7 ms·
You're conflating the effectiveness of the mechanism with its systemic impact. * Pangram: Yes we should really be discouraging people from putting trust in too
by treyd 22d ago
You're conflating the effectiveness of the mechanism with its systemic impact.
* Pangram: Yes we should really be discouraging people from putting trust in tools like this because they can't be made totally reliable.
* Antivirus: We should be building application environments with robust security models so that malicious software has a limited blast radius (like we do on mobile, like the Linux ecosystem is trying to do with Flatpak, etc).
* HTTPS: HTTPS is a strict upgrade from HTTP so we should be using it everywhere possible. The UI symbols to indicate to users the security expectations they're getting are good practice.
* ssh: This is just an inappropriate comparison.
The HTTPS comparison would make more sense if actually 0.1% of the time when their browser said they were using HTTPS it was just lying.
- fwipsy 21d agoPangram: I'm not arguing against encouraging skepticism; I'm arguing that the technology is not useless. It's good for people to know the limitations, but it's still evidence. Antivirus: "Actually, we should build this hypothetical better thing" is a cop-out. HTTPS: C2PA is a strict upgrade from unsigned photographs, so it should be used wherever possible. SSH: Totally appropriate, the entire point of the discussion is whether it's permissible to the user that they might be more secure.