Yes, this article is long on alarmism and short on serious critique:
> The design of the form does not match the design of either the merchant or the issuing bank. The design looks ‘cheap’. It doesn’t look trustworthy.
> No telephone number. When a user sees a telephone number it gives them a feeling legitimacy. They may not phone, they just want to see the number just in case.
> The calls to action at the bottom of the page really don’t work. ‘Submit’ is rather generic and does not give an indication of the next step. ‘Cancel’ gives no indication what will happen next and really should be removed.
> There is still very little recognition by users. Visa and Mastercard have done a poor job of marketing and raising awareness.
> The text is American "Expiration date" should be "Expiry date"
> Once the customer has overcome all 11 of those issues they can purchase. 11 issues. 11 serious issues.
Serious issues? Let's tally: cheap design, no phone number, button names, lack of marketing, bad copy. These are not serious issues that make a technology "broken" -- at least, not in the sense that, say, MD5 is broken. The points about the phone number, cheap design, and lack of marketing should not even be in this list.
And then there is this gem, from the guy who is going to fix our "broken" security technology:
> Firstly, the URL, well that’s an easy one, embed the page within an iframe. It does of course mean one can’t check the security certificate but hey, who ever does this?
> About the author: Joe specialises in designing every aspect of the user experience from initial research to developing a robust, measurable online strategy to producing beautiful, easy to use wireframes and website information architectures.
Comments
Yes, this article is long on alarmism and short on serious critique:
> The design of the form does not match the design of either the merchant or the issuing bank. The design looks ‘cheap’. It doesn’t look trustworthy.
> No telephone number. When a user sees a telephone number it gives them a feeling legitimacy. They may not phone, they just want to see the number just in case.
> The calls to action at the bottom of the page really don’t work. ‘Submit’ is rather generic and does not give an indication of the next step. ‘Cancel’ gives no indication what will happen next and really should be removed.
> There is still very little recognition by users. Visa and Mastercard have done a poor job of marketing and raising awareness.
> The text is American "Expiration date" should be "Expiry date"
> Once the customer has overcome all 11 of those issues they can purchase. 11 issues. 11 serious issues.
Serious issues? Let's tally: cheap design, no phone number, button names, lack of marketing, bad copy. These are not serious issues that make a technology "broken" -- at least, not in the sense that, say, MD5 is broken. The points about the phone number, cheap design, and lack of marketing should not even be in this list.
And then there is this gem, from the guy who is going to fix our "broken" security technology:
> Firstly, the URL, well that’s an easy one, embed the page within an iframe. It does of course mean one can’t check the security certificate but hey, who ever does this?
> About the author: Joe specialises in designing every aspect of the user experience from initial research to developing a robust, measurable online strategy to producing beautiful, easy to use wireframes and website information architectures.
Oh, I see.
You've taken a very specific definition of "broken", then decided that the article doesn't meet your definition, so the article is worthless?
If you're losing customers for a bit of security theater, I think "broken" is a pretty good term from the perspective of the retailer.