What's needed right away is a "badge of security approval" from an independent third party, which verifies not just the technological side, but the customer-service side too.
That sounds so good and the appeal of this kind of problematic scheme is what makes security such a hard, one that we likely won't see easily solved.
Aside from the usefulness or not of the stuff on your checklist, any "badge of security approval" is basically outsourced security. And that won't work because any wholesale security provider must provide one-size-fits-all security and one-size-fits-all fails because it must either so secure no one could break and so be far too unwieldy for most uses or it must be fairly flimsy and so fail exactly when the use case becomes critical (and of course trusting any third party expands your perimeter of trust in a fashion that you might not aware of).
The physical locks and strong boxes we have are scaled according to what we're facing and still real human beings to keep an idea of whether they are really secure. I live in a good neighborhood. I've lived in bad neighborhoods. It's part of becoming an adult. The lock on my gate is flimsy but it's enough. But I watch to see if the neighborhood is going down hill, if there's some factor which would make me a target. It's a paltry measure but it actually has pretty well. My security level can't be carte blanch guaranteed by anyone. Even if I hire security service, I'm not ultimately leaving everything to them.
Outsourced security won't work in the sense of entirely outsourced security*. The information age can't really get away from the "rings of trust" situation where the most highly entities can not really, should not be trusted to give away their trustedness on a wholesale basis. Some people can and should rely on outsourced security but the biggest targets should not and cannot.
And it is all a matter of levels. Average consumers can trust the browser bar (more than a lot of things) because they aren't special targets. That's OK.
That sounds so good and the appeal of this kind of problematic scheme is what makes security such a hard, one that we likely won't see easily solved.
Aside from the usefulness or not of the stuff on your checklist, any "badge of security approval" is basically outsourced security. And that won't work because any wholesale security provider must provide one-size-fits-all security and one-size-fits-all fails because it must either so secure no one could break and so be far too unwieldy for most uses or it must be fairly flimsy and so fail exactly when the use case becomes critical (and of course trusting any third party expands your perimeter of trust in a fashion that you might not aware of).
The physical locks and strong boxes we have are scaled according to what we're facing and still real human beings to keep an idea of whether they are really secure. I live in a good neighborhood. I've lived in bad neighborhoods. It's part of becoming an adult. The lock on my gate is flimsy but it's enough. But I watch to see if the neighborhood is going down hill, if there's some factor which would make me a target. It's a paltry measure but it actually has pretty well. My security level can't be carte blanch guaranteed by anyone. Even if I hire security service, I'm not ultimately leaving everything to them.
Outsourced security won't work in the sense of entirely outsourced security*. The information age can't really get away from the "rings of trust" situation where the most highly entities can not really, should not be trusted to give away their trustedness on a wholesale basis. Some people can and should rely on outsourced security but the biggest targets should not and cannot.
And it is all a matter of levels. Average consumers can trust the browser bar (more than a lot of things) because they aren't special targets. That's OK.