[sldev] Re: Patch to Address Debit Permission Spoofing

Argent Stonecutter secret.argent at gmail.com
Fri May 25 13:08:38 PDT 2007


> It also gives the permission a stigma, when it is commonly needed in
> everything that might ever need to give a refund!

While I am not too sure that debit permission SHOULDN'T have a stigma 
[1], I have to agree. that's why I think the appearance should be  
changed more radically. Make it (and any other dialog that can cost  
you money) look like a payment dialog, and you avoid it having a  
"stigma" and provide protection from the "click click click oops"  
problem.

[1] As defined, it's way too dangerous. I have only granted debit  
permission for two scripts. One I wrote (and knew exactly what it was  
capable of) and one I was testing for a friend and I examined the  
source before granting it.


More information about the SLDev mailing list