Re: Re: Gtk Certificate Dialogs

Eivind Tagseth <[email protected]>
Newsgroups gmane.comp.web.galeon.devel
Message-ID <[email protected]>
* David Adam Bordoley <[email protected]> [030829 05:29]:
> 
> Generally i think the messages are too long. It is important to remember 
> that users don't read these things and the longer your message the more 
> likely it is to be ignored. 

Very true.  Maybe a "More info"-button or something would be nice?

> Also the messages tend to be a little too 
> dooming in my opinion. 

I have to disagree here.  Having worked with internet banking, I'd say they
are too nice.  Especially the "It is possible, though unlikely, that someone
may be trying to eavesdrop your communication with this site, possible
to obtain your confidential information".  Sites that protect themselves
with SSL often protect information that you really don't want to end
up in someone elses hands.  Using dsniff, acting like a man-in-the-middle
is fairly easy, the site will look and behave like normal, but the
man-in-the-middle can view all information being passed through, and
much more seriously, may also intercept the ongoing session (i.e. stop
the user's logout-request and use the cookies to continue the session).

The only thing stopping such a scheme is that warning dialog, if the user
ignores it, that would undermine the concept of ssl completely.

I'd prefer a red dialog with animations and bells and whistles.  If not,
I think a brief text explaining that this site appears to be pretending
to be something it isn't and you really shouldn't go on unless you _know_
that this is ok.

> You should probably talk with someone from the docs 
> team though about improving the wording. They may also have some 
> suggestions for making the dialogs less techno-babble sounding. Some help 
> buttons in these dialogs might even be acceptable. 

True.  Most people will probably not know what a certificate is and
why it is at all...  Writing dialogs for "most people" is very hard though.

> Also i don't like the checkbox on the last dialog. That action should 
> probably be an alternative button like "view cert". In fact isn't the more 
> likely use case to always permanently accept certs for most users? 

The most likely usecase _may_ be to always accept a certificate, but please
note that in the ideal case, the only situations where this would happen
would be if the site was hacked or if there is a man-in-the-middle.  I
think the dialog is correct as it is, we shouldn't make it easy for
users to compromise their security.



Eivind


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.