Re: Car seatbelts (Was: Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor)

Chris Hofmann <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CA+zsDHAWfdvxuNQmkn77kRJSXWBBcZHy_5b-jAfDmeX5mybTxw@mail.gmail.com>
Personally I like the leaky pipe metaphor better.

The problem is not with the site.  Its with the pipe that connects a user
to the site.

The next stage is to explain to all parties what's needed and involved in
taking action to fix the leaky pipes of the internet just enough to make
progress on stampping out surveillance, and future risks of increasing
surveillance.

-chofmann

On Wed, Nov 25, 2015 at 6:10 PM, Robert Kaiser <[email protected]> wrote:

> Boris Zbarsky schrieb:
>
>> It doesn't do that, though.  It just beeps annoyingly.  ;)
>>
>> All of this is clearly veering slightly off topic, of course.
>>
>
> To bring it back on topic: Should we make the browser beep annoyingly when
> using a non-secure connection?
>
> (I prefer to say HTTP being "non-secure" or "not secure" vs. "insecure" as
> while that means exactly the same, it's psychologically easier to accept -
> HTTP is not suddenly becoming "insecure", it's just that it never was
> secure in the first place.)
>
> And that comment about beeping is only half-joking, we probably will need
> warning to go more intense after some time. OTOH, one issue with the
> comparison is that in the car example, the user can easily do something to
> secure themselves and use the seatbelt - while in our case, the user cannot
> make the site they want to use secure, the website author has to. But the
> user still wants to use the website and/or its content, so unfortunately we
> end up "punishing" them for wanting to see that content, and that's a bad
> experience and makes the user angry, without necessarily making the website
> author/owner/maintainer react. Unfortunately, sitting at the client side
> there makes this a difficult situation.
>
> KaiRo
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.