On 21/05/10 05:36, Matt McCutchen wrote:
I'm not claiming that the user knows. I only said that if there is in
fact no impersonation, then the error is a false positive.
This seems a fine definition to me.
If the browser says "OMG - someone might be trying to MITM you", and
no-one is, that's a false positive.
If a browser says nothing when someone is MITMing you, that's a false
negative.
If a browser says nothing when nothing is wrong (the common case),
that's a correct negative.
If a browser says something when someone is MITMing you, that's a
correct positive.
Gerv
--
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto