Live data from Hacker News

Chrome 69: “www.” subdomain missing from URL

bugs.chromium.org

171–180 of 919 posts

Re: Chrome 69: “www.” subdomain missing from URL

#171
post #47

Since everyone is wondering why, and since I happened to stumble across a reason during my time as a pentester, here you go: Spearphishing is still one of the most common ways of breaching a corporate network. If I target you, you will likely fall for one of my attempts. If you are a company rather than a person, my odds go way up, because I have N chances to trick someone rather than 1 (where N is roughly the number…

More targeted solutions:

Flag websites that look like phishing URLs - websites that contain domain names of popular websites in their subdomains or other parts of the URI. But initially, don't do anything. it could be harmless. AMP has domain names in the URI, right?

But, as soon as the user starts typing into a text-entry field (especially a password one), you bring a pop-up warning them that this might be a phishing site.

Re: Chrome 69: “www.” subdomain missing from URL

#172

I stumbled upon this bug too, and here's why this is not okay to me: For a couple of hours, I thought Citibank Singapore's website was down. If one tries accessing citibank.com.sg, there's no redirect to the www. subdomain. (That's still the case, if anyone wants to try.) If Chrome didn't hide the www., I would have been able to tell from Chrome's search/address bar that the various banking services that I've been ac…

It's not a shoddy implementation on Citibank's part. Google are just fucking the web over so we all have to fit their structure.

This is standard incumbent behaviour, they are drawing up the moat bridge, inch by inch.

Re: Chrome 69: “www.” subdomain missing from URL

#173

Considering a subdomain "trivial" is ridiculous... there's a difference between "www.example.com" and "example.com". Not only can they serve different sites, they can even have different DNS records! It seems that "m." is also considered a trivial subdomain. So when a user clicks a link to a "m.facebook.com" uri, they'll be confused why FB looks different when the browser reports it's on "facebook.com". I sincerely h…

>there's a difference between "www.example.com" and "example.com"

Can you link to a site where these two are different?

Re: Chrome 69: “www.” subdomain missing from URL

#174

Have any of you with corporate-type proxies been seeing authentication issues? Since moving to Chrome 69 a number of our users are reporting repeated proxy auth prompts when this should normally be handled transparently by Kerberos.

Yes, Chrome 69 has a bug with Kerberos: https://bugs.chromium.org/p/chromium/issues/detail?id=872665

Thank you very much. I'd been digging but hadn't found this yet.

Re: Chrome 69: “www.” subdomain missing from URL

#175
post #60

Earlier quoted context omitted.

99.9% of users have no idea what any of the words you just said mean. The change was made for them, not for you (the .1%)

Let's dumb down the internet even more because non technical users feel confused. Maybe we can actually remove the url field and just let the isp decide where they should go? They could offer a choice of 10 popular sites, like TV channels.. :)

Great idea! Hey, since these are non-technical users, why don't we just eliminate those pesky hard-to-use computers and just put the whole thing inside their TV? Y'know, kinda like 23 years ago... https://en.wikipedia.org/wiki/MSN_TV

Re: Chrome 69: “www.” subdomain missing from URL

#176

Earlier quoted context omitted.

99.9% of motor vehicle users have no use for airbags. We still keep them for the .1%.

This is a very bad analogy. Anyone in a car crash potentially benefits from airbags without knowing anything about them (or even if they exist at all). The 99.9% of people who don't even know the difference between www and non-www will never directly benefit from seeing www, ever.

> The 99.9% of people who don't even know the difference between www and non-www will never directly benefit from seeing www, ever.

You don't need to know the difference to be able to read the URL off, potentially to someone who does.

It's not impossible (though it's not a good idea) for “example.com” and “www.example.com” to both host web content, and whether or not they know or care about the meaning of the domain name, someone accessing one should be able to, in the event they have a problem, be able to read off which one they are accessing to the person trying to help them resolve the problem.

Re: Chrome 69: “www.” subdomain missing from URL

#177

Earlier quoted context omitted.

Is this specific to a version of Firefox, or an extension? I'm using Firefox 62.0, and I do not see a difference in color between the domain and the rest of the URL. (Windows 10, 1080p screen.) ETA: Holy crap, if I zoom into a screenshot, I can see the difference. My eyes cannot benefit from this feature under normal circumstances, though. Looks like black (#000000) and gray (#807D7D).

I get #9D9D9D on Firefox 61 on Ubuntu (1080p). It is perfectly clear to me. If you have trouble distinguishing between the grey and black, perhaps file a bug report requesting to slightly lower the saturation of the grey? Or perhaps your browser's theme is using that darker grey?

the parent might actually need an eyetest...

Re: Chrome 69: “www.” subdomain missing from URL

#179

Earlier quoted context omitted.

Thanks! This worked great for me and it brought back the https:// part as well.

Until a few releases down the line and it is decided for you that the flag should be removed.

This is the problem. Better to just switch to Firefox now and be done with it. Hopefully it'll send a message.

Re: Chrome 69: “www.” subdomain missing from URL

#180
post #130

Earlier quoted context omitted.

The padlock was already meaningless.

It started being meaningless thanks to Let's Encrypt. Before it meant you had to show your ID and banking info to a "reputable" corporation for them to make a cert for you. Yes I know I know, not always the case, but... LE means that the mantra "if it's https then it's a secure and reputable website" is now outdated.

> Before it meant you had to show your ID and banking info to a "reputable" corporation for them to make a cert for you.

No, it didn't. DV certs never meant that (EV certs did and still do, but LE doesn't offer EV and EV isn't and never was necessary for the padlock.)

Post reply on HN