Re: Fwd: Re: [Cryptography] Encryption opinion
"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, August 28, 2014 02:12, Raoul Duke wrote: >> In other words: I do not believe the problem of usable ocap security and >> user interfaces is solved. To that extent, the author is in my view >> correct. > > and in my mind: in other words, *especially when it comes to > usability*, if it hasn't shipped and been used by 10k+ people, it > hasn't provably been solved. :-) > > (and those 10k aren't allowed to be e.g. only people with security > clearance because they would already be in the mindset.) When it comes to usable security we actually have the problem that a 'security awareness' mindset, at least how people tend to get trained will reduce both the perceived usability and perceived security of solutions that are in sync with peoples natural disposition to delegation based patterns of interaction. You can more easily create usable security for children (or most many non IT-savvy senior citizens for that matter) with a blank mindset to both user interfaces and security than for people who have been using Pavlovian password-popup security solutions for decades and the security awareness training to compensate. The big problem is: how do you create a fearless usability path for people poisoned with a combination of the Pavlovian password-popup solutions and a 'security awareness' mindset? > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > >