6.7 KiB
6.7 KiB
Public trust user research
This guide is for conversations with non-specialists before Browsec commits to a distributed-trust architecture. Its purpose is to discover what people would benefit from, tolerate, distrust, and reject—not to persuade them that our current idea is correct.
Ask one question at a time. Let the participant describe concrete experiences before introducing terminology such as certificate authority, consensus, community trust, reputation, or distributed network.
Short conversational interview
Existing experience
- Have you ever opened a site and received a security or certificate warning? What did you think was happening?
- What did you do next, and why?
- Have you ever wanted to use a site that your browser blocked even though you believed it was legitimate?
- Have you ever trusted a site because the browser showed no warning and later regretted it?
What “trustworthy” means
- When you call an online service trustworthy, what do you mean?
- Does trustworthiness change with the activity—for example reading news, sending a private message, downloading software, or making a payment?
- What information would help you decide whether to continue to a questionable site?
- Which matters more to you: knowing who operates the service, knowing that other people have used it safely, or knowing that its technical identity has not unexpectedly changed?
People and institutions
- Whose judgment about an online service would you consider useful?
- Would you treat advice differently if it came from friends, technical specialists, an organization you know, your employer, your government, or strangers with a good history?
- Should several independent sources be able to disagree visibly, or should the browser combine them into one recommendation?
- Would you ever allow a chosen person or group to make a security decision automatically for you? In what situations?
- Whom would you explicitly refuse to give that power?
Desired behaviour
- If the browser distrusts a service but people you chose consider it legitimate, what should the browser do?
- If the browser accepts a service but a community you trust reports danger, what should happen?
- Should the system merely provide evidence, recommend an action, block the connection, or let you choose among those behaviours?
- How much explanation would you want before continuing: a simple warning, a short reason, or a detailed investigation?
- Should an earlier decision apply once, for the current session, for a fixed time, or until you revoke it?
Privacy and social cost
- Would you be comfortable if other participants could learn which services your browser checks or visits?
- Would you contribute observations about certificates or service behaviour if the system protected your browsing history? What protection would you expect?
- Would public participation under a stable identity feel safer and more accountable, or more invasive?
- What information about you should never leave your device?
- Would background network activity, battery use, or bandwidth use bother you? How much control would you expect?
Abuse and failure
- What would make you suspect that a trust community had been manipulated or captured?
- What should happen when trusted participants disagree sharply?
- How should the system respond if a once-reliable participant begins giving harmful advice?
- Should old recommendations expire automatically? How quickly?
- What would be worse: occasionally blocking a legitimate service, or occasionally allowing a harmful one?
- What behaviour by this system would make you disable or uninstall it immediately?
Governance and control
- Who should be able to create a trust community?
- Who should decide its rules, membership, and removal process?
- Should communities be able to split, merge, or recognize one another?
- Should there always be a local setting that overrides every community and institution?
- Which emergency security announcements, if any, should be allowed to reach everyone—and who should be permitted to issue them?
Closing
- What useful capability have these questions failed to mention?
- What part of this idea sounds most valuable?
- What part sounds most dangerous or unpleasant?
- Would you personally try such a system? Why or why not?
Very short version
Use these when there is time for only a brief conversation:
- What makes an online service trustworthy to you?
- Have browser security warnings ever helped or frustrated you?
- Whose security advice would you accept, and whose would you reject?
- Should advice remain visible as disagreement or become one browser verdict?
- What could such a system do that would make you want it?
- What could it do that would make you uninstall it immediately?
- What information about your browsing must never leave your device?
- When should the system advise, ask, block, or act automatically?
Interviewer notes
- Ask for examples: “Can you remember a time when that happened?”
- Do not correct technical misunderstandings during the discovery portion. Misunderstandings reveal what the interface will need to explain.
- Avoid presenting “the community” as inherently benevolent or “the authority” as inherently malicious. Both can fail or be captured.
- Distinguish what the participant wants, what they would merely tolerate, and what they would refuse.
- Record the intended activity. Trust for reading a public page may differ from trust for payment, identity documents, private communication, or executable software.
- Ask whether a desired automatic action should be the default or an explicit opt-in.
- Record exact phrases when possible; they may suggest better UI language than our engineering vocabulary.
- Do not collect names, browsing histories, or sensitive incidents unless the participant knowingly chooses to share them.
Synthesis questions for us
After several interviews, classify responses without forcing consensus:
- Which benefits recur across technically different participants?
- Which feared behaviours would be unacceptable even if technically useful?
- Which decisions do people want to retain personally?
- Which decisions are they willing to delegate, and to whom?
- Which activities require different trust standards?
- Where do people prefer visible disagreement over one combined score?
- What privacy cost are people unwilling to pay?
- Which terms were consistently misunderstood?
- Which requested benefits require distributed trust, and which could be solved more safely by a local tool?
- What is the smallest system that produces a real user benefit?