Re: What in practice I want to happen ...
Eivind Tagseth <[email protected]>
| Newsgroups | gmane.comp.web.galeon.devel |
|---|---|
| Message-ID | <[email protected]> |
* Colin Leroy <[email protected]> [021016 10:43]: > On 16 Oct 2002 12:18:26 +0200 Christophe Fergeau > > But let's consider the certificate dialog where you can choose to accept > > it temporarily, reject it or accept it always. There is a very long text > > with this dialog, and the user has to make a choice. I'm quite sure some > > users will be frightened by this dialog, and won't know what to do > > because they will fear to break something. > > I'm not sure this is a problem, l^Husers not really used to computers > usually click "positive" buttons (such as Yes, Ok, Accept, or Continue) You are definately correct about this. But it *is* a big problem. The non-technical user will try to log on to his Internet Banking System, get this dialog because of a dsniffing monkey, and will do as he always does when an unexpected dialog appears; press ok. Thereby handing over the control to his Internet Banking System to the MitM. For users not knowing what they are doing, the default *must* be to disallow access to any https site not certified by a root-CA. Eivind ------------------------------------------------------- This sf.net email is sponsored by: viaVerio will pay you up to $1,000 for every account that you consolidate with us. http://ad.doubleclick.net/clk;4749864;7604308;v? http://www.viaverio.com/consolidator/osdn.cfm