The screech of iron on iron at the Manggarai station isn’t a single sound; it is a physical weight that presses against the eardrums, accompanied by the smell of ozone and the faint, sweet scent of clove cigarettes clinging to the humid morning air. It is .
The KRL commuter train to Central Jakarta is a pressurized cylinder of human ambition and exhaustion. Within this metal tube, thousands of thumbs are performing the same frantic ballet.
Putri is wedged between a woman with a damp umbrella and a man whose shoulder is currently serving as her only stability. She has exactly before her stop. She needs to check a support message regarding a pending transaction on her gaming account-nothing life-altering, but the kind of loose thread that itches at the back of the mind until it’s pulled. She opens the app.
The Commuter’s Window
Attention is a dwindling resource before the next station.
The Six-Second Lifetime
The screen demands her PIN. She taps it out, her thumb moving with the muscle memory of a pianist. Then comes the SMS One-Time Password (OTP). She waits. The signal inside the metal car is flickering like a dying candle.
The code arrives late, a lifetime in commuter seconds. She switches apps, copies the six digits, switches back, and pastes.
The screen changes. It’s a security question she hasn’t seen in two years: What was the name of your first pet? Putri stares. She remembers the cat, but did she capitalize the ‘M’ in Meowster? She tries three variations. On the third, the lock turns.
But the gate isn’t open yet. Now, the screen presents a grid of grainy images. Select all squares with traffic lights. Her thumb stabs at the pixels. She misses a tiny sliver of a yellow light in the corner square. The grid refreshes. Select all squares with crosswalks.
By the time the fifth pop-up appears-a standard “Account Protection Agreement” or perhaps a “New Login Detected” warning-Putri is no longer a conscious agent of security. She is a biological machine seeking a “Next” button.
When the bright blue rectangle appears at the bottom of the screen, she taps it instantly. She doesn’t read the text. She doesn’t check if the prompt is asking for permission to wipe her data or simply confirming her location. She just wants the wall to vanish.
Analyzing the prompt, checking permissions, evaluating risk.
Muscle memory, clicking for removal, seeking the exit path.
Silence Over Safety
As someone who installs medical imaging equipment for a living, I see this same erosion of the soul every day. I recently won a heated argument with my supervisor about the sensitivity of the alarm sensors on a new line of portable X-ray units.
I insisted-with the kind of irritating certainty only a technician who hasn’t spent on a ward can possess-that the alarm for “improper caster alignment” should be loud and persistent. I argued that security and safety are binary: either it’s right, or it’s wrong. I won the argument. The units were shipped with my high-sensitivity settings.
Two weeks later, I visited the hospital. Every single unit had a piece of medical tape stuck over the alarm speaker. The nurses had become so habituated to the constant, “correct” warnings that they had silenced the machine entirely. My “win” for safety had created a vacuum of total silence where even a critical failure would now go unheard.
I was right about the specifications, but I was spectacularly wrong about the human being. The security teams for digital platforms are currently winning the same kind of argument. They look at a list of five security checkpoints and see a fortress.
They see a PIN, an OTP, a security question, a captcha, and a final confirmation as five distinct layers of protection. In their spreadsheets, the “Cost of Attack” for a hacker goes up with every layer.
The “Attention Tax”: Every layer depletes the user’s finite budget for skepticism.
The Finite Budget of Skepticism
But they are failing to account for the “Attention Tax.” There is a counterintuitive reality in cognitive psychology: the human brain has a finite budget for skepticism. Every time you ask a user to prove they are “themselves,” you draw from a pool of cognitive energy.
A study on “Alarm Fatigue” in clinical environments suggests that after the third consecutive interruption, the human brain stops processing the content of the alert and begins processing the removal of the alert. In plain terms, if you show a person three warnings, they will read them. If you show them five, they will treat the fifth one like a fly that needs to be swatted.
By the time Putri reaches that fifth screen on the train, she is more dangerous to her own account than any hacker could be. She has been trained by the interface to be reflexive rather than reflective. This is the great paradox of modern digital life: we are building walls so high that the only way for the owners to get in is to stop looking at the bricks.
This habituation isn’t confined to a single app. It’s an exportable behavior. When a user spends their morning being conditioned to click through five layers of friction just to check a message, they carry that “click-through” reflex over to their banking app, their corporate email, and their social media.
We are effectively training a generation of users to be the perfect victims for “consent phishing,” where a hacker simply waits for the user to be tired enough to tap “Allow.”
Platform designers often overlook the fact that the most secure system is the one the user actually understands. For instance, when looking at a complex digital ecosystem like
which offers a vast catalogue of real-money games from sports betting to live casinos under a single account, the goal of the interface should be to reduce unnecessary hurdles.
If the transition between a sports book and a slot game required a new OTP every time, the user would eventually stop caring about what they were approving. The value of a unified account is not just convenience; it’s the preservation of the user’s attention for when it actually matters.
The Architecture of Surrender
The “security” of five layers is a mirage. It assumes that Putri is a stationary observer with infinite time. It doesn’t see the screeching train, the person leaning on her shoulder, or the four-minute window before she has to jump onto the platform. It doesn’t see that her attention has been completely liquidated by the time she gets to the actual data.
I think back to that argument I won about the X-ray alarms. I felt so smug when the supervisor finally sighed and signed off on my plan. I had “protected” the equipment. But in reality, I had just made the equipment an adversary to the people using it. When we treat security as a series of obstacles to be overcome rather than a conversation with the user, we turn our customers into the very vulnerability we are trying to patch.
The industry needs a model of security that accounts for “Attention Exhaustion.” We need to stop counting layers and start measuring the cognitive load of a login. If a user is prompted for a PIN and an OTP, maybe the third layer shouldn’t be a captcha.
Maybe the third layer should be “Silence.” Maybe we should trust the first two proofs enough to leave the user’s remaining attention intact for the moment they encounter a genuine threat.
Because right now, the hackers aren’t trying to break our encryption. They are just waiting for us to get to the fifth screen. They are waiting for the moment when the screech of the train and the delay of the SMS and the graininess of the traffic-light images finally break our will.
Putri’s train pulls into the station. She finally sees her message. It’s a simple confirmation of a 50,000 rupiah credit. She tucks her phone into her pocket and disappears into the sea of commuters.
She has no idea what that fifth pop-up said. She doesn’t remember tapping it. She is “secure” according to the logs, but in the quiet spaces of her habit-formed brain, she has just learned that the way to survive the digital world is to stop reading and start clicking.
I was wrong about the alarms, and the industry is wrong about the walls. We don’t need more locks; we need better ways to remember why we’re locking the door in the first place. Until we respect the limited currency of human attention, we are just building faster ways to help people give their keys away.