Re: What in practice I want to happen ...

Eivind Tagseth <[email protected]>
Newsgroups gmane.comp.web.galeon.devel
Message-ID <[email protected]>
* Colin Leroy <[email protected]> [021016 10:43]:
> On 16 Oct 2002 12:18:26 +0200 Christophe Fergeau

> > But let's consider the certificate dialog where you can choose to accept
> > it temporarily, reject it or accept it always. There is a very long text
> > with this dialog, and the user has to make a choice. I'm quite sure some
> > users will be frightened by this dialog, and won't know what to do
> > because they will fear to break something. 
> 
> I'm not sure this is a problem, l^Husers not really used to computers
> usually click "positive" buttons (such as Yes, Ok, Accept, or Continue)

You are definately correct about this.  But it *is* a big problem.  The
non-technical user will try to log on to his Internet Banking System, get
this dialog because of a dsniffing monkey, and will do as he always does
when an unexpected dialog appears; press ok.  Thereby handing over the
control to his Internet Banking System to the MitM.

For users not knowing what they are doing, the default *must* be to disallow
access to any https site not certified by a root-CA.



Eivind


-------------------------------------------------------
This sf.net email is sponsored by: viaVerio will pay you up to
$1,000 for every account that you consolidate with us.
http://ad.doubleclick.net/clk;4749864;7604308;v?
http://www.viaverio.com/consolidator/osdn.cfm
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.