One thing the internet asks us to do constantly is trust things we barely understand.
Trust this website.
Trust this download.
Trust this extension.
Trust this login page.
Trust this permission request.
Trust that this popup is legitimate.
Most of the time, users don’t really verify any of it.
They make a quick judgment and move on.
That’s not because people don’t care about security.
It’s because checking everything properly is unrealistic.
You can’t expect the average person to inspect permissions, certificates, domains, background activity, and download sources every time they use the internet.
That’s one of the reasons we’re building Avao.
The idea is to reduce the number of moments where the user has to rely on instinct alone.
Instead of asking someone to figure out whether something is safe, Avao should help surface the important context in real time.
Something simple like:
“This extension is asking for unusually broad access.”
“This login page doesn’t match what we’d expect.”
“This download source deserves a second look.”
The interesting product challenge is deciding how much information is enough.
Too little and you haven’t helped.
Too much and the user ignores it.
We’re trying to find that middle ground where security becomes useful context, not another layer of noise.
For anyone building products that help users make decisions:
How much explanation do you think people actually want before they act?