Live data from Hacker News

An Update on the Lock Icon

blog.chromium.org

61–70 of 169 posts

Re: An Update on the Lock Icon

#61
post #56

I wonder how many ordinary users have any notion of what the “tune” icon [0] is supposed to indicate. [0] https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg...

This settings/configure/adjust icon seems to be in the middle of a transition between abstract and universal. Something like a magnifying glass didn't need any transition period because humans already associate it with "searching" from fiction. Other icons required reinforcement to learn (e.g. the share icon - or, even more well learned, the pause icon). One of the downsides of the modern hyper-focus on metrics in UI is that it dictates that iconography already be intuitive. Sometimes we need to ignore this rule in order to teach users a new icon, which then helps us improve interfaces by communicating more without words.

Re: An Update on the Lock Icon

#62
post #16

If you're using Chrome, right-click the URL bar and check "Always show full URLs", so you can see the https:// prefix like it's 1999. This also fixes a variety of UX problems with editing URLs. By the way, does anyone know of a good alternative to http://neverssl.com ? I had been using this for years, but now it supports SSL for some unfathomable reason.

> By the way, does anyone know of a good alternative to http://neverssl.com ?

http://http.rip/

Re: An Update on the Lock Icon

#63

I approve of getting rid of the lock icon, showing only a broken lock for HTTP and no lock for HTTPS. It's always been weird to have site permissions settings revealed by clicking that lock. But the replacement icon looks really strange to me. They're calling it a "tune icon," but I've never seen a tune icon like this, with just two circles and two lines. Looks weird. I'm surprised that it fared well in the experimen…

This icon is gaining traction fast. I've seen it a lot over the past few years. "Tuning" and "adjusting" is a slightly more specific concept than "settings". I think users associate the "settings" gear with whole-app settings, or "technical"/"system" settings, and it might be something they're loathe to click on because that's typically a large forest of things they don't care about or understand.

Also, I think using not-well-known icons is actually underrated (see my comment here: https://news.ycombinator.com/item?id=35793362)

Re: An Update on the Lock Icon

#64
post #50

It’s a continuation of the trend that led to them removing Extended Validation indicators: https://duo.com/decipher/chrome-and-firefox-removing-ev-cert... Here’s how they used to appear: https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easie…

A better approach would probably be to wildcard ban domains with your company name on the dns server (except for the real one).

Re: An Update on the Lock Icon

#65
post #50

It’s a continuation of the trend that led to them removing Extended Validation indicators: https://duo.com/decipher/chrome-and-firefox-removing-ev-cert... Here’s how they used to appear: https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easie…

> EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. Our company puts a big red banner on the top of all emails that come from an external source or don't have DMARC/SPF/DKIM/other security protections. Literally nobody ever checks the banner. It has no effect on phishing click rates. People do not read, or think. They just look for wherever it is expected for…

At my doorslam job, they hired a Director of Engineering Architecture or whatever title. He had a strong background in security, they said. Yeah well turns out his background was he led the offshore team that built an anti-virus company's .mobi website for 9 years. 1st hour of 1st day, he clicked the anti-phishing test "Click here to update your drivers" phishing email.

Re: An Update on the Lock Icon

#66
post #50

It’s a continuation of the trend that led to them removing Extended Validation indicators: https://duo.com/decipher/chrome-and-firefox-removing-ev-cert... Here’s how they used to appear: https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easie…

A better approach would probably be to wildcard ban domains with your company name on the dns server (except for the real one).

Good idea, that sounds very viable. Thank you!

Re: An Update on the Lock Icon

#67
post #60

Earlier quoted context omitted.

> EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. Our company puts a big red banner on the top of all emails that come from an external source or don't have DMARC/SPF/DKIM/other security protections. Literally nobody ever checks the banner. It has no effect on phishing click rates. People do not read, or think. They just look for wherever it is expected for…

If you had a tornado siren go off every 20 minutes every single day of the year, how long before you stopped ignoring the siren? How surprised would you be when a tornado hit 2 year later? "This product causes cancer" is ineffective when the warning is plastered on everything. Same goes for warning in computer systems.

San Francisco had a tsunami warning siren that was sound tested every Tuesday at 12pm for 30 seconds. It was fun!

It needed repairs so they dumped it. Few weeks later there was the 1st tsunami warning in ages but it went thru telephone since they dismantled their warning siren.

Re: An Update on the Lock Icon

#68
I'm glad they continued the "An Update on X" = "X is getting axed" tradition at google. It's one of the few constants. Maybe they even have a UX guideline about it by now :D

PS: I'm not writing this out of spite, btw. It just came to my mind when I saw the title and I was surprised I was right

Re: An Update on the Lock Icon

#69

Such a cryptic lock is even more confusing. I propose a very simple, easy to understand solution: http should simply be RED https should not be indicated at all A curated list, preferably by the gov. should indicate which SSL certificates are allowed to be green.

So as long as you're not color blind or vision impaired or from a country where red doesn't mean danger, sounds fine Government oversight of TLS certs? No way this could possibly go wrong

Traffic lights.

Everyone everywhere knows red, yellow, and green now, and how to navigate around colorblindness (both red and green lights are tinted to be distinguishable).

Re: An Update on the Lock Icon

#70
post #18
post #16

If you're using Chrome, right-click the URL bar and check "Always show full URLs", so you can see the https:// prefix like it's 1999. This also fixes a variety of UX problems with editing URLs. By the way, does anyone know of a good alternative to http://neverssl.com ? I had been using this for years, but now it supports SSL for some unfathomable reason.

> it supports SSL for some unfathomable reason. "neverssl.com now supports ssl, as some browsers and sites automatically use https even when you don't type that in. You get a browser-cacheable page that still helps you get online by forcing a request that ... never uses ssl." -- https://twitter.com/NeverSSL/status/1456310362551164928 They're trying to solve the "how do log into this captive portal" problem, and they…

Wow. Unfathomable indeed; that action and that explanation make no sense to me, and they haven’t even updated the HTML served—it still makes the claim of “never SSL” they’ve reneged on.
Post reply on HN