Secure Logins
I use Yahoo for a few of their services. As Aaron notes, Yahoo makes you log in excessively. This is a bit annoying, especially since each login usually requires multiple clicks for me - I always choose the secure option, because it submits the form over SSL, and this isn't the default. (If my wife has been using the computer, it usually also means that I have to log her out first, but that's another story.)
Recently, Yahoo removed the secure option:

If you read the fine print, however, you'll see "Submits over SSL." The problem is that Yahoo has focused too much on the technical issues and not enough on the social ones. The average user looks for the lock icon when entering sensitive data into a form. Although it's not required that the login form itself be sent over a secure connection, the average user doesn't know this.
If you view source (which is the only way to verify Yahoo's claim prior to submitting the form), you'll see that they're telling the truth:
<form method="post" action="https://login.yahoo.com/config/login?" ...>
Wouldn't it be nice if browsers could give us a visual indication that a form's action uses the https scheme? Imagine a cursor with a lock icon beside it:

Anyone want to write a Firefox plugin? :-)





31 Comments
1.
Nick said:
2.
Maarten Manders said:
3.
Harald Ponce de Leon said:
4.
S said:
5.
Ingmar said:
6.
Andrew Wooster said:
7.
Chris Padfield said:
8.
thomas said:
9.
timvw said:
10.
James Dykes said:
11.
Gabriel Ricard said:
12.
soenke said:
13.
S said:
14.
Mumbling Mutant said:
15.
Mike DeWolfe said:
16.
TopCat said:
17.
Chris Shiflett said:
18.
Tim Carey said:
19.
Hugo said:
20.
Chris Shiflett said:
21.
Hugo said:
22.
Chris Shiflett said:
23.
Brian said:
24.
BUses said:
25.
aRchitEKTurA said:
26.
Plasma said:
27.
RadioKat said:
28.
RadioKat said:
29.
księgowy said:
30.
John said:
31.
Andy James said: