3 ms·
Browsers completely stop the page from loading and show a full-page error for a certificate error. There's a huge difference between that and a small icon in th
by briansmith 12y ago
Browsers completely stop the page from loading and show a full-page error for a certificate error. There's a huge difference between that and a small icon in the location bar. Plus, if the red icon that is suggested in that bug report is too loud, a less loud indicator could be used instead.
There's a lot more to designing a UI for this than just changing the icon. For example, when you type "foo.com" into the address bar, browsers generally default to "http://foo.com" http://foo.com" instead of "https://foo.com." https://foo.com." And, consequently, browsers tend to show "http://foo.com" http://foo.com" as "foo.com" to suggest that you don't need to type the "http://" http://" part. All of that needs to change to become a lot smarter in order for this type of idea to succeed. However, it doesn't seem completely unreasonable to consider making all those changes. In fact, I think these changes should be a high priority for browsers makers.
tl;dr: I suggest people brainstorm ways to improve upon the idea to make it workable, instead of trying to shoot it down.
- zobzu 12y agoI wonder how that'd look like with http/2.0. If it goes ahead with certificate"less" https by default i'd wonder if they would use that icon for https websites which dont have a certificate ;)
- codezero 12y agoHonestly, I'd prefer a heuristic that could determine whether https was significant on the current URL. Are there submitted values, cookies of importance, get parameters? There are a lot of reasons https is important and there are a lot of places where it's totally not important. If you draw people's attention to something that isn't seriously important, then those times when the whole screen sends a warning you go, "oh well, I had that red warning going all along and it didn't matter, so why do I care?" I am saying that by pushing a warning where it's not necessary, you diminish the value of any warning.
- briansmith 12y ago> There are a lot of places where it's totally not important. See my other replies on this page for some reasons why I think there are no pages where HTTPS is not important. I agree with you regarding the UI issues and the potential to generate apathy by crying wolf. That's why I think that the specifics of the linked-to proposal won't work. But, I think the general idea is worth investigating. It just requires some user research. Also, the fact that browsers support a non-HTTPS mode at all is really the bigger UI issue. Imagine if HTTPS was the only option. The biggest UI security problems would instantly vanish! That's a big reason why a lot of people are actively working so hard on finding ways to make HTTPS work for everybody on every site.