by okneil on 4/1/19, 3:50 PM with 12 comments
by hannob on 4/1/19, 4:18 PM
I still have no idea what they have found. Far too little info to estimate how relevant this is.
by _bxg1 on 4/1/19, 4:04 PM
Alternately, an HTTPS implementation that can silently update itself without admin permissions like browsers can. The web moves too fast for manual security patches.
by mholt on 4/1/19, 4:12 PM
That's one of the reasons why, in my thesis (which I defend in... 1 week!), I propose replacing replacing security indicators with risk indicators [1]. I think technical properties of a web page, in conjunction with the context of specific interactions, can be used to determine whether the interactions might be risky. By informing users of risks they may be taking, they feel more confident making their own trust decisions.
(Meanwhile on the back-end: as a web server developer, I'm trying to find ways to make it easier to do upgrades when vulnerabilities in protocols are fixed, etc. It's also hard.)
by herodotus on 4/1/19, 4:03 PM
by ravenstine on 4/1/19, 4:05 PM
by zelon88 on 4/1/19, 4:28 PM