Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

151–160 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#151
While I agree the URL for the "normal" users is just meaningless ballast, I don't understand how this is great for security.

So what, now "normal user" Joe will still input his Paypal's user and password, because the web page clearly displays a very nice PayPal logo and has the same look&feel as the original page. What is to be gained?!

I feel like it is just an attempt to dumb it down and put even more power in Google's hands, transforming http:// into google://

No, thank you.

Re: Chrome's experiment of hiding the URL is great for security

#152

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

I would prefer if the hostname was clearly separated and highlighted with the path after. I don't really feel the need to be able to instantly enter a new url outweighs my desire to see what URL I currently am on.

Re: Chrome's experiment of hiding the URL is great for security

#154
post #140

I hate this behavior in iOS 7 Safari so much. Whenever I want to modify the URL, it's a huge pain (on HN specific links, usually) -- there's no way to edit the parameters at the end of a URL (that I've found), and typing the whole long url on a phone or tablet isn't fun (especially when it includes lots of parameters, rather than just a simple path). It's one of the few things an alternate browser on iOS actually fix…

In Safari, you can tap the address bar and hold down on the url to bring up the pointer and scroll over to whatever you want to edit/copy. It's the same behavior in Chrome on iOS7 (apart from the fact that the pointer is at the beginning of the URL in Safari and in the end in Chrome, which albeit, is preferable).

Ah! I didn't realize you could hold down and scroll left/right. Thanks!

Re: Chrome's experiment of hiding the URL is great for security

#155

Earlier quoted context omitted.

Just as it would be unreasonable to require that anyone who drives a car roughly understands how an engine works, it would be similarly unreasonable to require that anyone who uses the internet roughly understands how addressing works. It is of course true that your car ownership experience will be greatly enriched by understanding roughly how an engine works, and that your internet experience will be greatly enriche…

There's a rich irony in your avoidance of the most obvious car analogy possible: between internet addressing and street addressing . Understanding URLs is in no way similar to even a rudimentary understanding how an internal combustion engine works. What it's most similar is understanding how we address and route physical destinations so that you can get there in your car.

As I said in another comment:

Try and explain to the average user why URLs on HN look like this:

news.ycombinator.com/?id=123123

Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc...

Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html

Whereas on Reddit they look like this:

http://www.reddit.com/r/pics/comments/24p3tm/japanese_photog...

Each one of these is a completely different implementation detail which the average user doesn't care about and, honestly, won't necessarily understand without understanding the underlying technology behind these sites.

Remember: Most users barely understand, if at all, what a browser is! And if you want to see a comparable challenge, try to explain to someone just one thing - why do some sites have www vs. not.

The parent's sentence was really great:

"You underestimate how subtle the concepts underlying addressing are, probably because, like many technical people, you have understood how URLs work for so long that you can no longer remember what it is like to not understand them."

Re: Chrome's experiment of hiding the URL is great for security

#156
post #99

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

There is more that can be productively argued about this topic, at least for parties who decide to not insist otherwise. URLs won't go away as long as people are still sharing websites on social networks or their own websites. I don't see the problem with not displaying the entire URL at the top of the browser window, if no actual functionality it lost. I this case, there's not even any additional clicks required to…

I agree with the possibility for productive debate, my comment is probably a bit too cynical. I just see a lot of redundant arguments, bad analogies and strawmen coming up soon and jumped the gun.

Re: Chrome's experiment of hiding the URL is great for security

#157
post #111
post #69

There are a number of people in this thread posting things like "the average user should be educated" and "why break things for us technically savvy people just to please people who can't be bothered to read a whole url". I really con't stand this behavior. Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. Insisting that people are somehow…

> Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. There are also a surprising number of people that don't want to be literate . In the modern world, we have generally regarded such views as wrong . Basic literacy is such an important skill to have, we have even created various mandates to provide the necessary education to all children. T…

It's not literacy, it's more like knowing car's engine error codes. Arcane knowledge which is very useful if you're mechanic but would be mostly useless trivia for anybody else. Guessing "example.com/2014/04/18/the-great-quux" is a date-based URL is a nice parlor trick but most sites don't even have this URL scheme or any URL scheme at all. Next to none of the phishing-relevant sites does. No print ad would have URL of any complexity - if it would have anything beyond domain name it'd be a single keyword.

Re: Chrome's experiment of hiding the URL is great for security

#158
post #125

Earlier quoted context omitted.

So this came from the same genius who came up with the "checkbox to show all your passwords in clear text without any further safeguards" feature? Man, you're a menace to the web.

Personal attacks are not allowed on HN.

That should probably go in the Guidelines if true - it's not there now.

Re: Chrome's experiment of hiding the URL is great for security

#159
post #155

Earlier quoted context omitted.

There's a rich irony in your avoidance of the most obvious car analogy possible: between internet addressing and street addressing . Understanding URLs is in no way similar to even a rudimentary understanding how an internal combustion engine works. What it's most similar is understanding how we address and route physical destinations so that you can get there in your car.

As I said in another comment: Try and explain to the average user why URLs on HN look like this: news.ycombinator.com/?id=123123 Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc... Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html Whereas on Reddit they look like this: http://www.reddit.com/r/pics/comment…

> Try and explain to the average user why URLs on HN look like this:

That's easy. "The information following the domain name is used to route your request to the appropriate destination".

> Each one of these is a completely different implementation detail which the average user doesn't care about and, honestly, won't necessarily understand without understanding the underlying technology behind these sites.

Why do they have to understand the "underlying technology" at all?

If you think physical addresses are simpler, you'd be wrong:

   Sgt John Smith
   Headquarters Company
   7th Army Training Center
   ATTN: AETT-AG
   Unit 28130
   APO AE 09114-8130
or:

   Mr John Doe 
   CMR 333 Box 2345
   APO AE 09903-0024
or:

   John Doe
   C/O Acme, Inc.
   STE 12
   123 Main St NW
   Placename, State  12345-1234
or:

   Jane Doe 
   P.O. Box 562 
   Placename, State 12345
or (this is dual addressing, guess what it means? it doesn't mean the P.O. box is at 123 Main St NW):

   Jane Doe 
   123 Main St NW
   P.O. Box 562
   Placename, State 12345-1234
or:

   Don Johnson
   Professor, GIS Studies and Internet Arguments
   UCIA Computer Science Department
   5th Floor Rockefeller Building East
   C/O UCIA
   12345 Main Address Street
   Placename, State, 12345-1234
These are complicated, and we haven't even delved into common abbreviations, street layout consistency, relative addressing, or, god forbid, international addressing.

Yet somehow people write, address, and successfully send mail, every single day. They get in their cars and navigate the interstates and the weird street grids and one-way streets that they're unfamiliar with, and eventually wind up at the right place.

Or, they plug the address into their GPS and get there, without ever really understanding how the GPS performs the routing, just that it does, but still fully cognizant of what the addresses mean, even if they don't understand the system under which they were allocated.

I don't think your argument holds water; not even a little.

Re: Chrome's experiment of hiding the URL is great for security

#160
post #125

Earlier quoted context omitted.

Personal attacks are not allowed on HN.

That should probably go in the Guidelines if true - it's not there now.

If that isn't derivable from the guidelines' call for civility, nothing is.
Post reply on HN