Module 17: Usable Security: Warning Messages

Resources

badssl

Exercise - Review the current state of browser warning messages

  1. Using two different browsers such as Chrome and Firefox, or Safari and Edge, navigate to the baddssl.com web page.

  2. Using both browsers click on various bad links such as expired certificate, self-signed certificate, http (under HTTP), and webpack-dev-server (under Known Bad).

  3. For up to four different bad links on two different web browsers, describe the warning message that you received from the browser.

  4. Give your reaction and opinion regarding the effectiveness of the warning message. Would you "click through" or would you not go to a web site that had this warning message?

  5. For each warning message on both browsers, report which of the NEAT and SPRUCE design parameters where followed and are present in the warning message, and which ones where not followed and are not present in the warning message.

NEAT SPRUCE