Live data from Hacker News

Chrome 69: “www.” subdomain missing from URL

bugs.chromium.org

671–680 of 919 posts

Re: Chrome 69: “www.” subdomain missing from URL

#671

Earlier quoted context omitted.

A proposal for better security with domain names: The domain name system has been around for decades and it's a clever and proven system. It can – and should be – taught in school and, arguably, knowledge of it is, while not difficult to obtain, essential in our times. Additional ambiguity in this is probably not what we want. Arguably, the most sincere problems arise from mixed alphabets with Unicode domains and loo…

> Arguably, the most sincere problems arise from mixed alphabets with Unicode domains and look-alike characters/glyphs. No way. The most sincere problem is that hostnames do not enforce any binding to a real world identity that users can understand (nobody inspects certs) and that the most trustworthy component of a hostname is the second to the last section (right before ".com"). Humans tend to look at the front of…

I don't see how you could enforce a hostname binding to some real world identity. Hostnames really need to have a non-ambiguous mapping from a name to a computer (more or less), but real world entities don't have that, without using really cumbersome indentifiers. Many natural persons share a name, so how do we decide who gets a hostname based on that; the same is true of corporate persons -- there are many that share names. Even if there was a way to disambiguate these things, it seems unlikely that the entity in charge of this would also want to rub a public registry -- so how do you make that work.

Re: Chrome 69: “www.” subdomain missing from URL

#672
Those who are saying this change is to make things "easier" for certain non-literate users may be correct, but they should consider whether such a justification is desirable at all from a moral perspective.

No doubt all of us have at some point been forced to learn things that we did not find particularly useful or pleasant to learn at the time, but then later experienced a great "satisfaction of knowledge" when faced with a situation in which that knowledge became advantageous or even essential, and then proceeded to use it to better ourselves.

Imagine a world in which none of that learning took place; one in which you never have to think, everything you see and do automatically satisifies you and keeps you in a blissful state of ignorance. Who makes the decisions in that world; or rather, who can make those decisions? Who is in charge of your life? Not you.

Gradually reducing the motivation to learn, by making things "easy" and hiding/obfuscating anything that could be used as a starting point for more learning, makes for a population that won't think, won't learn, won't question or rebel. It makes them docile and easy to control.

Making statements like "ordinary users will never learn" is one thing, but explicitly making decisions to ensure that status quo is a horrible trend. It's quite a genius plan, and certainly used by organisations other than Google, but thoroughly disturbing.

I've said a few times before in the past: "knowledge is power --- they don't want you to have too much."

Re: Chrome 69: “www.” subdomain missing from URL

#673

Earlier quoted context omitted.

Have "most users" been measured? Perhaps they should be taught. Otherwise let's move on to making nuclear reactors less confusing.

My admittedly anecdotal evidence suggest that they do not. From my other comment: I worked as tech support for a large org (300+ users) most of my career and have dealt with most types of users. I've only seen them interact with the address bar in one of two ways: explorer shortcuts on the desktop/browser bookmarks (few) or stick-it notes on the monitor or keyboard (many).

If you count only the people who require tech support then of course you're only going to see the people who require tech support. But they're not the only users.

Developers and techies are users too and they're much less likely to call tech support in general.

This harms them far more than it helps the people who need help.

Re: Chrome 69: “www.” subdomain missing from URL

#674

Those who are saying this change is to make things "easier" for certain non-literate users may be correct, but they should consider whether such a justification is desirable at all from a moral perspective. No doubt all of us have at some point been forced to learn things that we did not find particularly useful or pleasant to learn at the time, but then later experienced a great "satisfaction of knowledge" when face…

Onward to Idiocracy we go!

/s

Re: Chrome 69: “www.” subdomain missing from URL

#675

Lots of people saying this is for the benefit of non-technical users. For me, this is a minor inconvenience, precisely because I'm technically capable/interested enough to handle the inconsistency. But this kind of stuff (and I am speaking somewhat generally here) tends to frustrate me, precisely when I'm trying to educate or deal with a non-technical user in some capacity where it happens to matter. I can't just tel…

This! Consistency.

Browser start screens with a large search box in the center haven't helped either. Some users do see no difference between the location-field and this search box. Some have even unlearned this. Arguably, it facilitates ignorance of the location, the significance of URLs and how they work. Reading a URL isn't witchcraft, it's just about three simple things. But dumbing things down towards convenience at the expense of consistency will not empower users.

(Surprisingly, ordinary people have been able to manually dial a phone or to parse a street address without the help of a map service in the past. It can't be that bad.)

Re: Chrome 69: “www.” subdomain missing from URL

#676

Earlier quoted context omitted.

Isn't this a security risk? What if someone malicious takes control of the www.com domain?

The www.com might not be easy to get, but there is probably a www name at another important TLD that can be purchased. And if you own that domain you can easily get SSL certificates too. Sounds like Chrome could now be a phisher's best friend…

It appears that it only does it for anything subdomainish -- that is, not the first part after the TLD. I tested it against .nz which has a silly mix of .{co,govt,school}.nz second-level domains and directly registered example.nz domains and it always displays at least one "registered" bit.

Which is almost worse because it seems like people have put thought into this.

Re: Chrome 69: “www.” subdomain missing from URL

#677
post #563

Earlier quoted context omitted.

You seem shocked at this with word usage like "actual users", "real url's" and "actually no idea" But how are we to expect users to know any better until general technology literacy improves? Many people can't tell you the difference between a modem, router, OS, browser, or website. I remember years ago sitting down with my elderly grandmother trying to show her how to use a desktop... We are too close to our work so…

> "Many people can't tell you the difference between a modem, router, OS, browser, or website." They don't care, nor should they. How many people know how many spark plugs are in their car? You're correct. We, the more tech-literate, take too much for granted; and most experiences and learning curves are too far over the head of the "average" user. It's not them. It's us.

Do you seriously not know how many spark plugs are in your car? It's the same as the number of cylinders. How could you not know that?

They absolutely should care. They should be aware that when they store things in "the cloud" they are not stored on their device and are visible to third parties. They should understand what encryption is and how to use it. "I don't know what I'm doing, and I didn't get the result I wanted, but it's not my fault it's the machine" is not an acceptable statement, whether we're talking about cars or computers.

Re: Chrome 69: “www.” subdomain missing from URL

#679
post #611

Earlier quoted context omitted.

> "Many people can't tell you the difference between a modem, router, OS, browser, or website." They don't care, nor should they. How many people know how many spark plugs are in their car? You're correct. We, the more tech-literate, take too much for granted; and most experiences and learning curves are too far over the head of the "average" user. It's not them. It's us.

I think the comparison to spark plugs is misleading when we talk about URLs and security. It's more like looking in the mirror before changing lanes. It's something you need to check in order to stay safe. Mirrors, like URLs, are just an implementation detail. But since currently driving works with mirrors, you have to learn how to use them.

The benefit is obvious in that instance. There is a very direct connection between checking your mirrors and not hitting a car as you merge or similar.

Where is the cause and effect for a URL or SSL cert? There is no learning experience.

Furthermore as some have claimed, and I've personally witnessed, for some URLS's literally dont exist. Just type whatever site you want into the google box and hope you get lucky.

Post reply on HN