Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Watch Google decide that the advanced option is a security problem, and remove it, and Mozilla gladly playing along because "security" and "users are dumb".

The "owner" is no longer in control, and has not been ever since the web became "app-ified".



It's not that 'users are dumb' it's that the only way to keep users and lazy IT staff from telling people to just click through the warnings is to make it difficult to do so. How else can you fight the 'click through until it works because I have work to do' mentality?

Browsers could have bright red flashing lights telling users that they're currently being phished and users would still enter their credentials because doing nothing isn't seen as a meaningful alternative action.


But there's no UI difference between "you're currently being phished", and "there's been a proof-of-concept white paper, that shows a nation-state level actor could theoretically decrypt this communication by spending a few hundred million".


Browsers already do this with HSTS.

https://tools.ietf.org/html/rfc6797#section-12.1




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: