logoalt Hacker News

lxgryesterday at 5:07 PM1 replyview on HN

Users will unfortunately click on absolutely anything that a trusted (deservedly or otherwise) source tells them to, and you won’t be able to reliable convince them otherwise with UX alone. This includes all “developers only”, “click 5 times” etc. UX interventions.

You have to decide whether the feature warrants the remaining risk after all mitigations, or at least exceeds other, simpler attack vectors.

I think in this case it does, but it’s not an easy decision and I can understand most opposing positions as well.


Replies

skybrianyesterday at 6:01 PM

I suppose if it’s being actively exploited, the next step would be to make users wait a day, like the plan to change how Android side loading works.

show 1 reply