Earlier quoted context omitted.
Did not try it, but apparently if you click on the domain label, it provides a standard url field so you can copy / modify the url.
In this case I'd be more open to the idea, although having some advanced preference to disable it if needed would be helpful, should it become the default.
Chrome's experiment of hiding the URL is great for security
31–40 of 211 posts
Re: Chrome's experiment of hiding the URL is great for security
#32Re: Chrome's experiment of hiding the URL is great for security
#33Earlier quoted context omitted.
Did you even read the article, where that comparison is made explicit?
Not only is it explicitly stated, but it's done so in the very first sentence.
Re: Chrome's experiment of hiding the URL is great for security
#34As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
chrome is already breaking half of the copy/pastes i do because it's from my history and not a page that's already loaded.
do you have any idea how many people actually use copy/paste? i would venture that ctrl-c/ctrl-v is probably the only key binding that the majority of computer users of all walks of life use.
half of the places i seem to be pasting links into don't pick up the links without the http. Including things like markdown in github issues, many chat systems.
Messing with the url bar when you did it last time has been a constant daily sense of irritation to me. So no. I don't want you to mess with it any further.
just please stop.
Re: Chrome's experiment of hiding the URL is great for security
#35As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
Re: Chrome's experiment of hiding the URL is great for security
#36As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
As a developer, if this is going to hide any useful information on first glance I am not sure how I feel about that. I already feel like Chrome has started shunning developers with that over the top annoying pop-up any time I open a new window (Ctrl+N, type, stop typing because I have to move my mouse to close the popup), and moving towards forcing developers to distribute their extensions through the play store (whi…
Firefox and IE have started copying Chrome in appearance and philosophy. Opera is now based on the same code. Safari is based on similar code, and is unusable by anyone not using a Mac of some sort.
Firefox is perhaps the most viable alternative to Chrome for web developers or advanced users. But due to that lack of competition or original thought, it really isn't much different from Chrome at all. This has become very apparent with the release of Firefox 29, where they both now look nearly identical, and both suffer from the same dumbing-down that has harmed the experience for more advanced web users.
Re: Chrome's experiment of hiding the URL is great for security
#37Re: Chrome's experiment of hiding the URL is great for security
#38Re: Chrome's experiment of hiding the URL is great for security
#39As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
> phishing is a very big problem Is it? What are the numbers? So many annoying things are done in the name of "security" without much justification (both online and in real life); Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help folks who can't be bothered to read it? Another comment suggests "source code highlighting" for the url, wh…
Providing more detailed background and better numbers on phishing sounds like a good idea. However, this is an experiment that is not on track to ship in any version of Chrome, so I wouldn't consider it a gating criteria for continuing to experiment.
> Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help folks who can't be bothered to read it?
The decision to not display the HTTP scheme was not related to security (and it wasn't to my personal liking). However, it was done in such a way that it was effectively security neutral.
> Another comment suggests "source code highlighting" for the url, where the actual domain would be emphasized while still showing the whole url: what are your thoughts on this?
As I commented elsewhere, Chrome has been highlighting the origin since its inception. However, phishing is still a serious problem, so the team that's working on this is investigating clearer indicators like the ones in this experiment.
Re: Chrome's experiment of hiding the URL is great for security
#40Earlier quoted context omitted.
Did you even read the article, where that comparison is made explicit?
No, I didn't read the article, nor did I claim or indicate that I did in any way. Yet here is yet another front pager about Chrome experimenting with something that Safari on iOS has done for some time, as if people just discovered fire.