Earlier quoted context omitted.
Everybody is complaining about the lack of contrast between the root domain and the rest of the domain in the URL bar. I reckon, both in Chrome and in Firefox, there is quite noticeable contrast between the root domain and the path/subdomain. If the contrast was bigger, then the path would be unreadable, which undesirable too.
In Chrome the domain is black and the path is grey. You could make one red and the other green and that would be actual contrast. Or give the domain a background and border. There's more ways to contrast things than adjusting the lightness of black.
Chrome's experiment of hiding the URL is great for security
171–180 of 211 posts
Re: Chrome's experiment of hiding the URL is great for security
#172Re: Chrome's experiment of hiding the URL is great for security
#173As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
http://googlechromereleases.blogspot.com/2014/04/stable-chan...
I agree that this would be a big win.
If this type of rendering were in place it would protect the user in most cases even when a secondary issue like the one I reported exists in the full rendering code. Well worth the minor inconvenience of having to click the 'chip' to show the full url if you happen to need to see/copy it.
Re: Chrome's experiment of hiding the URL is great for security
#174Earlier quoted context omitted.
That should probably go in the Guidelines if true - it's not there now.
If that isn't derivable from the guidelines' call for civility, nothing is.
Re: Chrome's experiment of hiding the URL is great for security
#175Earlier quoted context omitted.
As I said in another comment: Try and explain to the average user why URLs on HN look like this: news.ycombinator.com/?id=123123 Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc... Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html Whereas on Reddit they look like this: http://www.reddit.com/r/pics/comment…
> Try and explain to the average user why URLs on HN look like this: That's easy. "The information following the domain name is used to route your request to the appropriate destination". > Each one of these is a completely different implementation detail which the average user doesn't care about and, honestly, won't necessarily understand without understanding the underlying technology behind these sites. Why do the…
You're right that I could still send them mails though, in exactly the same way people use URL's - rote copying them, then letting the technology (or mail system) work its magic. I don't need to understand your PO box example to get it working.
Re: Chrome's experiment of hiding the URL is great for security
#176Earlier quoted context omitted.
As I said in another comment: Try and explain to the average user why URLs on HN look like this: news.ycombinator.com/?id=123123 Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc... Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html Whereas on Reddit they look like this: http://www.reddit.com/r/pics/comment…
> Try and explain to the average user why URLs on HN look like this: > > news.ycombinator.com/?id=123123 Easy. All most people need to get out of that is the fact that there's a domain name there, and something to make each page unique. I suspect most people would also quickly recognize that each page has it's own number, similar to street addresses or the serial number found on just about everything these days. They…
"They don't have to actually parse it as a query string. The fact that some URLs reveal a lot more information (like your CNN example) is a bonus."
Well, what you're saying is exactly what Chrome is doing - make people only care about the domain, don't bother with the rest of the information as it's "only there to make a page unique". What exactly are we disagreeing on?
Re: Chrome's experiment of hiding the URL is great for security
#177Earlier quoted context omitted.
So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…
I agree that this experiment isn't demonstrating a perfect mitigation, but it's important to appreciate that it's currently vastly easier for a phisher to permute paths and subdomain components than it is to create a convincing ETLD+1. There are various reasons for this, including less text for a phisher to work with and registration requirements for ETLD+1 domains (which means they can't be iterated and dumped as qu…
Re: Chrome's experiment of hiding the URL is great for security
#178As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…
Getting rid of the URL makes users effectively out of touch with 'where' they are on the web and within a website.
A browser is a navigation device, a browser without a sense of location is the digital equivalent of being lost.
Re: Chrome's experiment of hiding the URL is great for security
#179Earlier quoted context omitted.
There's a rich irony in your avoidance of the most obvious car analogy possible: between internet addressing and street addressing . Understanding URLs is in no way similar to even a rudimentary understanding how an internal combustion engine works. What it's most similar is understanding how we address and route physical destinations so that you can get there in your car.
As I said in another comment: Try and explain to the average user why URLs on HN look like this: news.ycombinator.com/?id=123123 Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc... Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html Whereas on Reddit they look like this: http://www.reddit.com/r/pics/comment…
You're missing the point, you don't have to understand that anymore than you have to understand why my street number is 4 digits long or my street name ends in "street" instead of avenue, crescent, drive, lane, etc.
Re: Chrome's experiment of hiding the URL is great for security
#180Earlier quoted context omitted.
> Try and explain to the average user why URLs on HN look like this: > > news.ycombinator.com/?id=123123 Easy. All most people need to get out of that is the fact that there's a domain name there, and something to make each page unique. I suspect most people would also quickly recognize that each page has it's own number, similar to street addresses or the serial number found on just about everything these days. They…
I'm very surprised at that statistic, so thanks for bringing it to my attention. "They don't have to actually parse it as a query string. The fact that some URLs reveal a lot more information (like your CNN example) is a bonus." Well, what you're saying is exactly what Chrome is doing - make people only care about the domain, don't bother with the rest of the information as it's "only there to make a page unique". Wh…
Sadly the simple principle of "same URL, same information" breaks down somewhat because of cookies (and, to a lesser extent, IP localization and user agent). http://facebook.com/ shows completely different information dependent on the logged-in account, and in fact that same person mentioned above was aware that URLs without a path part is the home page of that domain, and was thus expecting that http://facebook.com/ would show the same information to everyone. I'm not sure whether he/she really believed that the whole world should be seeing his/her posts, but it surely is a bad move by Facebook, it actively breaks the premise of URLs and is thus arguably damaging for internet literacy (and perhaps they are purposely doing it to mislead some people into a false sense of personal importance).