Hacker News new | ask | show | jobs
by lelanthran 1250 days ago
> I literally just said that I agree the UX is poor. Did you read my comment?

But I agree with that comment. The one I disagreed with is:

> Security is not something to sacrifice to gain less angry users.

Maybe I should rephrase (I'm a notoriously poor communicator) ...

Sometimes (like in the cases I pointed out), the security messages and warnings must be sacrificed because the practical security either doesn't matter (like hackernews) or hasn't been compromised (like the 5m after midnight example).

1 comments

Swallowing certificate expiration is not acceptable security, no. _Something_ needs to happen. What else is there than warning the user?

That being said, I've never liked how certificates are designed to begin with. They're overly complicated for very little gain IMO.