Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> > Firefox still doesn't say anything about the *server* being secure or > > not, it says "Secure Connection". This won't change. > > > We are in full agreement. Firefox does secure connections. Within a > security model (assumptions). What Firefox doesn't do is security. I feel my concern here is being missed; if users interpret it to mean a site is insecure rather than the connection not being encrypted which is likely (without craeful consideration by mozilla) then you may be damaging a site (possibly libellous) that uses TLS on some pages but is actually far more secure than facebook that now uses encrypted connections for every page but allows the server to write it's own pages for example. -- KISSIS - Keep It Simple So It's Securable