Closed Bug 1355171 Opened 9 years ago Closed 9 years ago

Do not display exclamation point in URL-bar for https connections

Categories

(Firefox :: Site Identity, defect)

52 Branch
defect
Not set
normal

Tracking

()

RESOLVED WONTFIX

People

(Reporter: grgwmsm, Unassigned)

Details

Attachments

(1 file)

Attached image screenshot.png
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Safari/602.1.50 Build ID: 20170210223443 Steps to reproduce: Visit a secure (https) webpage (e.g., https://bugzilla.mozilla.org/). Actual results: In the security field of the URL-bar (screenshot attached), an exclamation point with a circle around it is shown next to the green lock icon. Expected results: That exclamation point should not be shown on secure connections. This is confusing to people. I keep getting calls from clients because they think something is wrong with the secure connection (i.e., that there is a problem with the security and that the exclamation point is displaying to alert them to that fact). Security notices need to be simple. Google Chrome does this the best right now. They have effectively idiot-proofed it by showing the entity's name for EV Certs and simply showing "Secure" for non-EV. I would advise this for Firefox. But at a minimum, the exclamation point should be removed because it is confusing, informs the user of nothing, and is counter-productive to quickly assessing the integrity of the connection.
Component: Untriaged → Site Identity and Permission Panels
It's not an exclamation point, it's an "i" :/ Thanks for noting your client's concerns with this, though I must say that if they are using Firefox more than occasionally they should have noticed it appears on literally every page. In any case, it was a conscious design decision that will not be overturned just now, especially as it also serves for displaying a web permissions indicator. > Google Chrome does this the best right now. They have effectively idiot-proofed it by showing the entity's name for EV Certs and simply showing "Secure" for non-EV. We consider displaying "Secure" for random HTTPS pages a step back in fighting phishing, and are consequently not going to do that. Your concerns/suggestions will be considered in the future. Feel free to watch this component if you're interested in changes in the identity UI.
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → WONTFIX
> We consider displaying "Secure" for random HTTPS pages a step back in fighting phishing, and are consequently not going to do that. Random HTTPS pages? Are you saying it should be reserved for only EV pages? Or are you saying a "random" HTTPS page is no more secure than an HTTP connection? Nobody is going to enter a credit card into HTTP. And in everyone's daily lexicon, that makes an HTTPS site (even a non-EV one "Secure"). I don't think you guys are taking the right approach with your thinking on this. Your rationale is too esoteric. > Thanks for noting your client's concerns with this, though I must say that if they are using Firefox more than occasionally they should have noticed it appears on literally every page. In any case, it was a conscious design decision that will not be overturned just now, especially as it also serves for displaying a web permissions indicator. Well, that is the primary problem I was pointing out. When something is perpetually displayed across all contexts (preventing it from having any information value because it is a perpetual fixture) it can indicate a problem. What the hell is that "i" showing all the time for? What is its purpose? What is it supposed to communicate? It shows when there is HTTP and it shows when there is HTTPS. It's just always there which means it communicates nothing about the page. Hopefully you guys will rethink your Identity UI. The "i" is just one element that is problematic.
(In reply to Greg from comment #2) > > We consider displaying "Secure" for random HTTPS pages a step back in fighting phishing, and are consequently not going to do that. > > Random HTTPS pages? Are you saying it should be reserved for only EV pages? > Or are you saying a "random" HTTPS page is no more secure than an HTTP > connection? Nobody is going to enter a credit card into HTTP. And in > everyone's daily lexicon, that makes an HTTPS site (even a non-EV one > "Secure"). I don't think you guys are taking the right approach with your > thinking on this. Your rationale is too esoteric. > It's not all about network security. The content on a secure HTTPS page could be as malicious as the content on an HTTP page. Displaying a "Secure" label next to a phishing page that got a free HTTPS certificate doesn't sound great to me. The vibrant green is very clearly noticeable and users might tend to ignore the hostname in the urlbar even more than they already do. We have the in-content warning which alerts the user when it really matters, that is when entering their credentials on an insecure page. > > Thanks for noting your client's concerns with this, though I must say that if they are using Firefox more than occasionally they should have noticed it appears on literally every page. In any case, it was a conscious design decision that will not be overturned just now, especially as it also serves for displaying a web permissions indicator. > > Well, that is the primary problem I was pointing out. When something is > perpetually displayed across all contexts (preventing it from having any > information value because it is a perpetual fixture) it can indicate a > problem. What the hell is that "i" showing all the time for? What is its > purpose? What is it supposed to communicate? It shows when there is HTTP and > it shows when there is HTTPS. It's just always there which means it > communicates nothing about the page. Hopefully you guys will rethink your > Identity UI. The "i" is just one element that is problematic. Alright, I noted your concern, thank you. Feel free to open bugs for the other things that you consider problematic.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: