Edit comment LC-2027 for Mobile Web Best Practices Working Group

Quick access to

Previous: LC-2026 Next: LC-1995

Comment LC-2027
Commenter: casays <casays@yahoo.com>

Resolution status:

b) The guidelines do not state that the users "must be advised
of the security implications of rewriting HTTPS links" BEFORE
they have a chance to perform any operation with the target site.
If the advice takes place after an operation, then users may
unknowingly access the server through the point-to-point HTTPS
connection instead of the end-to-end one.

As an example, a small icon (perhaps representing a question
mark) in a corner of the first page accessed via HTTPS, and
pointing to a description of the consequences of the rewritten
HTTPS links, fully conforms to the guidelines. How many users
would notice it? How many would click on it, take the time to
read its content fully (and understand it), before performing
any further action?
(space separated ids)
(Please make sure the resolution is adapted for public consumption)

Developed and maintained by Dominique Hazaël-Massieux (dom@w3.org).
$Id: 2027.html,v 1.1 2017/08/11 06:43:16 dom Exp $
Please send bug reports and request for enhancements to w3t-sys.org