Re: Proposal: Marking HTTP As Non-Secure

Eitan Adler <[email protected]> Fri, 29 Jan 2016 19:09:19 -0800
Newsgroups gmane.comp.web.blink.devel,gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <CAF6rxgmTDvCNoY9=qVbuzQ5zyWmNR1tetNgEdm5hSPe+qZREeg@mail.gmail.com>
On 29 January 2016 at 13:09,  <[email protected]> wrote:

> There is little inherently "broken" about HTTP (without the "S").  It has security limitations which it's audience accepts.  Over the years people have been trained to look for proactive signs of security (https, green lock, etc) when they are doing activities that are sensitive (email, banking transactions, etc).

There is a ton of UI/UX research that people do not notice the absence
of positive indicators.  One can train as much as they want, but the
training has not worked to date.


-- 
Eitan Adler

-- 
You received this message because you are subscribed to the Google Groups "blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].