3 ms·
Excellent post. I also hate all of these trends. Unfortunately a lot of them are in fact pushed deliberately as anti-abuse and/or security measures, where in bo
by alisonatwork 2y ago
Excellent post. I also hate all of these trends. Unfortunately a lot of them are in fact pushed deliberately as anti-abuse and/or security measures, where in both cases (just like passkeys) they primarily exist to make the company's job easier and not to improve the user experience.
For example in my current job there's a push to follow the trend of splitting username and password entry onto two separate pages. Ostensibly this is to make it easier to deal with SSO because then you can look up on the back end the user's configured authentication type and direct them to oauth flow or passkey challenge or whatever instead of password entry box. But the bonus side effect is that it also provides an additional layer of tracking so that you can monitor mouse movements, keydown behavior etc and use that to feed into a model that can detect scripted attacks then push a captcha in between or block the login flow altogether and send a security alert to the owner of the account etc. This is all in pursuit of protecting the user's account, but at the same time it makes everything more inconvenient and privacy-invading for real life legitimate users who just want to log in.
I suppose you could blame malicious actors for forcing the enshittification, but in many ways I feel like it's a failure of the service providers because they're building technical solutions that make it easier for them to detect abuse rather than thinking about what the users themselves might prefer. It's like all the bureaucracy that still exists nowadays around flying thanks to terror attacks that happened decades ago. The terrorists may be long dead, but their impact is still felt in how they have changed everyone's way of life! I'm not sure that's a win for the good guys.