Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Have you looked at what the UX is for invalid certificates in 2022? It's not like ten years ago where you just click enough times and "visit anyway".

Here, try this link in Chrome: https://untrusted-root.badssl.com/. When you click Advanced, it tells you "the website sent scrambled credentials that Chrome cannot process". And beyond that there's just no button to bypass it. You can't visit the site. (Sure, there's probably a chrome://flags or --disable-web-security way to bypass this, but that's well beyond the average user's comfort zone, as well it should be.)



Uh I just have to click "advanced" and then "proceed anyway".

I tried on a blank profile to make sure there were no strange settings.


I clicked that link - in Chrome on Android all I had to do was click "advanced" then "proceed anyway". I have never changed any flags or default settings in this browser.


I just tried to open the site in Safari, and there's no "Continue anyway" button, only "Go Back". I did not change any default settings, because I use Firefox as my daily driver ( and Firefox does have "Accept risk and continue" button, but I think the word "risk" on it is scary enough for many people to not click it).

EDIT: It turns out there is a "visit this website anyway" option in Safari, but it is not a button, it's a link which you only notice when you click "Show details" button and read the warning.


A slight digression, but I read[1] recently that typing “thisisunsafe” while the tab has focus is sufficient for bypassing the warning.

[1]: https://twitter.com/cyb3rops/status/1561995926666985472?s=20...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: