Re: UI for secure web and email

2007-10-04 Thread Albert Cahalan
On 10/4/07, C. Scott Ananian [EMAIL PROTECTED] wrote: On 10/3/07, Albert Cahalan [EMAIL PROTECTED] wrote: The usual secure site icon and bad certificate warnings have lots of problems. Note that security in the browser has been *extensively* studied in academia, and there are numerous

Re: UI for secure web and email

2007-10-04 Thread C. Scott Ananian
On 10/4/07, Albert Cahalan [EMAIL PROTECTED] wrote: Specificly about the UI, or just security in general? Both. They are strongly related in the case of the browser. XSS and similar can be defeated later. Holding up security-related UI improvements is no good. I'm not advocating holding up

Re: UI for secure web and email

2007-10-03 Thread C. Scott Ananian
On 10/3/07, Albert Cahalan [EMAIL PROTECTED] wrote: The usual secure site icon and bad certificate warnings have lots of problems. Note that security in the browser has been *extensively* studied in academia, and there are numerous suggestions for improvements in the literature. We should