CanSecWest, Vancouver. In 2000, I released the first public cryptographic man-in-the-middle exploits against HTTPS and SSH in my dsniff toolkit. This talk explored some of the human factors engineering issues involved, paying homage to Don Davis' concept of "compliance defects" as a security design issue.