Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

41–50 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#41

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

[deleted]

Re: Chrome's experiment of hiding the URL is great for security

#42

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Well, if www and .com become meaningless then advertisers will use "type xxx yyy into you bar" instead (which goes to the search engine) or hash tags (already doing this). Then Google could come up with "associate permanent keywords with your URL" (for a small fee of course) to guarantee that those keywords won't shift under you when your Google ranking changes.

Re: Chrome's experiment of hiding the URL is great for security

#43

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

Firefox solves this rather elegantly by making the subdomain and the part after the domain light grey, with the actual root domain in black.

The URL is intact, and the root domain stands out clearly.

Re: Chrome's experiment of hiding the URL is great for security

#44

I think we are confusing the fact that phishing takes place with the purpose of the web. Even if 80% of the time I was trying to be phished, I'd still want the URL. Why? Because the URL is my ownership of the web. It's my address book. It's what domain owners pay to have. It's the roads that connect one spot to another. So sure, phishing is a problem. Figure out some way around it that doesn't involve Google locking…

Many people in this thread will confuse a clean interface with convenience and sloppy conclusions for protection.

Agreed.

Sorry for the cranky post today, but this purposefully (in my mind) obfuscates the issue. Clean UIs are awesome. Taking away the friction between my wanting to go somewhere on the net and getting there? Also awesome. Effectively killing the idea of the URL and giving yet more control to Google for my movement around the web? A disaster.

Re: Chrome's experiment of hiding the URL is great for security

#45
post #21

Earlier quoted context omitted.

> phishing is a very big problem Is it? What are the numbers? So many annoying things are done in the name of "security" without much justification (both online and in real life); Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help folks who can't be bothered to read it? Another comment suggests "source code highlighting" for the url, wh…

> Is it? What are the numbers? Providing more detailed background and better numbers on phishing sounds like a good idea. However, this is an experiment that is not on track to ship in any version of Chrome, so I wouldn't consider it a gating criteria for continuing to experiment. > Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help fol…

So you think crackers(>hackers) and people with bad intention will be unable to see the URLs and won't be able to do phishing easily.

So, through obscurity you will achieve security.

Edit: or you expect users to notice phishing attempts more clearly by only displaying the domain name?

Re: Chrome's experiment of hiding the URL is great for security

#46
post #21

Earlier quoted context omitted.

> phishing is a very big problem Is it? What are the numbers? So many annoying things are done in the name of "security" without much justification (both online and in real life); Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help folks who can't be bothered to read it? Another comment suggests "source code highlighting" for the url, wh…

> Is it? What are the numbers? Providing more detailed background and better numbers on phishing sounds like a good idea. However, this is an experiment that is not on track to ship in any version of Chrome, so I wouldn't consider it a gating criteria for continuing to experiment. > Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help fol…

If black vs. light grey is your concept of "highlighting" then I have to tell that I didn't even notice the behavior until today. Maybe you should try actual color before removing functionally?

Re: Chrome's experiment of hiding the URL is great for security

#47

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

You want to help people feel more secure? How about you downgrade every https website to Yellow color, unless it uses PFS (only with a few good cipher-suits) and the latest version of TLS. Requiring HSTS would probably be good, too. They should also be required to have 100 percent of the site under https, before getting the Green color. No mixed content.

Right now you (and other browsers, too) give the "safe" color Green to to the bare minimum of https security, even if it uses TLS 0.9.8 and RSA 1024-bit. Sites are not going to upgrade their security policies as long as you, the browser vendors, keep showing them to the users as "perfectly safe". There's no incentive in it. I think it's on browser vendors to push some of the incentives.

Re: Chrome's experiment of hiding the URL is great for security

#48
post #42

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Well, if www and .com become meaningless then advertisers will use "type xxx yyy into you bar" instead (which goes to the search engine) or hash tags (already doing this). Then Google could come up with "associate permanent keywords with your URL" (for a small fee of course) to guarantee that those keywords won't shift under you when your Google ranking changes.

I already see this happening in Japan. Rarely do I see ads include URLs, they have a search term.

Re: Chrome's experiment of hiding the URL is great for security

#49
post #42

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Well, if www and .com become meaningless then advertisers will use "type xxx yyy into you bar" instead (which goes to the search engine) or hash tags (already doing this). Then Google could come up with "associate permanent keywords with your URL" (for a small fee of course) to guarantee that those keywords won't shift under you when your Google ranking changes.

I already see this happening in Japan. Rarely do I see ads include URLs, they have a search term.

Re: Chrome's experiment of hiding the URL is great for security

#50

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

I agree that this experiment isn't demonstrating a perfect mitigation, but it's important to appreciate that it's currently vastly easier for a phisher to permute paths and subdomain components than it is to create a convincing ETLD+1. There are various reasons for this, including less text for a phisher to work with and registration requirements for ETLD+1 domains (which means they can't be iterated and dumped as quickly, and domain owners may have a more immediate legal recourse against phishers). That's the point of experimenting on features like this, to get an idea of whether or not the they would be beneficial.
Post reply on HN