[cap-talk] High level dissonance

James A. Donald jamesd at echeque.com
Sat Feb 23 01:10:32 EST 2008


Toby Murray wrote:
 > If we cannot convey the inherent power of the C:
 > authority (i.e. how dangerous it could be in the wrong
 > hands) users will be doomed to grant it all too
 > easily, thereby ensuring they remain no more secure
 > than they are today.

Rather, we need to protect users from the necessity to
make such hard decisions - and when a user *does* need
to make a hard decision, it should be "Do you trust so
and so?", not "do you trust some incomprehensible
something that you would never understand if we
explained it a hundred times over, so we won't even
bother explaining it."



More information about the cap-talk mailing list