Security Hype 7.6-SiteKey (not) broken and Mozilla’s radical Security UI idea
Posted by: bill in S/MIME, SSL, general security, podcast
Security Hype 7.6-SiteKey (not) broken and Mozilla's radical Security UI idea [30:03m]: Play Now | Play in Popup | Download (1881)Bill and Bob peel back the hype on “SiteKey is broken!” claims and find that it’s working as designed. SiteKey isn’t broken, but computer security user interface design IS broken. User’s don’t know how to evaluate when computer systems are behaving securely, and are struggling to stay safe on the Internet.
New MIT & Harvard research indicates that people don’t know that the ABSENCE of security information on a banking website means “danger”. More evidence that security usability - particularly with web browsers - is in a sad state.
Microsoft’s support for EV SSL certificates has several new UI changes in the IE browser in an attempt to help people make security determinations. The Mozilla Foundation is considering taking a radically different approach. Jonathan Nightingale believes that SSL web connections is not about encryption, it’s about identity of the website you’re connecting to. Is the Lock Icon going away!?! Will this actually work and protect users on the Internet? Does this make sense? Send us your thoughts to comments@SecurityHype.com. We’ll try to get Jonathan on the show.
DiscoverCard’s fraud detection process is being exploited by hackers through “phone phishing” attacks. We tried to explain this to the DiscoverCard operator and they just didn’t understand the attack vector. Credit card companies spend millions of dollars printing and issuing credit cards to people, why would they use a different phone number for their customers to call and report fraud? They should be encouraging customers to use a simple, verifiable, and secure process.
What other silly security processes have you run across?
If you like the show, please go to iTunes and add your reviews to our podcast. If you have suggestions for show topics or have comments on this episode please send your feedback to comments@SecurityHype.com
Thanks for listening!


Entries (RSS)