One Aging Geek

Thursday, November 13, 2003

Security snake oil

Security snake oil

To me, SSL security certificates have always seemed particularly stupid usability-wise. As I understand it, the system works like this:
  1. Alice trusts Fred.
  2. Fred trusts Bob.
  3. Bob gets a certificate of trustworthiness from Fred.
  4. When Alice visits Bob’s page, Bob shows Alice his certificate to demonstrate his trustworthiness.

The problems with this system are as follows:

  1. Alice doesn’t really trust Fred.
  2. Fred doesn’t really trust Bob.
  3. Getting a certificate is too hard, so Bob doesn’t bother.
  4. When Bob shows Alice his certificate, Alice isn’t paying attention.