Johnathan Nightingale wrote:
> Eddy's screenshots are taken on linux, which is absolutely the least
> noticeable of the three platforms in terms of state transition. The
> discussion around remedying that specific situation is happening (well,
> trying to happen!) in bug 430790.

OK. As a Linux-only person, I wasn't aware of the theme difference. I'm 
less worried now, because Linux users tend to be more aware of these 
things, but at the moment the difference is almost so slight that 
someone with slightly poor sight might miss it even though they are 
looking for it! If we can increase the size of the area that changes 
colour, that would be a great help.

Is there any chance of that happening before release?

> More broadly yes, there is less distinction between http and DV-SSL than
> there is between DV-SSL and EV-SSL. I would urge people interested in
> *that* debate go read bug 414627, where careful arguments were made by
> numerous people in support of various solutions that I think it will do
> no good to re-visit here.

It's actually a slightly different question to the 0 vs. 1 vs. 2 
question about that pref. Displaying the domain is not the only way to 
increase the UI difference brtween http and DV-SSL. Yellow background 
would be another (and I've read your comments on that), or blue 
background to match the button, or something else.

> Which I replied to with some information about the ways we're trying to
> bring out the message here:
>
> http://groups.google.com/group/mozilla.dev.apps.firefox/msg/53570f2c3d3a8516

Right. I can see how we are getting the message out to sites about EV 
adoption, but I'm concerned about how we are going to tell 150 million 
people that they need to check identity when doing financial stuff.

"If the name ain't in green,
  You should flee from the scene"
?

"If there ain't a green name
  Don't be trustin' their claim"
?

> To be honest, my gut reaction is that it doesn't feel necessary -
> clicking will get you that information quicker than a hover, and the
> tooltip is right now a consistent message about verifier, as
> counterpoint to the button's contents (for EV) and popup (for all types)
> being principally focused on owner. But I don't have a really strong
> opinion on it, so if people are interested in this discussion, I suggest
> we file a bug and chase down options.

There are probably more important things to be worrying about this close 
to release.

Gerv

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security

Reply via email to