Rating:

All watched over by machines of loving grace: Some ethical guidelines for user experience in ubiquitous-computing settings [1]

“If ubicomp applications are rushed to market and allowed to appear as have so many technological artifacts in the last thirty years, then they will present those users with a truly unprecedented level of badness.”

Note: It can be difficult, initially, to consider ubiquitous-computing environments as a special case for user experience work. Before they are knit together, the elements constituting ubiquitous systems may appear to be merely conventional technological devices, with relatively well-documented interfaces and affordances. It is only as they join and fuse that the emergent properties we think of as “ubicomp” come to the fore. It can be equally imprecise to speak of “users,” in a context where a human being encountering ubiquitous information-processing technology may more accurately be considered as a subject. Nevertheless, I have used the term throughout, as it is established and widely understood.

Ubiquitous computing is coming. It is coming because there are too many too powerful institutions vested in its coming; it is coming because it is a “technically sweet” challenge; it is coming because it represents the eventual convergence of devices, tools and services that became inevitable the moment they each began to be expressed in ones and zeroes.

It is a future structurally latent in the new schema for Internet Protocol addressing, IPv6, which, with its 128-bit address space, provides some 6.5×1023 addresses for every square meter on the surface of our planet, and therefore quite abundantly enough for every pen and stamp and book and door in the world to talk to each other. And of course it is a future economically latent in the need of manufacturers and marketers for continuous growth, and the identification of vast new markets beyond the desktop, laptop, personal audio player and mobile phone.

The slow fusion of our mobile phone and wireless broadband networks, the accelerating miniaturization and vastly reduced cost of RFID chips, the increasing ease with which circuits can be printed or embedded in wearable, even disposable items, improved techniques in ambient information display, the aging of society and corresponding necessity for outboard memory augmentation, even factors like public fear and the ostensible prerogatives of security in the post-September 11th era (“reduce the public sphere, restrict access, and limit unmonitored activity”2 ) all imply that ubicomp will play an increasingly prominent role in our lives, technically, socially and psychologically.

Despite our best efforts—which is to say, the best efforts of a great many sensitive and intelligent people working in good faith, over the course of a decade and in every country where access to the Internet is commonplace—even ordinary operations in such a comparatively simple regime as the World Wide Web still all too often present users with unacceptable difficulty, confusion and uncertainty. Moments of perplexity and doubt remain, strewn through even the most quotidian tasks like landmines among the fields. The Web works, but rarely as effortlessly or in a manner as free from undue complication as we might wish.

By comparison with the World Wide Web, ubiquitous computing is vastly more insinuative. By intention and design, it asserts itself in every moment and through every aperture contemporary life affords it3. It is everyware.

The prospect of such moments of disjunction and dismay being allowed to persist in the enormously more powerful, pervasive and intimate milieu of ubicomp, percolating through even to realms of existence not previously considered as subject to operations through an “interface”—and especially in contexts where users’ governing mental models are likely to be social and interpersonal4 in nature rather than technical—is still more unacceptable. (This is most especially so in the absence of compelling and clearly articulated value propositions for ubiquitous systems from the user’s point of view.)

Social engineering/society by engineers


It should be clear that ubicomp represents a substantial raising of stakes over the Web case, the PDA case, the mobile-phone case, or other scenarios we’re accustomed to; that its field of operation is by definition total; and that its potential for harm if poorly implemented is such that the user experience is too important to leave to chance, or the discretion of developers.

My sense is that the challenge of ubiquitous computing for user-experience professionals resides fundamentally in two places: in the regrettable quality of interaction typically manifested by complex digital products and services designed without some degree of qualified UX intervention, and in the ease with which ubiquitous systems can overwhelm or render meaningless the prerogatives of privacy, self-determination and choice that have traditionally informed our understanding of civil liberty.

We can all readily encompass the danger of the first situation. With all due respect, we have seen that products designed by engineers, or whose design is permitted to default to the tastes, preferences and predilections of engineers, almost always fail end users (unless those end users are themselves engineers).

This is not an indictment of engineers. They are given a narrow technical brief, and within the envelope available to them they return solutions. It is not in their mandate to consider the social and environmental impact of their work. From our vantage point as user-experience professionals, however, it is clear that there have always been emergent properties of systems that are designed with a given end in mind – and that sometimes, those properties and effects are of much greater consequence than the intended result.

If ubicomp applications are rushed to market and allowed to appear as have so many technological artifacts in the last thirty years—i.e., without compassionate attention to the needs and abilities of all sorts of human users, without many painstaking rounds of iterative testing and improvement in realistic settings—then they will present those users with a truly unprecedented level of badness.

Imagine the feeling of being stuck in voice-mail limbo, or fighting unwanted auto-formatting in a word processing program, or trying to quickly silence an unexpectedly ringing phone by touch, amid the hissing of fellow moviegoers—except all the time, and everywhere, and in the most intimate circumstances of our lives. Levels of discomfort we accept as routine (even, despite everything we know, inevitable!) in the reasonably delimited scenarios presented by our other artifacts will have redoubled impact in a ubicomp world.

Even if for this reason alone, we must ensure that this class of products and services is designed better, with more sensitivity and compassion, than others in the past.

It is, however, the impact of ubicomp on civil liberty that I am most concerned with. While the quality of ubiquitous interaction is more squarely within the typical ambit of our professional concerns, it is the civic sphere where our input and perspective is most critical and can be leveraged to secure the most enduring and important gains.

Ubiquitous systems lend themselves easily to—indeed, redefine—surveillance. However discrete they may be at their design and inception, their interface with each other implies a domain of action that extends from the very contours of the human body outward to whatever arbitrarily large civic space can be equipped with the necessary sensors and effectors. In short, there is no current technology with greater potential to support authoritarian and totalitarian social engineering, and the limitation otherwise of choice.

This will not always be a matter of imposition: it should be pointed out that some of us, perhaps even a majority, will want and strongly prefer such systems when they become available. As I have noted previously, critics tend to react negatively to the prospect of panoptical surveillance, “but what those who do so generally fail to understand is that many, many people like the idea that they’re always being watched, because they equate that watching with always being cared for…if the most accepted model for pervasive devices to date has been the Assistant, we should never forget that a competing model—one that holds strong appeal for a great many people—is the Superintendent.”

In the contemplated introduction of any system with so much inherent potential for oppression, it is clearly incumbent upon its designers to provide reasonable assurances for the maintenance or extension of human freedom, agency and autonomy.

Why us, why now?


With our orientation toward, and intense dedication to improving, the quality of interaction experienced by users of the World Wide Web (and technical systems of all sorts), we in the user-experience community are uniquely positioned to affect the emergence of this technological milieu for the better.

With our advocacy on behalf of a party otherwise under- or unrepresented in the development process—the human being(s) using the product or service at hand—we bring a certain grounding clarity to the proceedings. With our insights concerning the optimal order, sequence, priority, and rate of information presented to the user, we have frequently allowed a successful business case to be asserted where there was none before. We may even, if we are particularly lucky, be able to bring aesthetic sense and discretion to the projects on which we are engaged.

It is my sense that the time is apt for us to begin articulating some baseline standards for the ethical and responsible development of user-facing provisions in ubicomp applications, before our lives are blanketed with the poorly-imagined interfaces, infuriating loops of illogic, and insults to our autonomy that have characterized entirely too much human-machine interaction to date.

None of the following should be understood to arrogate to ourselves the role of sole guardian of the user’s interests, or to overlook the foundational work already done in the human-computer interaction community. These guidelines are intended for working information architects, usability specialists and user-experience designers, and address situations from their perspective.

Principles


The intent of this section is to enunciate some general principles for us to observe, as designers and developers for ubiquitous systems, whereby the ethical and social prerogatives of our “users” can be preserved.

The most essential and the hardest to express with any rigor, which we might call principle 0, is, of course, first, do no harm: if we could all be relied upon to take this simple idea to heart, thoughtfully and with compassion, there would be very little need to enunciate any of the following.

Given the difficulties of deriving practically useful guidance from such bywords, however, let us enunciate a further five guidelines that should go some way toward illuminating the challenges we face in designing useful, humane instantiations of ubicomp:


  • Principle 1. Default to harmlessness. Ubiquitous systems must default to a mode that ensures their users’ (physical, psychic and financial) safety.

    We are familiar with the notion of “graceful degradation,” the ideal that if a system fails, if at all possible it should fail gently in preference to catastrophically, with functionality being lost progressively rather than all at once.

    Given the assumption of responsibility for users and their environments implied by the ubicomp rubric, such systems must take measures that go well beyond mere graceful degradation.

    Slaved passenger vehicles, dosage settings for pharmaceutical-delivery systems, controls for sealed or denied environments are examples of situations where redundant interlocks must be provided to ensure user safety.

  • Principle 2. Be self-disclosing. Ubiquitous systems must contain provisions for immediate and transparent querying of their ownership, use, capabilities, etc., such that human beings encountering them are empowered to make informed decisions regarding exposure to same.

    Some analogue of broadcast station identification conventions, or perhaps of the Identification Friend or Foe (IFF) standards by which military systems identify themselves to each other, would be necessary.

    “Seamlessness” must be an optional mode of presentation, not a mandatory or inescapable one: both the interfaces through which information is passed between adjacent systems, and the actual data that is so communicated, must be equally capable of self-revelation.

    Ubiquitous systems, by definition, cannot help but gather information constantly, including arbitrarily granular location of users in four-dimensional spacetime. It would be unreasonable and unrealistic to assert a Web-derived model for user consent to such ongoing information-garnering activities in the ubicomp context: the scenario would be one of constant, exasperating interruption to task flow, as the user was asked to give explicit consent to the transmission of each momentary state. Given this, some provision for at least determining who owns a given system, and what will be done with information so revealed, is necessary.

  • Principle 3. Be conservative of face. Ubiquitous systems are always already social systems, and must contain provisions such that wherever possible they not unnecessarily embarrass, humiliate, or shame their users.

    Consider this brief vignette, from Thomas Disch’s legendary 1974 novel 334:

    “”Arnold Chapel,” a voice over the PA said. “Please return along ‘K’ corridor to ‘K’ elevator bank. Arnold Chapel, please return along ‘K’ corridor to ‘K’ elevator bank.”

    “Obediently he reversed the cart and returned to ‘K’ elevator bank. His identification badge had cued the traffic control system. It had been years since the computer had had to correct him out loud.”

    While Disch undoubtedly deserves credit for having so vividly imagined ubicomp avant le lettre, some twenty years ahead even of Mark Weiser, is there any reason why the system’s correction need be perceptible to anyone but Chapel himself? Why humiliate, when adjustment is all that is mandated?

    This goes beyond formal information-privacy concerns, toward the instinctual recognition that no human society can survive the total evaporation of its protective hypocrisy. Some degree of “plausible deniability,” including above all imprecision of location, is probably necessary to the psychic health of a given community, such that even (natural or machine-assisted) inferences about intention and conduct may be forestalled at the subject’s will. Still worse than the prospect of being nakedly accountable to an unseen, omnipresent “network” is being nakedly accountable to each other, at all times and places.

    At the absolute minimum, and in accordance with Principle 2, ubiquitous systems with surveillant capacity must announce themselves as such, in such a way that their field of operation may be effectively evaded.

  • Principle 4. Be conservative of time. Ubiquitous systems must not introduce undue complications into ordinary operations.

    If they impact such operations, they must be at least as transparent to users as the pre-existing equivalent: that is, one should be able to sit in a chair, place a book upon a shelf, boil a kettle of water without being asked if one “really” wants to do so, or having fine-grained control wrested away. In the absence of other information, the default assumption must be that an adult, competent user knows and understands what they want to achieve and has accurately expressed that desire in their commands to the system5.

    By the same token, a universal undo convention similar to the keyboard sequence “Ctrl Z” should be afforded; “save states” or the equivalent must be rolling, continuous and persistently accessible in a graceful and intuitive manner. If a user wants to undo, or return to an earlier stage in an articulated process, they should be able to specify, e.g., how many steps or minutes’ progress they would like to efface. (“Make it like it was two or three minutes ago!”)

  • Principle 5. Be deniable. Ubiquitous systems must offer users the ability to opt out, always and at any point.

    As an absolute ethical imperative, users must be afforded the ability to make their own meaningful decisions regarding their exposure to ubiquitous perception, the types and channels of information such exposure will necessary convey, and the agencies receiving and capable of acting on such conveyance.

    Critical to this is the ability to simply say “no,” with no penalty other than the inability to make use of whatever benefits the ubiquitous system offers its users. (The “safe word” concept may find an novel and unforeseen application here.)


Conclusion


These recommendations, clearly, are not comprehensive6:

They are certainly capable of being gamed, of being exploited by individuals determined to gain unfair advantage. They depend vitally for their effectiveness on voluntary compliance. They will necessarily involve compromises, conflicts, tensions and trade-offs. When were things ever otherwise?

But if thoughtfully and consistently implemented, it is my strong belief that they will go a long way toward improving the baseline experience for the human users and subjects of ubiquitous systems, and therefore rendering such systems acceptable for widespread implementation.

This, above all, is not a place for “service packs”; if ever there were a situation to compel the devotion of our full professional attention and compassionate effort to the individual human subject of technological intervention when it could still make a difference, this is it.7

For More Information


End Notes


  1. The reference is to Richard Brautigan’s bad, but perfectly illustrative, 1967 poem of the same name.
  2. T. Riley and G. Nordenson, curatorial notes for the exhibit “Tall Buildings,” Museum of Modern Art (MoMA QNS), 2004
  3. It is worth preserving here the distinction between discrete, situated systems and literally ubiquitous ones. (I’m grateful to Joe McCarthy for underlining this point.) However, my concern is with how such systems will be perceived by those people encountering them, and I have little doubt that users will fail to distinguish between one delimited, voice-accessed system and another, especially if those systems share (e.g.) CRM information.
  4. For a thorough description of the ways in which user mental models for their interactions with machines are heavily patterned on rules governing social interaction, see B. Reeves and C. Nass, “The Media Equation,” CSLI Publications, 1996
  5. The potential conflict with Principle 1 is obvious, and remains to be resolved: should ubiquitous systems permit their users to choose options harmful to themselves? Answering the question to anyone’s satisfaction will require both experience with the domain and a sensitivity to the specific context, against the background of an evolving jurisprudence of ubiquitous interaction.
  6. A sense for the degree to which these recommendations only scratch the surface can be gained by reading Roger Clarke’s commentary on Isaac Asimov’s “Laws of Robotics,” particularly its section on the structuredness of decision making.
  7. I am deeply grateful to Anne Galloway, Howard Rheingold, Nurri Kim, and Joe McCarthy for insights and commentary crucial to my formulation of this article. Any errors in fact, understanding or emphasis are of course my own.
 
 

Rate This Story

Register or log in to rate
 
Share on Facebook

Readers' Comments (9)

Martin's avatar

Reputation points

Posted 2004/10/30 @ 02:15AM with

A validly argued case, and one which far too few people will undoubtedly take to heart.

I can’t help but think “This is how it should be done, but will the uncomprehending masses not dismiss it as not economically viable?”

In the end, it might all be about helping people understand the importance of often not-thought-of things, and asking them to entrust care of these to those who do think of them…

justin m's avatar

Reputation points

Posted 2004/10/30 @ 23:10PM with

Unfortunately, many average people won’t think about such things until somebody tells them to be worried. That is why internet explorer is still so popular, phishing scams are so prevelant, and Nigerian princes ask me for assistance every other day.

I fear it is a situation where the public will have to be educated and re-educated on a daily basis. What such systems will need is a safeguard that will ensure all these things before an individual piece is allowed to go online and connect with the rest of the network. But how do you promise and ensure those kinds of ethics and morals on the world though?

Michael Honey's avatar

Reputation points

Posted 2004/10/31 @ 10:33AM with

Great article: I haven’t had time to think through all the implications yet, but some thoughts follow.

I feel that “Principle 5 – Be Deniable” (perhaps “refusable” would be better here) deserves primacy. I’m thinking of the opter-out, who has chosen, for whatever reason, to not avail themselves of ubicomp opportunities – perhaps on this occasion only, perhaps all the time. This person might be a general objector to invasive/ubicomp augmentation, a “natural”, or they may just be wanting to work/play incognito. (The desire for anonymity might imply another principle – that an anonymous option always be available).

Should not this person be offered at least a minimal functionality (via a non-ubicomp interface, for example) which is their right? (I’m thinking here of fundamental public infrastructures such as the Disch elevator example, not private/optional niceties.)

I think there’s an off-topic but interesting discussion to be had here regarding the naturals vs. augmented humans in, say, the job market. No doubt, even in the face of possible legislation, there will be some professions which will be de facto only open to augmented individuals [or gestalts…]: should naturals be somehow compensated(/for)?

AG's avatar

Reputation points

Posted 2004/11/03 @ 23:47PM with

Anyone want to start an approval facility?

I think that’s a splendid idea. It would be nice to be able to offer users, consumers, or subjects the information that a panel of knowledgeable people have found the system they’re using meets the Good Housekeeping Seal Of Approval.

It’s a starting place, a basis for informed choice.

Christopher Fahey's avatar

Reputation points

Posted 2004/11/07 @ 01:58AM with

I wonder if the “opt out” criteria isn’t a little backwards. Won’t most people wish to spend the majority of their time “out” of the system, or at least mostly out of the system?

I’d rather see this criteria reversed, with the default mode of a ubicomp world being more compatible with the natural state of the human psyche: solitary and private. You can “opt in” at will, and you can immerse yourself only as far as suits your mood or needs. Some will spend every waking hour immersed in ubicomp, but others may only keep their toes wet enough to be able to stay on top of urgent issues or to receive communications from friends and loved ones. This is the difference between leaving your cell phone at home (or even taking it with you but with the ringer turned off) and being an annoying crackberry addict.

I’m not a Luddite, but I find it hard to imagine a world (in the near future at least) where it would not be considered impolite to have one’s attentions focused on digital activities while engaged in the intimate physical company of other human beings. Nor do I find it appealing to live in a world where my privacy and indeed the solitude of my own mind is considered the exception, not the rule. I want to choose to step in. I don’t want to have to remember to choose to step out.

And again, this is not an “all or nothing” deal. One can be “plugged in” only enough to access one’s personal files on-demand, or to make one’s attention freely accessible only to one’s closest friends, without opening the floodgates and transforming oneself into a constant target for needy employers and persistent digital marketeers. But even informal, benign modes of ubicomp should be acts of volition, of deliberate choice. At least for the near future, the default mode should be nothing: no net, no computers.

You begin each day naked and alone in your own mind, and you take a series of deliberate steps to “jack in” to the ubicomp world. And you end the day as you began it. I shouldn’t have to remember to unplug myself before going to sleep.

It’s bad enough that I sometimes forget to turn off my cel phone when I’m at a nice restaurant with good friends.

-Cf

hect's avatar

Reputation points

Posted 2004/11/07 @ 11:40AM with

interesting piece thanks.

Robert C. Worstell's avatar

Reputation points

Posted 2004/11/09 @ 02:43AM with

Reminds me of Azimov’s Robot Laws, which was another future-looking view of ubicomp.

Metropolitan areas will be more affected by this than rural areas. While GPS will be nearly universal in modern cars and trucks, and satellites overhead already can (and probably do) photograph any area of interest to anyone watching, the need for supervision of a few individuals over many geographic miles is less rewarding than supervising a few million people within a single square mile or less.

So the “Digital Divide” which already slows rural areas from adopting infrastructure which ubicomp would need in order to thrive would also protect those same areas from the supervision.

A point would be to watch for FCC utilization for Federal or other governmental agencies when Digital TV upgrades to two-way systems, much as satellite computers already use – and pay per view, which utilizes telephone uplinks – and could autodial based on usage, or use any phone call as a carrier to get its data out and up to a central database system…

These would be the first points of inroad: Sattelite TV/radio, always-on computer networks via broadband, GPS systems, and cellular phones. In-home networking with IPv6 would be next, since all sorts of computer-enhanced equipment (security system, refrigerator, heating and cooling – even wireless self-starting mechanisms from the car) these could then be the promulgation of ubicomp.

Again, rural areas will be less affected than newer condominiums in/around urban areas which tend to be “breaking edge” in design in order to attract upscale customers. Similarly, inner city areas will also be longer to adopt these “advances.” Where there is the fastest ROI will be the proving ground and fastest expansion of ubicomp.

Artie Turner's avatar

Reputation points

Posted 2005/01/01 @ 06:43AM with

A great article. I sympathize with Greenfield’s skepticism of ubicomp, and his principles for developers are well reasoned. But is ubicomp really inevitable?

I don’t see the kind of solid business case(s) to spur the kind of investment needed for the Greenfield’s future, at least not in the US.

If there’s going to be a ubicomp boom, I would expect the Chinese to be leading the way.

Antiwikipedia.com Antiwikipedia.com's avatar

Antiwikipedia.com Antiwikipedia.com

0 Reputation points

Posted 2006/06/16 @ 09:38AM with

Excellent article. I’ve linked it from http://www.antiwikipedia.com
See: TransEthics and TranshumanSpace