3 ms·
"[getting] mixed content issues worked out" seems like such an incredibly weak signal to determine whether someone is trustworthy "with the security of my money
by blake8086 14y ago
"[getting] mixed content issues worked out" seems like such an incredibly weak signal to determine whether someone is trustworthy "with the security of my money". Is this really the best tool you have available to decide whether to trust or not?
- simonbrown 14y agoIf someone doesn't take care to make sure there are no mixed content errors, they may be less likely to take the care to make sure there are no other obvious security problems in their system, which handles money.
- drivebyacct2 14y agoIt's the same as someone sending my password in plaintext. It's a trust issue and a miserable first impression with something as complex as trusts.
- latortuga 14y agoI totally 100% agree with you but I'm not the average web user who will see a red lock icon with an X over it and think "these guys aren't running a secure site". As web-savvy folks, sure, we know that it's a basic change and the security shortfall is minor (potentially not, though! there's a reason for mixed content warnings). You're average user has to be conditioned to even look for the lock or the https and seeing a big red X over it isn't doing anything for trustworthiness.
- simonbrown 14y agoThe security shortfall isn't minor. In Chrome (other browsers don't distinguish the severity), a crossed-out HTTPS means that a MITM attacker has the ability to run arbitrary javascript on the page. It doesn't even bother running severe mixed content now, though.