Review/improve the counterfeit/verify warning in key assistant resolve view.
Categories
(MailNews Core :: Security: OpenPGP, enhancement)
Tracking
(Not tracked)
People
(Reporter: KaiE, Unassigned)
Details
In the "resolve" view of the OpenPGP key assistant (step two), the screen where we ask the user to select the key they want to accept, we also show a warning message.
With bug 1767592 that warning message says:
"Avoid accepting a counterfeit key. To ensure you have obtained the right key you should verify it."
Magnus asks that we further improve that string.
Please read the discussion found here:
https://phabricator.services.mozilla.com/D145438
(search for the word counterfeit, and see the comments below that).
My arguments on Magnus' latested comments are, I want to have some kind of initial warning (like the text about counterfeit). And I want to avoid introducing separate instructions for checking vs verification. And I think the sentence in that dialog shouldn't be too long (which means, a short sentence has the risk for unclarity). My intention is really to ring a bell, so the user raises an eyebrow, and possibly reads the "learn more" link, and possibly clicks "view key" to verify it with the correspondent.
| Reporter | ||
Updated•4 years ago
|
Comment 1•4 years ago
|
||
I'm not sure about this, sorry.
The text seems clear enough, and we offer a "leader more" link beside it which it should maybe point to a more detailed explanation of what a counterfeit key is.
In general, I always recommend to not write long description or introduction text in the UI, and only use short descriptions and one liners when possible, to not make the UI "heavy" and hard to digest.
Long text are usually skipped and not read at all. Maybe this is more a "support article worthy" type of solution.
We could also consider reaching out to a UX copywriter as a temporary contractor to go through our strings and suggest improvements.
Comment 2•4 years ago
|
||
I would be fine with completely removing this notice as well. I don't think it adds value at least in it's current form, which is confusing since the user is at the stage of accepting, not verifying, the key.
The text I had suggested was "If you don’t know whether you have the right key, you should ask the recipient for their key fingerprint and check it corresponds to the fingerprint of the key you obtained. Asking that over email is not safe." That at least conveys the possibility that it's not the right key, and tells users how to proceed next. The current text doesn't help at all: very few users will ever really see a counterfeit key, nor would they understand what that is. The text as is would suggest to a naive user to accept the key, set the state to verified, and then it's all safe, because it's mixing up what verified means.
| Reporter | ||
Comment 3•4 years ago
|
||
Alex said the string is acceptable.
We missed the deadline for changing the string for the 102 release, because the responses came on the day of the deadline,
so we aren't able to immediately provide a follow-up fix.
This means the string is now part of our product just like all the other strings, and I suggest to wait for user experience and feedback prior to considering amendments to it.
Description
•