[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Draft Charter




At 9:18 AM +0200 8/17/07, Seppo Lindborg (JO/LMF) wrote:
This the current situation, but is it OK, or even acceptable? Wouldn't
it be more appropriate approach that there were no ready trust
assumptions or settings in the tool, and the user would add his, either
from some ready file, or case-by-case when he surfs?

Seppo Lindborg

For some, sophisticated users this could be a great improvement. For 99% of the users it would likely create more opportunities for social engineering. We have years of experience, plus a nice study by folks at CMU, showing that the average user is clueless about SSL/TLS, lock icons, etc. and is easily fooled. That's why phishing is so successful.

Steve