Authorisation vs. Consent An Article by Terence Eden shkspr.mobi I recently read this interesting, and distressing, story of a man who was drugged and robbed. A form of crime which has been going on for centuries. But the 21st Century twist is that the thieves forced him to transfer large sums of money via his phone's banking apps. While under the influence, the victim used his usernames, passwords, PINs, and biometrics to send money to the criminal's accounts. Is there a "technological" way to stop this? His banks initially refused to refund the stolen money. Only once the press stepped in did they relent. One bank, Revolut, said: This was an unusual case where the payments were authorised by the customer but, as is now clear, without his consent. Upstream Color crime
Rethinking Twitter Verification An Article by Terence Eden shkspr.mobi The main problem, I think, is that no one knows what "Verified" means. If I were in charge (which I'm not) there would be various types of ticks. 🤖 is a bot 🆔 proved their legal identity 🏭 is run by a brand ⚖ is run by a government department 👮 Official law enforcement 😎 Celebrity And so on. iconographyidentity
You and your user are one In the case of the seeming egalitarianism and beneficence of the voice from the cloud that says “You Are Not Your User,” what I hear in that voice is the ringing of a cash register, and the creaking of the crank on the side of a box that software development efforts disappear into, and that money comes out of. A mechanism that would seize up instantly if some still small voice were to propose the opposite of what the thunder says: that you and your user are one. Dan Klyn, Sermon for WIAD Bristol 2021 understandinggroup.com My job is simply to design gadgets that I likeReversibility of perspectives uxsoftware