[packagekit] This dialog sucks

Duncan Mac-Vicar Prett dmacvicar at suse.de
Thu Apr 23 06:04:21 PDT 2009


Richard Hughes wrote:
> On Wed, 2009-04-22 at 10:16 -0400, Matthias Clasen wrote:
>> Thanks, some things are clearly improved in this mockup. 
>> But some problems remain:
> 
> What about the attached?
> 
> Richard.

What happens if anyone fakes the key and names it RPM Fusion? That
dialog is tempting the user to click continue if the gpg key description
matches, which makes the situation worse (half of the social engineering
work to click on a faked key is done by the dialog).


-- 
Duncan Mac-Vicar P. - Engineering Manager, YaST
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)




More information about the PackageKit mailing list