Re: What will incentivize deployment of explicit proxies?

On 3/12/13 11:53 AM, Nicolas Mailhot wrote:
>
> If browser people do their part and implement the (admittedly non-trivial)
> UI to manage that, there will be a strong incentive to deploy because you
> can't imagine how sick operators are of all the ways browsers screw up
> http/1 by refusing to admit intermediaries exist.
The UI is extremely important here. If we create this protocol that 
allows both client and server to be aware of the proxy, and allows them 
to authenticate the proxy, a good UI (and I don't claim to know how this 
can be done) will let the user know that (a) her traffic is being 
decrypted on the way, and (b) by whom. If we can get to the position 
that she would accept this at her workplace, but would not accept this 
at, say, a coffee shop or airport, this will influence the decision made 
by websites a lot.

If customers can be trusted to not allow decrypting proxies everywhere, 
then banks will not prohibit online banking with proxies present. If the 
UI looks like this, they might:

  +-----------------------------------------------------------------------+
  | A decrypting proxy called 'sslproxy.localhost' was detected.          |
  | |
  |  +----+ +---------------------------------------------------------+  |
  |  | OK |  | Nah, I'm so over this whole browsing the Internet thing |  |
  |  +----+ +---------------------------------------------------------+  |
  +-----------------------------------------------------------------------+

Yoav

Received on Tuesday, 3 December 2013 11:15:25 UTC