Sarcasm aside, I'm a software engineer with a very superficial understanding of the certificate system. I'm not even convinced of my own ability to notice when something's wrong.
Sarcasm aside, I'm a software engineer with a very superficial understanding of the certificate system. I'm not even convinced of my own ability to notice when something's wrong.
Because that's what you're doing when you say shit like this. Thinking like that is what gave us forced automatic updates.
The text of one of your post's siblings is:
> A root lets you make a valid cert for any domain. It can be used to create a man-in-the-middle attack if paired with a proxy.
If you were to walk down the street tomorrow and ask 10 people to define "cert", "domain", "MITM", and "proxy" I'd wager you'd get 0 correct responses. I'd also wager those 10 people use computers every day -- and I don't think that's a problem. You shouldn't have to study and understand byzantine systems just to use a computer.
Could the message explain the problem better? Maybe, but when you characterize the user the way the parent did, you're not going to stop there, you're going to make them jump through all sorts of hoops or just outright deny the ability all together in the name of saving them from themselves, and that's a huge pain in the ass for the people who do know what's going on and are just trying to get some shit done and use their computer as the tool it was meant to be.
[1]Even if the user knew what it was saying it seems unlikely that they'd think it was malicious. They trust blizzard enough to install their software anyway, so if blizzard says they need this thing, why wouldn't they say ok?