<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>UIE Brain Sparks &#187; Security</title>
	<atom:link href="http://www.uie.com/brainsparks/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uie.com/brainsparks</link>
	<description>UIE\'s latest insights on the world of design</description>
	<lastBuildDate>Fri, 10 Feb 2012 20:02:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.3" -->
	<itunes:summary>The latest insights from User Interface Engineering on the world of design. Shows include the SpoolCast, Userability and Usability Tools Podcast.</itunes:summary>
	<itunes:author>Jared M. Spool and User Interface Engineering (UIE)</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.uie.com/BSAL/Artwork/bsalart144x.jpg" />
	<itunes:owner>
		<itunes:name>Jared M. Spool and User Interface Engineering (UIE)</itunes:name>
		<itunes:email>mailbag@uie.com</itunes:email>
	</itunes:owner>
	<managingEditor>mailbag@uie.com (Jared M. Spool and User Interface Engineering (UIE))</managingEditor>
	<copyright>2006-2011</copyright>
	<itunes:subtitle>The latest insights from User Interface Engineering on the world of design, including the SpoolCast, Userability, and the Usability Tools Podcasts.</itunes:subtitle>
	<itunes:keywords>Design, web, usability, Spoolcast, information architecture, interaction design, user experience design,</itunes:keywords>
	<image>
		<title>UIE Brain Sparks &#187; Security</title>
		<url>http://www.uie.com/BSAL/Artwork/bsalart144x.jpg</url>
		<link>http://www.uie.com/brainsparks/topics/security/</link>
	</image>
	<itunes:category text="Technology" />
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Arts">
		<itunes:category text="Design" />
	</itunes:category>
		<rawvoice:location>North Andover, Massachusetts</rawvoice:location>
		<item>
		<title>But, what if?</title>
		<link>http://www.uie.com/brainsparks/2008/12/19/but-what-if/</link>
		<comments>http://www.uie.com/brainsparks/2008/12/19/but-what-if/#comments</comments>
		<pubDate>Sat, 20 Dec 2008 01:18:39 +0000</pubDate>
		<dc:creator>Jared Spool</dc:creator>
				<category><![CDATA[Brand Engagement]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=759</guid>
		<description><![CDATA[The security challenge question on Bank of America&#8217;s site seems innocuous: In what year (YYYY) did you graduate from high school? But, what if the user didn&#8217;t graduate high school? (Little known fact: I didn&#8217;t graduate high school, so I&#8217;m a little sensitive to this question.) Should the user enter the date they would&#8217;ve graduated [...]]]></description>
			<content:encoded><![CDATA[<p>The security challenge question on Bank of America&#8217;s site seems innocuous:</p>
<p><img src="http://www.uie.com/images/blog/BankOfAmerica_SecurityQuestion-20081219-200933.png" alt="Bank of America Security Question" /></p>
<blockquote><p><em>In what year (YYYY) did you graduate from high school? </em></p></blockquote>
<p>But, what if the user didn&#8217;t graduate high school? (Little known fact: <em>I</em> didn&#8217;t graduate high school, so I&#8217;m a little sensitive to this question.)</p>
<p>Should the user enter the date they would&#8217;ve graduated high school? Should they make up a date? How will they remember something that didn&#8217;t actually happen?</p>
<p>It&#8217;s surprising how many security challenge questions are unanswerable like this. I doubt it leaves the user with a positive feeling about the experience.</p>
<p><strong>Update: </strong>This is from the Vanguard web site:</p>
<p><img src="http://www.uie.com/images/blog/Vanguard_SecurityQuestion-20081219-204555.png" alt="Security Challenge Question on Vanguard" /></p>
<blockquote><p><em>Where did you and your spouse meet for the first time? (Enter the full name of CITY only)</em></p></blockquote>
<p>What about multiple marriages? Widows?</p>
<p>To add insult to injury, the design replaces every letter the user types with a dot, so they can&#8217;t see if they&#8217;re typing the city correctly. (Again, I grew up in a city named <em>Schenectady</em>. Not something I&#8217;d want to type in the dark.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.uie.com/brainsparks/2008/12/19/but-what-if/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
	</channel>
</rss>

