Security and Convenience

I received this on a form I submitted incorrectly today.

- Security is using HTTPS to encrypt traffic between my browser and the web server.

- Security would be to have the page automatically time out and redirect to a page without any of my personal information.

- Making me re-enter something I just typed because I forgot to fill out a form field is not added security, it's just inconvenient and annoying.

The same is true for sites that believe using fields with TYPE="PASSWORD" to mask the text somehow increases security. I have no empirical evidence, but I'm sure those forms are re-submitted significantly more than non-obscured counterparts. At the very least it makes users want to bite your face.

 

Leave a Reply


© 2007-2012, Corey Gilmore | Posts RSS Feed | Comments RSS Feed | Contact

 

The views expressed on these pages are mine alone and not those of any past or present employer. All information presented on this site was obtained lawfully and not through disclosure under the terms of an NDA.