This document:Public document·View comments·Disposition of Comments·
Nearby:Mobile Web Best Practices Working Group Other specs in this tool Mobile Web Best Practices Working Group's Issue tracker
Quick access to LC-1995 LC-1996 LC-1997 LC-1998 LC-1999 LC-2000 LC-2001 LC-2002 LC-2003 LC-2004 LC-2005 LC-2006 LC-2007 LC-2008 LC-2009 LC-2010 LC-2011 LC-2012 LC-2013 LC-2014 LC-2015 LC-2016 LC-2017 LC-2018 LC-2019 LC-2020 LC-2021 LC-2022 LC-2023 LC-2024 LC-2025 LC-2026 LC-2027 LC-2028 LC-2029 LC-2030 LC-2031 LC-2032 LC-2033 LC-2034 LC-2036 LC-2037 LC-2038 LC-2039 LC-2040 LC-2041 LC-2042 LC-2043 LC-2044 LC-2045 LC-2046 LC-2047 LC-2048 LC-2049 LC-2050 LC-2051 LC-2052 LC-2053 LC-2054 LC-2064 LC-2065 LC-2066 LC-2067 LC-2068 LC-2069 LC-2070 LC-2071 LC-2072 LC-2073 LC-2074 LC-2075 LC-2076 LC-2077 LC-2078 LC-2079 LC-2080 LC-2081 LC-2082 LC-2083 LC-2084 LC-2085 LC-2089 LC-2090 LC-2091 LC-2097
Previous: LC-2023 Next: LC-2030
d) Informing the user that there are security implications in the way he chooses to access the server, and providing him with an alternative link to it risks causing the following reactions: i. WWW-beginners may simply not bother reading the advice and always take the default action, which according to the guidelines seems to correspond to taking the less safe, point-to-point HTTPS connection. ii. Somewhat WWW-knowledgeable users, aware of the existence of Trojan horses and phishing, may reel at the invitation to try alternative links. If they are curious and examine the URI of the current page, they may further suspect foul play, as the rewritten URI may not match the one they accessed originally. iii. Expert WWW-users will understand the implications of the proxy set-up, but may be wary at using its services for HTTPS links -- after all, what is the guarantee that the proxy will not misuse or unintentionally disclose private information in a point-to-point connection? And if there is a proxy acting as middle-man, what is the guarantee that the end-to-end HTTPS link is actually an end-to-end one and the proxy is not just performing some other tricky manipulations? Overall, fiddling with HTTPS connections risks reducing, rather than increasing, the willingness of end-users to access the mobile Web. A relevant point is that these end-users may actually assign the fault with the untrustworthy connections to the content or application provider, rather than to the operator of the proxy.