<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-13998656.post3498462802857196456..comments</id><updated>2009-10-14T21:27:10.289-05:00</updated><category term='Misc'/><category term='Games'/><category term='Security'/><category term='Technology'/><category term='Consumer Advocacy'/><title type='text'>Comments on Brian Hall: The Broken Web Browser Model</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.bhall.com/feeds/3498462802857196456/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13998656/3498462802857196456/comments/default'/><link rel='alternate' type='text/html' href='http://www.bhall.com/2009/10/broken-web-browser-model.html'/><author><name>Brian Hall</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-T3MGqzquQHA/AAAAAAAAAAI/AAAAAAAB8Vc/RbQjP8ddZ2c/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-13998656.post-2018278548683026056</id><published>2009-10-14T21:27:10.289-05:00</published><updated>2009-10-14T21:27:10.289-05:00</updated><title type='text'>Very good point.  Indeed there is a great need to ...</title><content type='html'>Very good point.  Indeed there is a great need to educate users on what to watch out for.  I think at one point Moxie even mentions injecting a &amp;quot;padlock&amp;quot; favicon.ico to further trick the user into thinking that they&amp;#39;re on a secure connection.  Most users I know would probably fall for that.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13998656/3498462802857196456/comments/default/2018278548683026056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13998656/3498462802857196456/comments/default/2018278548683026056'/><link rel='alternate' type='text/html' href='http://www.bhall.com/2009/10/broken-web-browser-model.html?showComment=1255573630289#c2018278548683026056' title=''/><author><name>Brian</name><uri>http://www.blogger.com/profile/06967275817126310908</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp0.blogger.com/_ThjJN3tYwgM/SCGjAIw10qI/AAAAAAAAAFw/I94A1ipcPqY/S220/bhall_simpsons_100x100.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.bhall.com/2009/10/broken-web-browser-model.html' ref='tag:blogger.com,1999:blog-13998656.post-3498462802857196456' source='http://www.blogger.com/feeds/13998656/posts/default/3498462802857196456' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2136077599'/></entry><entry><id>tag:blogger.com,1999:blog-13998656.post-9082288918355299914</id><published>2009-10-14T19:56:13.894-05:00</published><updated>2009-10-14T19:56:13.894-05:00</updated><title type='text'>I suppose that&amp;#39;s true, but in the same breath,...</title><content type='html'>I suppose that&amp;#39;s true, but in the same breath, he&amp;#39;s essentially pointed out why the attack against SSL *doesn&amp;#39;t* work: the user is signalled that the connection is insecure (by various means: a missing padlock icon, a lack of https in the URL, a non-green address bar in IE8). What he&amp;#39;s highlighting is a lack of user-education; users don&amp;#39;t understand https in general.&lt;br /&gt;&lt;br /&gt;I don&amp;#39;t think this is a fundamental failure of browsers, but it is something that browsers need to do a better job of: alerting users that their connection is insecure. It&amp;#39;s difficult to strike a balance between notifying users on the one hand and annoying users on the other (as witnessed by the annoyance of UAC in Windows Vista). How do you unobtrusively alert users when they&amp;#39;re about to do something dangerous?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13998656/3498462802857196456/comments/default/9082288918355299914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13998656/3498462802857196456/comments/default/9082288918355299914'/><link rel='alternate' type='text/html' href='http://www.bhall.com/2009/10/broken-web-browser-model.html?showComment=1255568173894#c9082288918355299914' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.bhall.com/2009/10/broken-web-browser-model.html' ref='tag:blogger.com,1999:blog-13998656.post-3498462802857196456' source='http://www.blogger.com/feeds/13998656/posts/default/3498462802857196456' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2079506965'/></entry></feed>
