Sunday, October 30, 2011

The Priority of Constituencies

Lawrence Lessig wrote in Code is Law that the choices we make in writing code embody our values.  This observation is especially true when building a browser because the browser mediates interactions between many distinct entities.  Because the browser's security policy is at the heart of mediating those interactions, we should ask ourselves what values the browser's security policy embodies.

One key value is the priority of constituencies, which is enshrined in the HTML Design Principles:
In case of conflict, consider users over authors over implementors over specifiers over theoretical purity.
To better understand this principle, let's consider a specific example: whether the browser's password manager should be enabled for a given web site.

The password manager is a source of conflict for these competing interests.  Implementors (myself included) believe that password managers improve security by reducing the costs of using a large number of more complex passwords.  Many banks, however, disagree.  They believe that password managers reduce security because passwords stored in password managers can be stolen by miscreants.

How do browser vendors resolve this conflict?  By default, we enable the password manager.  Because users have a higher priority than implementors (i.e., browser vendors), browsers let users turn the password manager off.  Because authors (i.e., site operators) also have a higher priority than browser vendors, browsers let authors disable the password manager on their own web sites by setting autocomplete=off.

The careful reader will have noticed that the scheme above violates the priority of constituencies in one case.  What if the user wants to use the password manager on a web site sets autocomplete=off?  Because users have a higher priority than authors, the browser should resolve this conflict in favor of the user.  Typically, browsers handle this case via their extension system.  For example, the autocomplete=on extension lets users override authors who want to disable the password manager.

How, then, should we respond to web site operators who wish to block or override these sorts of extensions?  As long as we believe that these extensions faithfully enact the user's will, we're hard-pressed to let authors block these extensions because that would violate the priority of constituencies.  Instead, we ask authors to be humble and accept the user as sovereign.

84 comments:

  1. As the author of that extension, let me also note that for a long time I've wanted to change Chrome so that its built-in UI lets users override site authors here.

    There is a difficulty, though, in that "autocomplete=off" is used in many types of data fields -- passwords, credit card numbers, and "fields it wouldn't be very useful for the browser to provide completions for later" are three distinct cases -- and while the right behavior may differ from case to case it's often hard for the browser to know which case a particular field represents.

    ReplyDelete
  2. Some users belong to an organization, which may have its own policies. Where do they fit in?

    ReplyDelete
  3. And today is your day, Peter.
    "As we’ve previously discussed, Chrome will now offer to remember and fill password fields in the presence of autocomplete=off. This gives more power to users in spirit of the priority of constituencies, and it encourages the use of the Chrome password manager so users can have more complex passwords. This change does not affect non-password fields." -Daniel Xie, Google Chrome, Chrome release blog

    ReplyDelete
  4. To see latest Tamil movie updates and reviews visit
    Latest Tamil Movie Reviews

    ReplyDelete
  5. This is a great post ! it was very informative. I look forward in reading more of your work. Also, I made sure to bookmark your website so I can come back later. I enjoyed every moment of reading it.
    baju batik modern baju batik baju batik wanita batik pekalongan batik couple batik online batik modern gamis batik

    ReplyDelete
  6. Thanks for Nice and Informative Post. This article is really contains lot more information about This Topic.
    world famous astrologer

    ReplyDelete
  7. Thanks for providing such a great info, you can see Easter Greetings Sayings plz like and share this post. Thanks Regards

    ReplyDelete
  8. I hope KKR will win this year because the team have ability to beat all the teams playing in IPL 2016

    ReplyDelete
  9. Nice to be visiting your blog again, it has been months for me. Well this article that i've been waited for so long. I need this article to complete my assignment in the college, and it has same topic with your article. Thanks, great share.
    five nights at freddy's 3 five nights at freddy's 4 five nights at freddy's 2 five nights at freddy's

    ReplyDelete
  10. Indian Premiere League (IPL)Starting from April 9 to 29 May 2016.Check out latest IPL 2016 Schedule

    ReplyDelete
  11. This is a really super post. Must admit that you are amid the best writer I have read. I appreciate your making the effort to discuss this class of article.

    - usps tracking
    - iphone 7 release date
    - Netflix

    ReplyDelete
  12. It is the best time to make plans for the future and it's time to be happy. I have read this post and if I could I wish to suggest you few interesting things or advice.
    Maybe you could write next articles referring to this article. I want to read even more things about it. Great blog. Thanks!
    http://www.juegosfrivol.com/
    http://www.juegoskizi20.com/
    http://www.frivallgames.com/

    ReplyDelete
  13. Hi Admin,

    Great post indeed!
    ACtually I visit your blog first time through someone blog. So I bookmakred this page for further usage.
    Thanks for sharing such great content with us.

    Happy Mothers Day 2016 | Happy Mothers Day Wishes | Happy Mothers Day Messages | Happy Mothers Day Quotes | Happy Mothers Day Sms | Happy Mothers Day Images


    Regards:
    Hafiz Junaid

    ReplyDelete
  14. Thanks for the great post. Pretty good post. I just stumbled upon your blog and wanted to say that I have really enjoyed reading your blog posts.
    impossible quiz
    learn to fly
    minecraft unblocked
    plazma burst 2
    qwop
    superfighters
    raze

    ReplyDelete
  15. Good blog post. I want to thank you for interesting and helpful information and I like your point of view. Thank you!
    - Mortal Kombat XL
    - Atari Breakout
    - Dragon Ball Z Games

    ReplyDelete
  16. Thanks for the best blog.it was very useful for me.keep sharing such ideas in the future as well.this was actually what i was looking for,and i am glad to came here!
    earn to die
    Hi! I’ve been reading your blog for a while now and finally got the courage to go ahead and give youu a shout out from Austin Texas! Just wanted to tell you keep up the fantastic work!my weblog:
    tank trouble
    tank trouble

    earn to die 1

    earn to die 2

    earn to die 3

    tank trouble 4
    tank trouble 3
    tank trouble 2

    ReplyDelete
  17. Thanks for the best blog.it was very useful for me.keep sharing such ideas in the future as well.this was actually what i was looking for,and i am glad to came here!

    hotmail sign in Hotmail is an email account of Microsoft Corporation. Like Google’s Gmail, it is full of the features of a regular email.

    hotmail login Hotmail was previously a quite popular email service. It has the features and utilities similar to other email services, but users encountered many annoying issues, and even lost fees they had paid for this service.


    recover hotmail password Therefore, there are many users who have a registered Hotmail account but no longer wish to use it as they are unhappy with the service.

    sign in to Hotmail  At this time, some users sought to remove their Hotmail account, but has some difficulties as it is a complicated process.

    ReplyDelete
  18. Thanks for the best blog.it was very useful for me.keep sharing such idea
    s in the future as well.this was actually what i was looking for,and i
    am glad to came here
    you keep up the fantastic work!my weblog
    age of war
    Hi! I’ve been reading your blog for a while now and finally got the
    happy wheels

    tank trouble 3

    ReplyDelete
  19. This content is written very well. Your use of formatting when making your points makes your observations very clear and easy to understand. Thank you.
    - usps tracking
    - iphone 7 release date
    - netflix

    ReplyDelete