Showing posts with label IT. Show all posts
Showing posts with label IT. Show all posts

Saturday, August 21, 2010

Badly designed websites

@TimHarford offers illuminating advice on the dark art of ‘drip pricing’ (Financial Times, 21 Aug 2010), which the UK’s Office of Fair Trading (OFT) now regards as a most pernicious pricing scheme.

As Tim explains "Under the scheme, customers agree to pay a price only to discover that there is a charge for delivery; another charge for paying by credit card, and another for insurance. Drip pricing taps into the endowment effect, because customers feel that they have already made the decision to purchase; it creates loss aversion because customers commit time and effort to the search before being hit with extra charges; and it is a form of complex pricing which makes it hard to compare offers."

Ever wondered why those websites were so hard to navigate? Did you think it was because the computer programmers were incompetent? Think again - who benefits from simplicity or complexity? See my earlier post on Complexity-Based Pricing.


@gagan_s comments "Sometimes bad websites, phone-trees and policies have a dark purpose".

The word "dark" can mean "hidden", "obscure", "mysterious", "secret", "unconscious"; or it can mean "devious", "evil", "malicious", "treacherous".  Harford's use of the term "Dark Art" in relation to drip pricing clearly denotes a practice that is not just unclear and confusing but also morally questionable.

In terms of the dark purposes of behavioural economics, a website designed to exploit drip pricing should be just complicated enough that when the customer reaches the webpage that demands an additional payment for paying by credit card, the customers have already wasted so much time that it isn't worth starting again with a competing website, so most of them grumble but pay. (Obviously if it is too complicated, then the customers never complete the transaction, which is why the Internet contains a wide variety of these nefarious websites, designed for customers with different patience thresholds.)

IT professionals who understand commercial software and/or website design also grumble about the incompetence of the developers of the website. That just goes to show how naive most IT professionals are, if they imagine that all companies genuinely want websites that are simple and easy to use.

As regular readers of this blog will know, our starting point is Stafford Beer's maxim The Purpose Of a System Is What It Does (POSIWID). According to this principle, there is no such thing as an unnecessarily complicated website: the complication emerges from some conscious or unconscious dark purpose. In the case of drip pricing, the purpose is to chisel a few more dollars from weary and/or confused customers.

But maybe that's too simple. Many people interpret POSIWID to imply that there is exactly one purpose in any system, as if the presence of a dark purpose somehow negates all other purposes. (Beware taking the word "the" too literally. See my post POSIWID should be plural.) But clearly the purpose of chiselling customers has to be balanced against the purpose of selling them stuff in the first place, or the company would go out of business. (Some bad companies do go out of business, but we don't generally suppose that to be their purpose either.)

It is conceivable that the developers of these websites are given explicit instructions to produce exactly the outcomes that their websites achieve, and that they test them carefully to adjust the complication level to optimize the economic returns. But this isn't generally how dark purposes are wreaked. When you speak to people in these organizations, they often seem genuinely frustrated about many aspects of these systems. The dark purpose is rarely if ever an openly acknowledged agenda, but what Blake called an invisible worm.

 

See also: Defence against the Dark Arts (August 2010)

Tuesday, March 25, 2008

Photoshop

Why on earth is the British secret intelligence service recruiting computer graphics specialists [recruitment advert]?

And why on earth are people so suspicious?

Wednesday, October 11, 2006

Identity Cards

Grasshoppermind asks for a POSIWID take on identity cards, refers us to the latest story in Computing Identity card scheme to cost $5.4bn, and suggests that the purpose of the system is to subsidize the IT industry.

There are many other large IT schemes for which this explanation might make sense, including the NHS's National Programe for Information Technology (NPfIT). (For general information about this scheme, see the NHS IT Info page put up by a number of senior academics including Professor Ross Anderson.)

Obviously there are some highly influential representatives of the IT industry who have excellent access to Government ministers, and there are government ministers (as well as opposition politicians) who happen to have a background in management consultancy and IT.

Not surprisingly, the main beneficiaries of these very large schemes tend to be a small number of large IT companies. So the effect is not an evenly distributed subsidy of the IT industry, but a concentration of economic power.

And I think that's the clue. Perhaps the hidden agenda behind these schemes is not subsidy but centralization?


But there is something particularly odd about the identity card scheme, which the other schemes don't share. Identity cards are being proposed to solve a rapidly-shifting series of social problems, including terrorism, crime, identity theft, illegal immigration and benefit fraud. Whenever some expert points out that it will not solve problem A, the proponents of the scheme immediately start talking about problem B instead. Which makes us doubt whether any of these stated purposes are genuine.

We also need to recognize that the widespread criticism of the scheme includes articulate voices from some of the largest computer companies, including Kim Cameron of Microsoft, Michael Osborne of IBM, and of course our old friend Robin Wilton of Sun Microsystems.

But the Government seems determined to go ahead. Is this just some massive folly, like the Millennium Dome squared, or is there some more sinister explanation?

See my earlier posts: The True Motive for Identity Cards and ID Card Compromise, as well as a post on Identity Cards on the TrustBlog.

Wednesday, June 07, 2006

Pact with the Devil

Is the University of Cambridge Computing Laboratory superstitious? Report number 666 (on computer malware) was published on 6/6/6 and is entitled Pact with the Devil [abstract, pdf, announcement]. 

This was clearly contrived. The Laboratory normally publishes a couple of reports every month. Report number 665 was published in April 2006, and then several reports were apparently held back so that the malware report could be assigned an auspicious number and date.

(Three further reports were published immediately after the malware report. Perhaps the numbers and dates are assigned by some bureaucratic computer system; but we may presume that the computer scientists at Cambridge would know how to cheat the system if they had chosen to do so. Perhaps it matters to some people whether this really was the 666th report, and not the 669th report with the code numbers swapped.) 

Superstition is an interesting phenomenon. The computer scientists can claim an interesting defence: they are not irrational themselves, merely exploiting the irrationality of other people. Contriving an auspicious number is a trick to get themselves some publicity for the report. (Hey, it's got me to post a blog about it, and I'm not admitting to being superstitious either.)


The report itself talks about malware that coopts users to help with propagation - exploiting their greed, malice and short-sightedness. 

It can be observed that a biological virus may alter the host's behaviour - for example, causing them to cough germs over other people. I understand that some people infected with a biological virus become so angry and alienated that they deliberately set out to infect other people. Obviously a biological virus that can cause this kind of behaviour is likely to be more successful at propagating itself.

The authors of the paper discuss various mechanisms and incentive structures that a crafty computer virus could use to bribe and blackmail users, causing them to assist with propagation. It's a scary thought. But the authors end with an even scarier thought - we may no longer be able to draw a hard line between malware and other propagated software. Until we have proper controls, "running other peoples software will remain an activity to be undertaken with caution". 

 

See also Pact with the Devil 2 (June 2006)

Saturday, March 11, 2006

PowerPoint

What exactly is PowerPoint for?

If you were the richest person in the world, and your presentation skills resembled Mr Burns from the Simpsons, you would have two choices.

Either you could get the most brilliant presenters in the world to coach you in presentation skills.

Or you could get everyone else in the world to use the same mind-numbing software, so that their presentations were nearly as bad as yours.

The purpose of a system is what it does.

Further Reading

On Microsoft's use of Powerpoint: Bill Gates and Visual Complexity, Gates, Jobs and the Zen Aesthetic (both from Presentation Zen)

On not using PowerPoint: PowerPoint, sans PowerPoint (Presentation Zen), The Best Presentation (Seth Godin)


Update (May 2006)

I have to give it to Microsoft. They are making concerted efforts to improve their own use of PowerPoint, and to encourage others to use it better [comment]. Bill Gates spoke without slides in his keynote speech at Mix06 [review].

So does this refute my original (mischievous) POSIWID comment? Microsoft can now claim that the poor use of PowerPoint was a temporary aberration, a vulnerability rather than a permanent feature of the product. So let's see how many PowerPoint users bother to install the patch, and whether the patch removes the vulnerability.



Related Posts: The PowerPoint Collection

Sunday, January 02, 2005

Beyond FearMongering

Bruce Schneier regrets making the following statement to an AP journalist (Harry Weber), while discussing a series of minor computer problems affecting airline systems.
"If this kind of thing could happen by accident, what would happen if the bad guys did this on purpose?"
Bruce now regards this as just the sort of fear-mongering that he objects to when others do it. When talking to the journalist, he apparently wanted to motivate the airlines to work harder to prevent computer problems in the future. In such a context, it is surely right to inform airline executives of a possible additional risk, and perhaps Bruce wasn't then thinking about the effect on the general public. But in other contexts, Bruce is the first to advocate public disclosure of any vulnerability.

POSIWID thinkers, forensic scientists and readers of murder mysteries are always suspicious of accidents, and suspect foul play on the slightest provocation. Security consultants such as Bruce are always aware that even small vulnerabilities can be exploited and amplified by intelligent attackers. Users of computers can easily imagine the potential disaster from computer failure - whether induced by clever hackers or incompetent programmers or both. Makers of disaster movies looking for the next big script - please contact me.