1 comment

[ 3.2 ms ] story [ 12.3 ms ] thread
I really don't know too much about this game or it's author. I saw it referenced on BoingBoing. For all I know, they could be a horrible person. It could be festooned with privacy invading malware. I'm too lazy to open the developer's console in chrome and find out.

I'm posting a link to it because I like the game play. Most importantly, I don't have to log in to start playing. I have the option of looking at some docs or to jump right in.

This is in contrast to another game posted here recently: https://news.ycombinator.com/item?id=31980980 by @drcode.

I'm not saying the dream book game is bad. I'm not discouraging you from playing it. But what I am saying is the first thing it presented me with was a login screen, and that's just more than I can handle with a game. I have "login fatigue" from work. Every ten minutes I'm logging into another system. I really can't handle that during recreation times. And yes... it turns out there are reasonable reasons why our SSO experience is so sub-standard. Not good reasons, but understandable-given-the-circumstances-and-if-only-we-had-enough-manpower-we-could-fix-this kind or reasons. Not enough reasons to quit; most every other aspect of my job is great.

But getting back to the experience of not having to log in.

In the old days you had a personal computer and it booted up and you saw your desktop. You didn't log in. Your desktop was right there because you owned the computer. On my classic Mac, I only had to log in when I wanted to access a shared, protected resource on the network. And even then it only affected my experience with THAT resource. They eventually created the moral equivalent of SSH Agent for the Mac for people who had a bazillion file servers on their network. And it was okay.

[ and yes. you could lock your screen if you were worried about people accessing your desktop. but if you were seriously paranoid, you would eject the floppy disk with the files you were working on and take it with you to lunch. ]

So what am I saying... I'm asking app developers to consider delivering a base level experience without having to authenticate the user's identity. Yes. It's horrible from a security perspective. We all know that true information security comes from requiring people to memorize another password. I'm sure that's written down in a NIST 800 manual from 1978 or something.

And I'm completely not trying to disrespect drcode's work. This just wasn't at the top of their list and that's completely fine.

But... having an experience for users who haven't logged in reduces friction.