The death of the line of death
emilymstark.com
emilymstark.com
> security indicators in the URL bar are misunderstood.
it really amazes me how for 10 years we had java applets that can just show an obscure message to the user about "something something signing" and if they press okay they can execute arbitrary code as design (because they consented to running unsigned code which implies that the code can run on your computer with full privileges, and the only way youd know this is if you read about java sandboxing internals for a few hours), and security experts cant find out why the user cant figure out how to be secure. the reason is what people keep saying: everything is broken. all these bullshit HTTPS symbols in the URL bar dont help either, nor does "oh noes self signed blah blah".
> New web platform features have introduced new modalities for displaying web content. For example, the Payment Handler API introduced a new type of embedded browser window for completing payment flows.
which were absolutely never legit. you should never trust a website that wants you to log in to your bank which shows a bank page ostensibly being served by your bank in their own window. its unfortunate that web devs (predictably) took the path of least resistance but thats how it is. everything is broken.
So many tech people think that if there's an explanation it legitimizes the end behavior, but I emphatically disagree with that.
It doesn't matter WHY the browser is popping up a window that is indistinguishable from the surrounding website, it's shitty, compromising, behavior. Any series of decisions that end up with that as the result is mistaken somewhere in the chain, even if the mistake is the lack of the decision "this will make it confusing to users so we can't do it".
I don't use the in-built payment stuff and had no idea it popped up a modal, but when reading the article I absolutely had the same thought you did. Why the fuck would you do that?
And the answer is going to be "user experience" as if allowing a website to style that payment modal comes anywhere near allowing a site to style an inline video player. If you don't think user safety wrt payments isn't more important than "user experience" then what the hell is? Your head isn't on right.
1. Invest in negative security warnings. This is fair, but how would that really work? HTTPS seems like an odd example, given how binary it is. How do you generalize it to online safety? Blocking known bad sites or behaviors is a never-ending game in a world where it costs next to nothing to set up a new phishing site or roll out a new malicious binary.
2. Unphishable credentials. This is reasonable - but what about attacks that don't care about credentials? Again, malicious downloads and plenty of other things that are happening today.
3. App-level content moderation. Sure, but this works only as long as you stay within walled gardens of a small number of platforms and are not an interesting target. What if you go to an URL not ending with .google.com or .facebook.com? What about specific, targeted populations that aren't adequately protected by the heuristics used at that scale?
And it has the benefit of being dramatic and attention grabby!
*Edited for grammar and clarity
Then he mentions mountaineering, and I think Mt Everest, thinking "Thank God they removed some bodies"
And then I see it's webdev. AGREED. "Line of Trust" instead, please
Extensions also appear in the browser toolbar, and aren't always trustworthy.
Edit: early 2000s when browser plugins were able to do practically anything, we would often have people come in with so many “extensions” installed that you could barely see the page you were looking at. Yes, they likely provided some kind of affirmative action to install those, but the user’s intent wasn’t ever to have so much shit installed in their browser that they couldn’t use it. Further evidenced by the fact they were in my store spending $100/hr to have them removed.