security vs. ux

66
Security vs UX Deathmatch @ccollingridge @Avecto @nuxuk

Upload: chris-collingridge

Post on 13-Apr-2017

62 views

Category:

Technology


2 download

TRANSCRIPT

Page 2: Security vs. UX
Page 3: Security vs. UX

Security is human

We’re not making good design decisions

We can do better

Page 4: Security vs. UX

Security is human

We’re not making good design decisions

We can do better

Page 9: Security vs. UX

Chaoyue超越 PAN 潘

Page 13: Security vs. UX
Page 14: Security vs. UX

Alexandra Bolzer

Page 15: Security vs. UX
Page 16: Security vs. UX

Security is human

We’re not making good design decisions

We can do better

Page 18: Security vs. UX

Overloading memory

Page 19: Security vs. UX
Page 20: Security vs. UX

Jason Kottke

Page 22: Security vs. UX
Page 23: Security vs. UX
Page 24: Security vs. UX

Nihilistic password security questions (by Soheil Rezayazdi)

What is the name of your least favorite child?

In what year did you abandon your dreams?

What is the maiden name of your father’s mistress?

At what age did your childhood pet run away?

In what city did you first experience ennui?

What is your ex-wife’s newest last name?

What sports team do you fetishize to avoid meaningful discussion with others?

What is the name of your favorite canceled TV show?

What was the middle name of your first rebound?

On what street did you lose your childlike sense of wonder?

Page 25: Security vs. UX

Technically driven barriers

Page 26: Security vs. UX

Troy Hunt

Page 27: Security vs. UX
Page 28: Security vs. UX
Page 29: Security vs. UX

Relying on users making good decisions

Page 33: Security vs. UX

Not promoting good practice

Page 34: Security vs. UX
Page 35: Security vs. UX
Page 36: Security vs. UX
Page 37: Security vs. UX
Page 38: Security vs. UX
Page 39: Security vs. UX
Page 40: Security vs. UX
Page 41: Security vs. UX
Page 42: Security vs. UX
Page 43: Security vs. UX

Security is human

We’re not making good design decisions

We can do better

Page 45: Security vs. UX
Page 46: Security vs. UX
Page 48: Security vs. UX
Page 49: Security vs. UX
Page 50: Security vs. UX
Page 51: Security vs. UX

@Elgarfrombeyond

Page 52: Security vs. UX

Encourage

two-factor

Page 53: Security vs. UX
Page 54: Security vs. UX
Page 55: Security vs. UX
Page 56: Security vs. UX

Stand on the

shoulders of giants

Page 57: Security vs. UX

Start thinking about biometrics

Page 58: Security vs. UX

Encourage passphrases

Page 59: Security vs. UX

Password-less login

Page 60: Security vs. UX

“Regular password changing harms rather than improves

security, so avoid placing this burden on users. However,

users must change their passwords on indication or

suspicion of compromise.”

Page 61: Security vs. UX

Use honeypots

& throttling

Ram Joshi

Page 62: Security vs. UX

Don’t break

password managers

Page 63: Security vs. UX

Set safe

defaults; be

proactive

Page 64: Security vs. UX

Create secure-by-design places

Page 65: Security vs. UX

Security is not an inconvenience, but a human need

Good security serves your user, your organisation, and the wider world

You can design for better security and less friction

Page 66: Security vs. UX

Joachim S. Müller

Security vs UX DeathmatchRomanceBe the love you want to feel

@ccollingridge

@Avecto

@nuxuk