2 ms·
They shouldn't exactly be optimized for friendliness. In a sense, that's the problem we have now. They should be optimized for security, but right now they're o
by parenthephobia 9y ago
They shouldn't exactly be optimized for friendliness. In a sense, that's the problem we have now. They should be optimized for security, but right now they're optimized for developers and network administrators.
It'd be interesting to see research on how many laypersons understand which way around the "chain of authority" goes for domain names. I can easily imagine somebody not Internet savvy thinking that "facebook.hackable.org" was a legitimate Facebook domain. (And it doesn't help that some organizations spread their site over many domains that - even to a skilled user - are indistinguishable from phishing domains.)
It is unclear how a domain like that could be optimized to ensure a novice user understands that what they're looking at isn't Facebook, even though the domain starts with "facebook" and the page they're looking at looks exactly like Facebook's login page.
One general, slightly off-topic, notion: there should be a protocol whereby a password manager can ask facebook.com what sites are legitimately going to ask for your Facebook credentials - not entirely unlike SPF for passwords. Then even if you search for Facebook in your password manager, it should refuse to automatically provide the credentials to the site.
(More off-topic aside: Password managers should be properly integrated into all browsers. Knowing your passwords should be considered unusual, and actually choosing them yourself downright stupid.).