Re: Car seatbelts (Was: Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor)
Robert Kaiser <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Boris Zbarsky schrieb: > It doesn't do that, though. It just beeps annoyingly. ;) > > All of this is clearly veering slightly off topic, of course. To bring it back on topic: Should we make the browser beep annoyingly when using a non-secure connection? (I prefer to say HTTP being "non-secure" or "not secure" vs. "insecure" as while that means exactly the same, it's psychologically easier to accept - HTTP is not suddenly becoming "insecure", it's just that it never was secure in the first place.) And that comment about beeping is only half-joking, we probably will need warning to go more intense after some time. OTOH, one issue with the comparison is that in the car example, the user can easily do something to secure themselves and use the seatbelt - while in our case, the user cannot make the site they want to use secure, the website author has to. But the user still wants to use the website and/or its content, so unfortunately we end up "punishing" them for wanting to see that content, and that's a bad experience and makes the user angry, without necessarily making the website author/owner/maintainer react. Unfortunately, sitting at the client side there makes this a difficult situation. KaiRo