Skip to main content

When Friction Pretends to Be Security

28/07/2025 · 1 min read

Rant Alert: Who designs this stuff?

I just tried to book an appointment to pick up my passport at the Bürgeramt in Berlin-Lichtenberg. Yes, in Berlin you need an appointment just to collect your passport – annoying, but I can live with that.

What really drove me up the wall? I had to manually enter all my details – name, email (twice!) – and none of my usual helpers worked: 🚫 no browser autofill 🚫 no copy-paste 🚫 no text expansion tools like Typinator 🚫 not even browser plugins could break the barrier

Someone deliberately built the crap like this. Probably with the classic excuse: “It helps prevent typos in email addresses.”

As if typing everything twice by hand magically improves accuracy. And the cherry on top? The whole mess lives under the domain service.berlin.de. Now that’s a joke with layers.

What can we learn from this? – Friction ≠ Security. Disabling helpful features doesn’t make a service safer – it just makes it worse. – Trust people and their tools. Autofill, clipboard and text expansion aren’t cheats. They’re accessibility tools. – If even browser plugins can’t help you fill a form – you know it’s a hostile design. – Bad UX is bad enough. But when it actively excludes? That’s a11y gone wrong.

This form breaks core accessibility principles: – People with motor or cognitive impairments rely on copy & paste. – Autofill and text expansion are assistive technologies for many. – Forcing manual input and duplicate email fields without alternatives? That’s not thoughtful – it’s exclusion by design.

The worst kind of broken? The kind that pretends to work.

Originally posted on LinkedIn.