Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

1–10 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#6
post #4

As the article states, this is likely good for the non-tech-savvy people, but what it needs is a button to copy the URL as easily. If the problem is misleading subdomains, would some kind of a detection and a warning be a better solution to the problem?

Did not try it, but apparently if you click on the domain label, it provides a standard url field so you can copy / modify the url.

Re: Chrome's experiment of hiding the URL is great for security

#7
As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possible, while removing the components that are not security relevant and are currently being abused to trick users.

No one has any intention of diminishing usability or making it hard manipulate URLS. The team working on this is still actively refining things and studying what works and what doesn't. But, phishing is a very big problem, and this change to the omnibox shows real promise in countering the attacks. So, I think we would be remiss in not pursuing the investigation further.

Re: Chrome's experiment of hiding the URL is great for security

#8
A native breadcrumbs display might be a great addition to this.

I mean, show the domain first, and show a subsection that the website provides, so I can click on that to navigate. If I click on the domain name, provide a standard url input field.

Google already does that with search results: http://d.ekin.io/bOdk

Re: Chrome's experiment of hiding the URL is great for security

#9
post #6
post #4

As the article states, this is likely good for the non-tech-savvy people, but what it needs is a button to copy the URL as easily. If the problem is misleading subdomains, would some kind of a detection and a warning be a better solution to the problem?

Did not try it, but apparently if you click on the domain label, it provides a standard url field so you can copy / modify the url.

In this case I'd be more open to the idea, although having some advanced preference to disable it if needed would be helpful, should it become the default.
Post reply on HN