22 May 2009

Poor Security Instructions in IE8

How can we use security awareness to train users to spot security threats? Having consistent instructions in our applications is one way for regular users to detect changes that may be malicious.

Therefore I was surprised to see this reality vs. instructions mis-match in Internet Explorer 8 when accessing the Microsoft Updates site:

Partial screen capture showing Internet Explorer 8 web browser accessing the Microsoft Updates website shortly after its initial installation - the browser is warning about installing a component and asks us to click on 'Run Add-on' if we trust Microsoft, but the page instructions and illustration tell us to 'Install ActiveX Control'

The warning suggests you need to click on "Run Add-on", but the help information in the body of the page says to click on "Install ActiveX Control". And would I want to "Run Add-on on All Websites"? I'm not really sure. Does "run" mean "install" or does it suggest something less permanent?

I think we have a mixture of re-branding and Windows Vista syntax leakage, but it doesn't help end users—it just adds to security information noise. If Microsoft do it, phishers and malware writers can too.

We should do better than this in our own web applications.

Posted on: 22 May 2009 at 09:17 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Poor Security Instructions in IE8
http://www.clerkendweller.com/2009/5/22/Poor-Security-Instructions-in-IE8
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/5/22/Poor-Security-Instructions-in-IE8
Requested by 38.107.179.222 on Saturday, 4 February 2012 at 22:09 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2012 clerkendweller.com