6 ms·
The browser could just not show the "secure" visuals, instead of making us click through another page.
by goldmab 15y ago
The browser could just not show the "secure" visuals, instead of making us click through another page.
- wladimir 15y agoWell, the warnings are only shown once. Once you import the self-signed certificate into your keystore, it never bothers you again (unless the certificate changes). This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...
- goldmab 15y agoIt's a usability problem. Firefox (at least 3.x) does a full-on freak-out if the cert is untrusted, despite the fact that the site is no more unsafe than an unencrypted website. Your statements about what should happen are only true if you are requiring encryption for everything that you do. On the web, it's assumed (although most people don't actually know this) that your information is not secure unless you see the green bar or whatever the security visual is on your particular browser. This brings me back to smanek's point. We have three levels of security: no SSL, untrusted cert, trusted cert. Nothing about the first level is superior to the second level, except for the possibility of a false sense of security. Therefore, a browser should not freak out more in the second situation.
- burgerbrain 15y agoAh, but HTTPS with unsigned certs are less secure than plain old HTTP. Or more accurately, for all intents and purposes they are exactly as secure, but carry an unearned sense of security. Unjustified senses of security are a very very dangerous thing.
- goldmab 15y agoThat's exactly what I said. But if the browser doesn't show any indication that it's secure, the problem doesn't exist. The way some browsers behave, there's a very strong implication that a website with a self-signed cert is more likely to result in your information being stolen than a website with no encryption. And that's not true.
- burgerbrain 15y agoIf the browser (or even the URL that got the user there) even so much as shows the string "https", that is a form of positive feedback. The only responsible way for a browser to act is to give a strong negative feedback, to more than offset any potential positive feedback.
- goldmab 15y agoChrome (in some situations, I forget which) puts the "https" in red and strikes it through. The implied message: this is HTTPS, but it's broken or bad. The important thing here is that a browser can do something like this without interrupting something that the user actually cares about with an annoying message. Annoying messages are bad.
- burgerbrain 15y agoAnnoying messages are good when it is vital that the user be annoyed (read: informed).