Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Consider https. That is very easy to use, because the user doesn't have to do anything to use it. The user doesn't need to know anything about encryption.

Doesn't this mean that many users will just click through any errors, thus making https less secure than it could be?

Consider the evolution of warnings. Padlocks were shown in different states and colours, then pop-up dialogue boxes appeared, and now Chrome has an entire red screen with a suitably stern warning.

You're right that https is the easiest form of PKI for users to understand. And they still get it wrong. And that's for encryption that could make a difference to their lives - people could steal their money or their products or whatnot.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: