Re: Re: Gtk Certificate Dialogs
Eivind Tagseth <[email protected]>
| Newsgroups | gmane.comp.web.galeon.devel |
|---|---|
| Message-ID | <[email protected]> |
* David Adam Bordoley <[email protected]> [030829 05:29]: > > Generally i think the messages are too long. It is important to remember > that users don't read these things and the longer your message the more > likely it is to be ignored. Very true. Maybe a "More info"-button or something would be nice? > Also the messages tend to be a little too > dooming in my opinion. I have to disagree here. Having worked with internet banking, I'd say they are too nice. Especially the "It is possible, though unlikely, that someone may be trying to eavesdrop your communication with this site, possible to obtain your confidential information". Sites that protect themselves with SSL often protect information that you really don't want to end up in someone elses hands. Using dsniff, acting like a man-in-the-middle is fairly easy, the site will look and behave like normal, but the man-in-the-middle can view all information being passed through, and much more seriously, may also intercept the ongoing session (i.e. stop the user's logout-request and use the cookies to continue the session). The only thing stopping such a scheme is that warning dialog, if the user ignores it, that would undermine the concept of ssl completely. I'd prefer a red dialog with animations and bells and whistles. If not, I think a brief text explaining that this site appears to be pretending to be something it isn't and you really shouldn't go on unless you _know_ that this is ok. > You should probably talk with someone from the docs > team though about improving the wording. They may also have some > suggestions for making the dialogs less techno-babble sounding. Some help > buttons in these dialogs might even be acceptable. True. Most people will probably not know what a certificate is and why it is at all... Writing dialogs for "most people" is very hard though. > Also i don't like the checkbox on the last dialog. That action should > probably be an alternative button like "view cert". In fact isn't the more > likely use case to always permanently accept certs for most users? The most likely usecase _may_ be to always accept a certificate, but please note that in the ideal case, the only situations where this would happen would be if the site was hacked or if there is a man-in-the-middle. I think the dialog is correct as it is, we shouldn't make it easy for users to compromise their security. Eivind ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf