these days feels more and more like it's been designed by somebody who don't actually use email. In this case, the top priority should be display name, (verified) source address and time of reception. The To and BCC line is not that important, thus can be folded under description such as "To you and another...". I hear that product design in Google is data driven, I'm not really sure what UX data Gmail team has been consuming.
- someweirdperson 4y ago> The To and BCC line is not that important bcc in inbound mails?
- wildrhythms 4y ago100% We are so focused on "simplifying" everything... to what end? Maybe it's actually good for people to learn the thing they're using to some degree rather than hiding the functionality away because it "looks cleaner".
- mulmen 4y agoSimplifying makes learning easier. But there is a limit. The problem starts when the simplification removes critical functionality.
- foogazi 4y agoWhy not check your Venmo account instead of email ?
- dawnerd 4y agoLiterally the first thing I did when selling stuff on ebay. Would verify that payment actually went through. I did have a couple people message saying they 'paid'. I'm sure it works just enough to be worth the trouble.
- bombardier6789 4y agoIndeed this is what I thought after reading the article. While there is a point to the article, it misses the basics entirely. Internet makes a lot of things easier, losing money included.
- alistairSH 4y agoThis. Always check the app directly, never rely on email, SMS, of phone calls. Though sadly, on some (most? all?) platforms, even that isn’t a guarantee, as some forms of payment can be rescinded. Or, the notice is communicated as “received” when it’s really more like “requested and processing” (much like banks crediting you for a deposited check, even though it takes weeks for a check to fully clear).
- samemail88 4y agoSome non techie users might not think to do that since they received what appears a legitimate email from Venmo.
- jeff_vader 4y agoMy father avoided using any kind of computers until he was 68. The we got him an Android tablet. Not the best choice to be honest, but it's too late, he got used to it. He's now 77 and he still cannot distinguish what's part of Android OS, what's part of some application or what's just a web page in browser. All the popups confuse and overwhelm him. Somehow he still manages to take some photos of his plants and watches ton of YouTube. It's both fascinating and terrifying to watch him use his tablet. I do sometimes wonder how he'd adapt to UI like Windows 95/XP Classic.
- nmilo 4y agoThat's the thing about people who aren't "into" tech, they have no idea what all this terminology is. What the hell is an OS, an app, a browser, a website? My grandma was completely shocked when I told her that some $100 phone she saw at the mall behaves exactly the same as her $1000 Samsung flagship whatever. To her, the whole phone is just run by Samsung. If you start telling people like her to always check the domain name in the email sender field, she won't even ask, "what's a domain name," she'll ask, "what's email? You mean the Yahoo button on my phone?"
- karaterobot 4y agoI am skeptical that showing the sender address would prevent scams like this, because I suspect that relatively few people who would get tricked by this scam are likely to figure it out based on noticing the full sender address. I agree that more information is generally better, except that people often learn to ignore extraneous information in UIs, and in most cases the full address of the sender is not important. And what makes these scams successful may not be lack of information in the UI, but something else. For example, users not recognizing the significance of the sender's address, or not paying attention to it at all. People have never been good at recognizing email scams, which is why detecting them before they get into the user's inbox is the best solution I know of. The author may be right, but I would not take it for granted, and would want to see some research done to support this.
- aetherspawn 4y agoI got scammed around $3000 because stripe sent me an email saying “payment received”, but it was actually processing, and it was eventually declined. So I gave away the goods thinking everything was good to go. When it bounced, I rang up and complained and they did nothing, just shrugged it off. Story ends like this though: caught the thief with the Stripe IP audit log, police raided his house, found hundreds of other items but I never managed to recoup the loss, because mine was gone. I still think that it was Stripes fault because the UX on the email (even the green banner) made it seem like everything was good to go. (I routinely tell everyone to avoid Stripe now and go with PayPal, someone from Stripe feel free to reach out and change my mind ..)
- xwdv 4y agoYou have convinced me to never use Stripe and I will share this story to people in the future as to why.
- bombcar 4y agoStripe has reinvented check clearing fraud, how wonderful :(
- AussieWog93 4y agoI also ran into issues with Stripe, as their automated systems flagged my business as fraudulent and there was no way to call them or get a fast response. Ended up switching to these guys in Melbourne, never looked back: https://pinpayments.com https://pinpayments.com
- walrus01 4y agoIn this particular case, did the card billing address and shipping address match? If you were selling high dollar electronic items or similar online, in my opinion it would be reckless to not implement that as a firm policy, which is fairly standard with high fraud risk vendors such as for photography equipment. As a purchaser, I know that I've been on the customer side of this many times, ensuring that whatever small, high value electronic thing that I was purchasing from a certain vendor was being shipped to the address which is also set up for my bank and credit card bill.
- nikanj 4y agoMy basic assumption is that with online marketplaces, you inevitably get scammed. As a seller you get scammed out of your item, as a buyer you get scammed out of your money. The platforms hide behind an EULA, the police are both disinterested and powerless. I've reverted back to good ol' "Meet me at $place, bring cash." Preferably picking a place like the police station lobby.
- alistairSH 4y agoYep. I use Facebook to sell things. Mostly by necessity - Craigslist seems to have dropped way off in popularity while also increased in amount of scam/spam. But, I use local groups. Might take a bit longer to sell, but cash in hand, no shipping shenanigans, etc. One benefit of living near a city vs a smaller town, I guess.
- gerash 4y agoI agree that the fix is not to display the full email header for the "tech savvy" people. The real fix is some kind of reliable trust mechanism where the real Venmo account gets some visual indicator (pad lock, blue check mark, etc.)
- layer8 4y agoThat worked well for websites…
- bvrmn 4y agoAnd what did happen? Why EV is not used anymore?
- darkerside 4y agoYeah EV is something between a joke and a scam
- jwilk 4y agoBrowsers stopped displaying EV indicators in the URL bar. Barely anyone noticed. https://duo.com/decipher/chrome-and-firefox-removing-ev-certificate-indicators https://duo.com/decipher/chrome-and-firefox-removing-ev-cert...
- solardev 4y agoGmail has this for PayPal but seemingly nothing else. Shrug.
- userbinator 4y agoNo. The less we rely on Big Tech to think for us, the better.
- bentcorner 4y agoThat requires all clients to agree to some kind of standard. Better to teach people not to trust email and to check the source of truth themselves. In this case they should check their bank account and verify they received a transfer (or their venmo/zelle account etc).
- cloudking 4y agoThis is typically what happens when UX designers come up with a "beautiful" design, and test it in a small UX study with 5-10 people to get it approved. IMO, when you have a product with millions or billions of users, you have to assume that most users are not technically savvy and need to be hand held through your UX to avoid issues like OP shared.
- meristem 4y agoI'd say it is less about small tests and more about the cases and questions one is trying to cover during the usability tests.
- drekipus 4y agoAnother bad UI/ux problem is advertising standards. I had to go help my 70yo neighbour deal with Microsoft scammers after she clicked the "continue" button for her time scheduling form: https://ibb.co/CKCbRpf https://ibb.co/CKCbRpf Guess where the actual continue button is? Computers are hell for normal people. There needs to be some sort of standards both on the appearance of ads ("can't look like the flow of a page, must be ""clearly"" an ad") and the positioning of ads (must be in margins, can't use absolute positioning). After clicking this, it takes you to a Microsoft security product page looking website, forces itself to full screen, robotic voice blaring " your computer is insecure, please step away from computer" and a pop-up telling you what number to call to sort it out. She came knocking on my door with the Microsoft tech support on the phone. Thankfully she had problems with the run prompt, and wanted me to help. I just hung up, closed the site. And installed an ad blocker. And then people out there who support ads on the internet as they are right now
- andrei_says_ 4y agoI do weekly videocalls with my parents. My mother uses an android tablet. We've given up on zoom because the interface is too complicated for her. Currently using google duo. Some things that stop her in her tracks: - any control that requires a touch to activate and then disappears on a timeout - like all the controls for video apps. She takes 3-4 seconds to realize something changed and then 5 more more to start orienting herself. The controls usually disappear within 5-7 seconds. - any surprising prompt from the os throws her into helplessness and panic - updates that need a restart, etc. - anything that switches the focus away from the current activity. Why would android interrupt a live call with some BS, ever, is beyond me. - communications apps show a screen with names but that's often the log of past calls or a chat. She wants to just click a name and make a call. On zoom, going to her contacts required 2 or 3 clicks which were not intuitive for her, and so she can never initiate a call. - zoom audio needed active confirmation to connect to audio. On a tablet, where no options are available but the over-wifi audio. - her having to slide a control in order to answer a call. - anything that requires a reaction within 10-15 seconds - anything that uses (even widely accepted) technical jargon. She is not deaf or disabled nor visually impaired and yet the complexity of using this device presents serious obstacles. These are just from the top of my head. She doesn't browse or use a computer and I'm happy for her. TV and newspaper are enough and I just don't feel good about having her navigate a world of malicious predatory dark patterns. This makes me realize how used I am to not trusting anything online and presuming the worst by default - in order to protect myself. I remember how about a decade ago my dad wanted me to help him with an important email. Someone had emailed him to tell him he won a lottery in Britain. It took me a lot of effort to explain to him that it is a scam, that they've emailed everyone, automatically, (to him a simple email takes half an hour so he can't imagine so much effort going into a scam) and that despite them knowing his name... they don't really know him. The asymmetrical nature of malicious activity online is so... dishartening.
- EternalFury 4y agoThat's cute, but I am more concerned about losing my phone, which contains so many MFA means. If that happens, I'm not sure I will be able to prove I exist and that I am who I am. And even if you don't lose your phone, you should dread the near impossibility of ascertaining the authenticity of anyone sending you text messages, which are so often used as poor-man MFA devices.
- projektfu 4y agoWhy not use something like Authy that's backed up and has a recovery password? I just download it on my next phone and am good to go.
- throwawaysleep 4y agoWith all the credulous idiots out there, I consider scams just bug bounties on stupidity at this point.
- userbinator 4y agoNotice the ridiculous amount of whitespace in the UI? They clearly could have shown the full address but they don't. That's why I think stuff like this is entirely deliberate. They don't want you to think. They want you to live in a world where they make all the decisions for you --- and decide in the way that benefits them the most, not you. They want to filter out scam emails for you, they want to control your life. The phrase "don't make me think" is common in UX, but in reality, what they're aiming for is "don't let me think". Hiding everything and making it harder to discover the details is precisely to discourage it. ...or at least that's my theory, but there's plenty of evidence.
- niceWokr8 4y agoWhat was the technical excuse for people getting scammed before UI? Has anyone considered the real scam is using people like monkeys pushing UI buttons for carrot sticks?
- coding123 4y agoThis might be a slight aside but I can't STAND "toggles". Weather it's green or red, it's often not even labelled what green means or what red means. Like when you see these COOKIE screens. If you don't click Accept All you click "Adjust Choices" And then you see a bunch of toggles that look either all on or all off. But they are simply labelled with "Targeted Cookies", "Personal Cookies"... But if it's ON does that mean YES Block such cookies. Or is ON mean "Allow these cookies". Really confusing. It's not like they're going to try to fix that either.
- userbinator 4y agoIn that example, I agree that it is probably deliberate. I still do not understand why designers don't like checkboxes.
- shultays 4y agoI doubt seeing "onlinevenmoforwarderserver@gmail.com" would raise any red flags for your average non tech savy person that gets scammed, so making it more visible probably wont help that many people. And people that are able to tell if a mail adress is legit probably already knows how to expand that "sender's adress"
- userbinator 4y agoNo, on the contrary I think seeing it would be a red flag, especially if the user has been seeing what Venmo's real email address looks like and has become accustomed to it. People notice things if you give them the chance to, and they will learn from it too. Removing things so they don't notice will only keep them ignorant. Here's an interesting comment tree related to that, around the similar subject of hiding URLs: https://news.ycombinator.com/item?id=23516774 https://news.ycombinator.com/item?id=23516774
- LASR 4y agoGoogle has been completely infuriating over the last few years. It’s email. They hide the forward and reply all behind multiple clicks. Where is the Subject? CC? BCC? I get that grandpa and grandma benefit from removing some extra functionality for usability. The worst is that my Google Workspace account works the same. How can you ship this to serious enterprise users?
- pkz 4y agoA large email provider like Gmail could probably train a network to find emails that look similar to an official brand (start with payment providers). The client could warn the user that "Warning! This email looks a lot like it is trying to impersonate a different brand".
- shswkna 4y agoThe paid-for “Google Workspace” does mark emails that look suspicious. It also uses the well known Gmail interface.
- tsimionescu 4y agoThat's exactly what spam filters are. Since they are relying on heuristics and ML, they aren't completely accurate, unfortunately. It is fair to criticize some of the obvious misses though - these algorithms and heuristics are clearly pretty bad.
- noAnswer 4y agoSince a view years United Internet (mail.com, gmx.de, web.de) verifies some big players. So a email from Paypal, eBay or Postbank is visibly different from a standard email. (In the Web and App UI. Of course not if you use IMAP.) IIRC it has a individual icon and a green boarder. (I don't know whether there is a standard behind it or if it is some kind of manual certificate pinning.)
- epistasis 4y agoEmail UI is getting particularly bad. Trying to copy and paste email addresses is absolutely ridiculously hard. Oftentimes programs don't even understand the mailto: text that they insist on placing on clipboards. And then there's the challenging of displaying the actual email address rather than just the label, which is usually a name. It's ridiculously bad UI and any program manager that tries to hide the simple and necessary email addresses, that we type and use, and are the closest thing to "security" that is possible with an incredibly secure system... well those program managers are not doing their jobs and are causing great pain in the world.
- butz 4y agoI wonder how all those people building dark patterns today will be swindled in the future, when they get old themselves.
- shreyshnaccount 4y agogoogle, for all its money, makes shitty shitty UI, and not only is it shitty, it feels like its made specifically to make your life worse. lemme explain: 1. Gmail on phones -not only are there tons of minor design inconsistencies, oversight like what this article shows, theres also no effective way to organise your messages. there's an option to open calendar on the bottom of the hamburger menu (also inconsistent, this menu got removed from some other Google apps) it only works with Google calendar.
- shreyshnaccount 4y ago(cont'd, pressed send by mistake) ang i couldn't find the option to make or remove new labels in the app. alternative is TwoBird, much easier to use imo 2. phone - while this app is majorly okay, I am super annoyed by the giant list of ways to contact a person that hangs just under a contact.. (things like message with whatsapp, call with whatsapp, video call etc with all the different apps. its clutter, rather just have an option to open in app) doesn't really need an alternative tbh it's good enough 3. calendar. i hate this app. from the bottom of my heart. its impossible to delete all the instances of a recurring event, doesn't have a decent monthly view. clicking on an event in the view doesn't open it (why?), changing the time never works on all the instances of a recurring task, some reminders just appear twice? it's unusable. alternative-install an open source calendar from fdroid. those are better. and you can export your data easily. 4. calculator. it seems to think in stupid. big bold buttons (okay, should be optional tho) taking up most of the screen, can't do anything remotely complex. no way to plot stuff, theres lag on the UI. its just freaking dumb and no one asked for it. 5. photos. welp, promised me free storage forever. used all my data to train some AI models. then took back the storage. this one's on me I guess. 6. drive. slow and filled with needless animations no one asked for. really basic things are missing or hand to find. can't open a terminal to edit files. alternative sync thing, a self hosted server.
- shreyshnaccount 4y agooh yeah, and all the app icons look the same it's ridiculous and I don't want it. alternative- use a launcher, change your icons.
- bsenftner 4y agoBad UI? Criminal UI! I often have to stop using any software other than my development tools because consumer UI design is so riddled with dark UI patterns I get far too emotional about the mass deception I see taking place. Software UI design is a legal frontier waiting to be cracked, and many corporations-as-people are going to jail and/or be shut down when this train gets rolling. Back when Prohibition had bathtub gin making people blind is the same type of crap taking place today with fraudulent and simply stupidly designed user interfaces.
- krade 4y agoJust FYI, but that email is faked. By default, gmail will only show logos for senders automatically for domains with verified BIMI certificates. Since that's obviously not the case here, the only other way is to add the gmail address to your contacts and manually set an image for that contact. Or I guess the logo could have been added to the screenshot. In any case, rather misleading. Without that Venmo logo the whole scam is rather obvious. But hey, anything for clicks I guess. Edit: Also obvious from the times of the screenshots. The email was received at 9:47am, the screenshot not showing the logo was taken at 9:49am. The screenshots showing the venmo logo however weren't taken until 2:23pm and 2:50pm.
- wizofaus 4y agoThe fact you are able to receive emails that look indistinguishable from legitimate ones sent by the apparent sender is surely a problem with the email protocol, not really a UI issue, though certainly hiding the sender address is a part of it. Why we still communicate using a channel that does nothing to verify sender legitimacy in this day and age baffles me somewhat, and it really shouldn't be a difficult problem to solve (e.g. who browses the web without using https these days?)