Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

131–140 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#131

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Good summary, basically the inter web linking will become: google:// keyword or better google keyword or even simply keyword

no it wouldn't. You might put that in an ad (and as people above note, this is already happening), but this only changes what's displayed in the location bar. It would be stupid to link to another site through a web search when you can just link to the site.

although, I'll note that once again, the internet is already on the case. The link you were looking for was http://lmgtfy.com/?q=keyword

Re: Chrome's experiment of hiding the URL is great for security

#132
post #21

Earlier quoted context omitted.

> phishing is a very big problem Is it? What are the numbers? So many annoying things are done in the name of "security" without much justification (both online and in real life); Chrome removed the protocol for no reason and Firefox felt obliged to do the same, and now we're removing the whole url just to help folks who can't be bothered to read it? Another comment suggests "source code highlighting" for the url, wh…

I feel I'm fairly immune to traditional phishing because I never click a URL in an email. If namecheap sends me an email saying one of my domain names is about to expire, I don't use their "Renew Now" link I go to "namecheap.com" (not hard to type), log in, and renew the name. Banks and other organizations that send long complicated links in emails and encourage people to click them are part of the reason phishing is…

Yeah, part of me wonders how bad it would be / what would break if email clients banned outside links (e.g. beyond fragments in the email). My suspicion is that the only useful use of a link is a confirmation email which have other potential implementations...

Re: Chrome's experiment of hiding the URL is great for security

#134
post #111

Earlier quoted context omitted.

> Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. There are also a surprising number of people that don't want to be literate . In the modern world, we have generally regarded such views as wrong . Basic literacy is such an important skill to have, we have even created various mandates to provide the necessary education to all children. T…

Just as it would be unreasonable to require that anyone who drives a car roughly understands how an engine works, it would be similarly unreasonable to require that anyone who uses the internet roughly understands how addressing works. It is of course true that your car ownership experience will be greatly enriched by understanding roughly how an engine works, and that your internet experience will be greatly enriche…

There's a rich irony in your avoidance of the most obvious car analogy possible: between internet addressing and street addressing.

Understanding URLs is in no way similar to even a rudimentary understanding how an internal combustion engine works.

What it's most similar is understanding how we address and route physical destinations so that you can get there in your car.

Re: Chrome's experiment of hiding the URL is great for security

#135

Earlier quoted context omitted.

So you think crackers(>hackers) and people with bad intention will be unable to see the URLs and won't be able to do phishing easily. So, through obscurity you will achieve security. Edit: or you expect users to notice phishing attempts more clearly by only displaying the domain name?

It's the latter. By only displaying the domain name users are more likely to notice a scam domain name, e.g. the Halifax.co.uk case in the parent blog post.

Thanks for understanding former or latter iquestion which I wrote at once:-)

Re: Chrome's experiment of hiding the URL is great for security

#136

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Good summary, basically the inter web linking will become: google:// keyword or better google keyword or even simply keyword

We've seen this before:

http://www.musicman.com/00pic/credits.jpg

Re: Chrome's experiment of hiding the URL is great for security

#137

Earlier quoted context omitted.

What about doing something more like this: https://twitter.com/aripalo/status/462942544007929857 The issue isn't users recognizing path, it's the domain. It's also that they aren't taking special care while logging in. Additionally, what about addressing insecure forms that fail to utilize https. Chrome is already detects login forms. So just warn users by turning the origin chip to a red background when they are on…

> What about doing something more like this: https://twitter.com/aripalo/status/462942544007929857 The team may choose to do something like that in the end. That's really the point of experimenting with different approaches; they use them to get feedback, run user studies, and get a sense of what works best. > Additionally, what about addressing insecure forms that fail to utilize https. Chrome is already detects log…

You could detect forms that have more than one user provided input field as they are submitted. This wouldn't detect most search boxes or forms that use hidden inputs to transmit values to the backend.

Re: Chrome's experiment of hiding the URL is great for security

#138

Earlier quoted context omitted.

I feel I'm fairly immune to traditional phishing because I never click a URL in an email. If namecheap sends me an email saying one of my domain names is about to expire, I don't use their "Renew Now" link I go to "namecheap.com" (not hard to type), log in, and renew the name. Banks and other organizations that send long complicated links in emails and encourage people to click them are part of the reason phishing is…

Yeah, part of me wonders how bad it would be / what would break if email clients banned outside links (e.g. beyond fragments in the email). My suspicion is that the only useful use of a link is a confirmation email which have other potential implementations...

It could be interesting if Gmail did the Chrome experiment in email links in a popover, by displaying the domain of a link...

Re: Chrome's experiment of hiding the URL is great for security

#139

Earlier quoted context omitted.

As a developer, if this is going to hide any useful information on first glance I am not sure how I feel about that. I already feel like Chrome has started shunning developers with that over the top annoying pop-up any time I open a new window (Ctrl+N, type, stop typing because I have to move my mouse to close the popup), and moving towards forcing developers to distribute their extensions through the play store (whi…

What is the popup you're encountering? Because it sounds like a bug, and I'd like to make sure someone is working on fixing it (or has already done so).

The custom extension popup, and you dont want to fix it(status is wontfix) ,where a simple checkbox in the settings could have fixd it... you made our lives miserable.

Re: Chrome's experiment of hiding the URL is great for security

#140
I hate this behavior in iOS 7 Safari so much. Whenever I want to modify the URL, it's a huge pain (on HN specific links, usually) -- there's no way to edit the parameters at the end of a URL (that I've found), and typing the whole long url on a phone or tablet isn't fun (especially when it includes lots of parameters, rather than just a simple path). It's one of the few things an alternate browser on iOS actually fixes.
Post reply on HN