Laurie: Improving SSL certificate security
Laurie: Improving SSL certificate security
Posted Apr 7, 2011 11:50 UTC (Thu) by tialaramex (subscriber, #21167)In reply to: Laurie: Improving SSL certificate security by jthill
Parent article: Laurie: Improving SSL certificate security
Red or missing icons, "Are you sure?" messages, changed site layout, missing authentication steps, none of those clue in the ordinary users Microsoft studied that something is wrong. A Firefox-style full-page warning which requires considerable extra steps tugs at them slightly, but not enough to stop most from continuing to enter valuable financial details.
Users don't have the sophistication we assume in our security designs. Even in djao's much simplified system.
SSH works better mostly because it's used by more technical users. Boring, but true.
Any system that doesn't have a hard stop won't be effective. The response to any validation failure, security problem, error etc. has to be "You can't view that website". No "If you're really sure click this" because every single ordinary user will click the button for an easier life. It's just human nature.
