1 Feb 2007 07:13
Re: Study questions EV certs effectiveness?
beltzner <mbeltzner <at> gmail.com>
2007-02-01 06:13:52 GMT
2007-02-01 06:13:52 GMT
On 1/30/07, Ka-Ping Yee <mozilla <at> zesty.ca> wrote: > That's interesting. Where is the design discussion about the UI taking > place? There's been no real design discussion about how to surface EV certificates in Firefox yet, really. But I'm pretty well established on record as saying that the red/yellow/green treatment proposed by IE, while an incremental improvement over what we have now, also represents an oversimplification of a bunch of concepts into a set of disingenuous "danger!", "caution!" and "safe!" metaphors. Here's a set of equations I like to repeat whenever I notice anyone's listening - trust me, it's awkward at bus stops - and which are also pretty tied to my disdain of the "green bar" UI: EV != safe EV = validated identiy SSL/TLS != safe SSL/TLS = encrypted conduit Being able to talk about validated identity is indeed quite interesting, but advertising "get the green bar"[1], "go green"[2] or telling users that they are safe when they see a green URL bar all cause concern in my mind. As for the future, I'm not sure that dev.security is the right place for discussions of the UI. It's the right place for discussions of the EV specification, for discussion of our plans to be able to detect, parse and make EV metadata available, but the front end design of how(Continue reading)
So a prominent section in the address bar dedicated to the
lock and additional information if the page is secured, would attract
more attention than currently. I think the combination of both steps
would bring an improvement to FF.
RSS Feed