Poor Security Instructions in IE8
How can we use security awareness to train users to spot security threats? Having consistent instructions in our applications is one way for regular users to detect changes that may be malicious.
Therefore I was surprised to see this reality vs. instructions mis-match in Internet Explorer 8 when accessing the Microsoft Updates site:
The warning suggests you need to click on "Run Add-on", but the help information in the body of the page says to click on "Install ActiveX Control". And would I want to "Run Add-on on All Websites"? I'm not really sure. Does "run" mean "install" or does it suggest something less permanent?
I think we have a mixture of re-branding and Windows Vista syntax leakage, but it doesn't help end users—it just adds to security information noise. If Microsoft do it, phishers and malware writers can too.
We should do better than this in our own web applications.
Posted on: 22 May 2009 at 09:17 hrs

Comments are filtered automatically and should appear shortly after they been checked.