How VeriSign Could Stop Drive-By Downloads
emcron writes "Ben Edelman has been doing great forensic work looking at spyware, adware, and malware. His latest piece, How VeriSign Could Stop Drive-By Downloads, turns the harsh light of public scrutiny on VeriSign's grubby practices in issuing digital certificates to vendors who try to install spyware by tricking users into clicking 'yes' with low-down dirty lying dialog boxes. Now, Ben wants VeriSign to clean up its act: it should refuse to issue certificates to companies that use obviously fake names (such as "CLICK YES TO CONTINUE") or that use those certificates to deceive consumers."
Perhaps, one day after Drive-By Downloads are stopped, a new era could emerge...
A time in which east-side nerds could live side by side with west-side nerds.
I have a dream...
Sigs are for the weak.
Do You Want To Trust The Certificate For Make Your Penis Smaller?
I DARE YOU TO CLICK YES
we were also considering
CLICK YES YOU MORON
OMG, WERE YOU SERIOUSLY GOING TO CLICK NO
and
THIS IS SO COOL, YOU GOTTA SEE WHAT HAPPENS WHEN YOU CLICK YES
is to design a mechanism for stabbing people in the face over the internet.
Wanna get rid of spyware, adware and malware?
CLICK YES TO CONTINUE
Reminds me of a comment on politics which also appeared on /. some time ago.
It was proposed to change one's name to None Of The Above and run for presidency.
Oh, and my personal favorite is when I see the option: "Always trust software content from Microsoft" Yeah sure, I could use a bridge!
Send whiskey and fresh horses!
From what I have seen, I believe that the employees at Verisign are "Clicking yes to continue" when approving certificate requests. Or someone mistakenly clicked the "Yes to All" button.
So if someone comes to their (physical) door and presents a laminated ID they pull down their trousers and bend over?
You haven't seen goatse yet have you?
1) the word "language" does not appear in the label,
2) or the header of the section it's in,
3) or the help that comes up with [?].
Not having a go at you there, by the way. Unless you're a usability specialist at MS.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
setting "sex bits" on IP packets to indicate sexual content.
Are those like the Evil Bits?
I saw the Sign, and it opened up my eyes
"CLICK HERE TO INSTALL" is not a legitimate name, not even a legitimate business name
Sir, I resent your libelous filth and my legal counsel will be conacting you shortly.
Aaron Firouz
CEO
CLICK HERE TO INSTALL, LLC.
Slashdot: News for nerds. Stuff tha-- MICRO$OFT IS THE DEVIL!!1
Asking Verisign to stop being unethical is like asking fresh manure to stop smelling.
Not that this is a shock, but checking that box never seems to work. I still to this day do not know whats up with that.
the problem is literacy and common sense, something that many people seem to lose the minute they touch a computer.
I think it is long before that point in time.
"Are those like the Evil Bits?"
No. You are getting this confused with your "Naughty Bits".