Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Users inundated with pop-ups
Scott Granneman, 2005-12-12

There are many examples where users are now being inundated with pop-up messages asking them to respond to things they don't know about or don't understand, and it leads to weaker security overall.

Comments Mode:
Users inundated with pop-ups 2005-12-13
Erik Norgaard (1 replies)
Firefox "install extensions" popup now has a timer that simply does not let you press OK for 5 seconds.

This is neat: It cleverly disables that "just click OK" reflex and - at least first time - makes you read the message.

I do think that users should be asked to accept the responsibility of their actions, and this requires their confirmation. Did you ever read this:

http://www.ranum.com/security/computer_security/editorials/d
umb/

The six dumbest things in computer security, all boils more or less down to one: default permit.

Noone should enable a default permit policy on behalf of others. The IE choice is the right choice in this respect. If it would then be enhanced with a timer like that in firefox, we're getting closer.

And add to that, first time the popup is shown, more detailed information should be shown with a disabled next button that will be enabled after some time. If the user does not select "default permit" that message can be skipped subsequently.

Yes, it's anoying for users. But, I'd rather annoy users than become implictly responsible for their errors because I chose default permit on their behalf.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/374/32823#32823
Re: Users inundated with pop-ups 2006-01-10
Anonymous
Users inundated with pop-ups 2005-12-20
3mu180r
Users inundated with pop-ups 2005-12-23
Alexey Vesnin
OSX? Huh? 2005-12-23
Penguinisto
Pop-up Fatigue 2006-06-27
Andrew







 

Privacy Statement
Copyright 2009, SecurityFocus