Closed Bug 427665 Opened 16 years ago Closed 8 years ago

Malware warning page should make it clear that merely *visiting* the page is dangerous

Categories

(Toolkit :: Safe Browsing, defect, P5)

defect

Tracking

()

RESOLVED WONTFIX

People

(Reporter: jruderman, Unassigned)

References

()

Details

(Keywords: sec-want, Whiteboard: [sg:want P5])

The warning page for malware should make it clear that merely *visiting* the page is dangerous.  This is especially important now that the malware warning page has a clickthrough link (added in bug 422410).

I don't know what the best way to do this is.  The simple solution of replacing the heading "Reported Attack Site!" with "Visiting this site may harm your computer" would break the current visual design due to its length, and it might be far away from the "Ignore this warning" link.

(There's also the problem that the phishing-warning and malware-warning pages look very similar, which could cause warning-fatigue issues for users who encounter phishing warning pages frequently and then encounter a malware-warning page.)
Whiteboard: [sg:want P5]
Product: Firefox → Toolkit
Matej, do you have any thoughts as to:

- whether or not we should make that change
- how we could phrase the warning to highlight this risk

Currently the warning interstitial reads:

> Reported Attack Page!
> 
> This web page at itisatrap.org has been reported as an attack page and has been blocked
> based on your security preferences.
> 
> Attack pages try to install programs that steal private information, use your computer
> to attack others, or damage your system.
> 
> Some attack pages intentionally distribute harmful software, but many are compromised
> without the knowledge or permission of their owners.
Flags: needinfo?(matej)
OS: Mac OS X → All
Priority: -- → P5
Hardware: x86 → All
I'm not sure I know enough about these pages and their function to recommend whether or not it should be changed, but I would say "Reported Attack Page" sounds scary enough to me that I likely wouldn't proceed and that the suggested version in comment 0 feels like it's roughly saying the same thing, just in more words.

Hopefully that helps.
Flags: needinfo?(matej)
Thanks Matej. Let's keep it the way it is then.
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.