3 ms·
That's exactly what I said. But if the browser doesn't show any indication that it's secure, the problem doesn't exist. The way some browsers behave, there's a
by goldmab 15y ago
That's exactly what I said. But if the browser doesn't show any indication that it's secure, the problem doesn't exist. The way some browsers behave, there's a very strong implication that a website with a self-signed cert is more likely to result in your information being stolen than a website with no encryption. And that's not true.
- burgerbrain 15y agoIf the browser (or even the URL that got the user there) even so much as shows the string "https", that is a form of positive feedback. The only responsible way for a browser to act is to give a strong negative feedback, to more than offset any potential positive feedback.
- goldmab 15y agoChrome (in some situations, I forget which) puts the "https" in red and strikes it through. The implied message: this is HTTPS, but it's broken or bad. The important thing here is that a browser can do something like this without interrupting something that the user actually cares about with an annoying message. Annoying messages are bad.
- burgerbrain 15y agoAnnoying messages are good when it is vital that the user be annoyed (read: informed).