It's time we add friction to digital experiences and slow them down
- Reference: 1707899235
- News link: https://www.theregister.co.uk/2024/02/14/friction_is_good/
- Source link:
Thieves came in, found more than $90,000 in cash stuffed into a few wallets, helped themselves to it, and escaped.
My friend never heard a thing – because this heist happened electronically. A combination of poor password hygiene and weak security on his Windows laptop gave the intruders unfettered access to the digital wallets in which he stored cryptocurrency. By the time my friend knew he'd been robbed, the thieves had likely “washed” the coins using sophisticated cryptographic tools that made those coins – if not quite anonymous – very difficult to trace.
[1]
Similar incidents happen every day at scale: people get robbed; organizations have their [2]data lakes drained ; nations find themselves [3]under threat . We reckon this as the price of a connected world.
[4]
[5]
Our answer? Throw a few “speed bumps” onto the road with 2FA and hope for the best. Sometimes that works – but sometimes that mobile's SIM has been [6]cloned and it's all for naught. Speed bumps provide the illusion of safety and security, without actually doing much to slow the escape vehicle. To do that requires a bit more of a rethink.
For sixty years, computing has emphasized speed – low latency, transactions per second, megahertz and the like. (Twenty-four years ago, at the famed Game Developers Conference, I remember seeing the very first AMD Athlon [7]running at 1GHz – and thought it a wonder.)
[8]
The singular focus has us prioritizing the accuracy of granular operations – load, store, move, add, subtract, test, jump – over the systemic product of those operations – such as moving data between machines (and owners) across a network. Our relentless optimization for speed has us [9]valuing a 120Gbit/sec Thunderbolt port over a more thoughtful consideration of how we might be far better served by an operation more complex, secure – and slower. Thinking fast has left us vulnerable.
Even suggesting that slower might be better seems like an anathema. If computing can't be fast, then what's the point?
Perhaps the point should not be which chip or algorithm renders the fastest or most accurate operation, but which systemic approach offers the greatest level of safety and security. Systems that have no friction in them – running unsupervised, without speed bumps, with no skeptical humans in the loop judging and grading – are hurtling down the highway to hell. That we also happen to be in these vehicles seems to occur to no one – until after the inevitable crash.
[10]
If we want to avoid the unpleasant consequences of collisions, we urgently need to consider how we might make all of our key IT infrastructure “slow”.
[11]Apple has botched 3D for decades. So good luck with the Vision Pro, Tim
[12]It's uncertain where personal technology is heading, but judging from CES, it smells
[13]Digital memories are disappearing and not even AI or Google can help
[14]Software is listening for the options you want it to offer, and it's about time
Some criteria appear immediately obvious: friction should be proportionate to the danger inherent in the transaction. A private message between two close confidantes needs very little friction. On the other hand, a massive financial transaction or data migration could include baked-in “breakpoints” that require human intervention before automated work continues. Making those big and dangerous transactions slow and expensive, studded with human oversight, makes them less likely to suddenly spiral out of control.
We're already accustomed to the idea of “slow food” and “slow fashion” – even “slow television”. “Slow computing” could provide the safety belt, airbags and crumple zones needed to keep us from becoming digital roadkill. Speed can be useful, but physics tells us that the damage of a crash increases with the square of the velocity. We need to hit the brakes – before we hit the wall. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcydVik7BS90zuXJZOK8ygAAARA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2024/01/17/extortion_bot_is_autopwning_postgresql/
[3] https://www.theregister.com/2023/11/29/water_authority_ciso_iran/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcydVik7BS90zuXJZOK8ygAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcydVik7BS90zuXJZOK8ygAAARA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2009/07/10/comic_book_sim/
[7] https://www.theregister.com/2000/03/03/how_amd_beat_intel/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcydVik7BS90zuXJZOK8ygAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/10/19/intel_nextgen_thunderbolt/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcydVik7BS90zuXJZOK8ygAAARA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2024/01/24/apple_vision_pro_good_luck/
[12] https://www.theregister.com/2024/01/12/ces_analysis/
[13] https://www.theregister.com/2023/12/06/down_the_memory_hole/
[14] https://www.theregister.com/2023/11/15/chat_interfaces_software_options/
[15] https://whitepapers.theregister.com/
Re: Flash crash
Moving large quantities of cash between banks (in different countries) for a recent house purchase required my presence in the branches with government provided ID. A bit of a pain but understandable and I think a worthwhile check. Smaller amounts between countries are a simple bank 2FA log-on, with a further 2FA for the transaction itself in many cases.
Though it does amuse me that my bank will cheerfully open my credit card website and log me in using my credentials from the bank site, but requires multiple further 2FA checks when I actually try and pay off a credit card balance from the same bank...
Tom Cruise to the rescue
Watched Mission Impossible 2 the other day. That's 2 hours of my life i'll never get back..
It's er, the one where a pharmaceutical company produces an artificial supervirus and the drug to cure it, by "splicing different viruses together"
Anyway, there was a scene where the company was forced to transfer an enormous amount of money (47 Million Dollars!) to some common/garden terrorists, but it took a comically long time, as if each dollar were being transferred individually.
Long enough for the saviour of scientology to come along and save the day, as he does..
At that speed, Elon Musk would need to wait several months for his pay packet to arrive
Ain't Gonna Happen ...
... unless everyone goes in on this. That will not happen, because in a world with high-friction and low-friction transaction channels, the economic winners will be those who use the low-friction channels.
On the low-money end, they'll be the ones who get the best Internet deals, because they could complete their transaction (pay off the seller) before the guy or gal using the slower, high-friction channel.
On the high-money end, they'll be the ones who make the most money on the stock, currency, and futures markets, because their transactions complete a fraction of a second (or multiple seconds, or multiple minutes) faster than the high-friction-channel users, before the market changes (yet again).
Why else are traders and brokerage houses screaming for systems with lower latencies, paying fortunes to get and maintain them, and paying fortunes to be connected to the same subnet, and same switch as the computers processing all this data?
There are tonnes of people who choose potential profits over security.
Re: Ain't Gonna Happen ...
"There are tonnes of people who choose potential profits over security."
...and that will continue to happen for as long as they are allowed to reap the profits while passing on the losses
Re: Ain't Gonna Happen ...
That's the unfortunate truth, convenience will always trump security for the average person. Providing a faster and hands-off experience is always going to be more attractive because people are inherently lazy and would rather have mundane tasks completed quickly rather than ensuring they're done safely (and yes, I'm including myself in that lot as well). Give the average person a choice between using 2FA and manually entering their details and going through a basic security check, or just dumping all their credentials into a one-click solution presented to them and just presuming that it's going to be fine and never end up being compromised and they don't have to worry about it anymore, and they'll always go for the easier option.
It's never a problem, until it is a problem.
unfettered access to the digital wallets in which he stored cryptocurrency.
Oh good, nothing of any actual value was lost then.
Re: unfettered access to the digital wallets in which he stored cryptocurrency.
The issue here is to educate people and stop people pushing financial scams (just like we stop people pushing drugs).
Cryptocurrency is a toy. A game. It is clear to most of us who post here that, like share trading, you should never invest money you can't afford to lose and that you should transfer any gains out into a safe form.
If you can afford to lose 90,000 then there is no need for speed bumps, brakes, etc. If you can't afford to lose it then don't play with it.
I doubled my money on cryptocurrency a while ago; I invested 5000. When it doubled in value to 10000 I transferred 5000 back into real money. At that point I was quids-in - I had made my initial investment back and anything more was profit. It doubled again and I transferred another 5K back into real money. The remaining 5K has gone down a bit but I don't care: I doubled my money.
Oh, and by the way, I paid tax on it.
Or users could just follow established best practice, keep their cryptocurrency wallets locked, encrypted and offline, ensure proper password hygiene and implement sensible update practices.
But, no, let's SLOW EVERYTHING DOWN because people are too dumb to follow even basic security practices to secure $90,000 of digital assets.
Imagine if your bank said "Sorry, we lost your $90,000 savings because we don't have doors on our safes, the password to the box with the money in was 1234 and we haven't updated our CCTV since 2000."
You'd be up in arms.
From the opening paragraphs it appears that the laptop was left running overnight. So there's one way of introducing friction, right there: switch it off when you're not using it.
Long
How long would you like to wait today?
So let's get this straight....
Your friend decided to put his money into cryptocurrency, stored it on a badly secured Windows laptop, and connected it to the internet. It then got robbed, which means that now you think that the way to prevent this happening again is to slow everybody else's computers down? No thanks, tell him to use real money and keep it in a bank in future. They do have the sort of checks you're suggesting on large transactions.
No need to remodel the entire digital world, just because of the naivety of foolish crypto believers.
THIS!!!
Excellent article that unfortunately most people will not read/understand/action. The pointless obsession with often irrelevant CPU speed is a good example - who cares if an on screen task takes 0.6 seconds rather than 0.7 seconds!? It's the same kind of nonsense that idiots with too much money spout when buying Bang & Olufsen - they really can't hear the difference but want to show off by pretending they can.
Maybe we could all start by being professional and push back whenever we're asked to do something quickly and badly rather than doing a good job in the time that it actually requires (because if you don't the fool that asked you to do it will as sure as can be make you the fool when the proverbial hits the fan) or maybe that's too much to ask? Probably the latter as most people seem to prefer an easy life to a good life.
Flash crash
The wall street flash crash comes to mind here of what can happen with unsupervised computers screwing up.... they can screw a lot of things up very very quickly!!
Absolutely makes perfect sense to have more controls for actions or transactions that have bigger consequences. That is already the case for many offline or online transactions, eg if I withdraw £100 from an ATM it happens immediately, but there is a limit on withdrawal. large transfers of a few £k can be ordered online but done usually on next business day. Anything above that eg buying a house usually involves multiple human interventions.