Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-11-04 Thread carsten.mueller.gl--- via dev-security-policy
Am Sonntag, 20. Oktober 2019 03:59:10 UTC+2 schrieb scott...@gmail.com: > > If I’m right, they might get upset with the removal of the UI. > > Hey Paul, > > To the best of my knowledge the UI isn't being removed, it's simply being > moved to another location. If a consumer wishes to continue

Re: Intent to Ship: Move Extended Validation Information out of the URL bar

2019-10-08 Thread carsten.mueller.gl--- via dev-security-policy
> But the target audience for phishing are uninformed people. People which have > no idea what a EV cert is. People who don't even blink if the English on the > phishing page is worse than a 5-year old could produce. > > You cannot base the decision if a EV indication in the browser is useful

Re: Intent to Ship: Move Extended Validation Information out of the URL bar

2019-10-14 Thread carsten.mueller.gl--- via dev-security-policy
Already the screenshots of the report from 2016 on page 3 show why no normal user can recognize if a website was encrypted or if an EV certificate was in use. The browser manufacturers must agree on a uniform, easy-to-understand presentation of the security indicators and not change them every