Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

121–130 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#121
post #48

Earlier quoted context omitted.

I already see this happening in Japan. Rarely do I see ads include URLs, they have a search term.

Which IMO is a smart idea. URLs are too often hard to remember and/or type correctly if not too long anyway.

Until a competitor's SEO outranks your site for those keywords or buys similar Google AdWords.

Re: Chrome's experiment of hiding the URL is great for security

#122
post #42

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Well, if www and .com become meaningless then advertisers will use "type xxx yyy into you bar" instead (which goes to the search engine) or hash tags (already doing this). Then Google could come up with "associate permanent keywords with your URL" (for a small fee of course) to guarantee that those keywords won't shift under you when your Google ranking changes.

Aren't Google AdWords effectively "stable keywords for sale" today?

Re: Chrome's experiment of hiding the URL is great for security

#123
post #101

Earlier quoted context omitted.

respectfully ... chrome is already breaking half of the copy/pastes i do because it's from my history and not a page that's already loaded. do you have any idea how many people actually use copy/paste? i would venture that ctrl-c/ctrl-v is probably the only key binding that the majority of computer users of all walks of life use. half of the places i seem to be pasting links into don't pick up the links without the h…

Why should it make copying, pasting, or editing URLs more difficult? Right now in stable Chrome, you click once on the URL bar and it selects the entire URL. Then you can Ctrl-C to copy, Ctrl-V to paste, or click again to put the cursor in a specific place to edit it. That shouldn't be any different with this new Chrome feature they're testing.

Indeed, or make it even simpler: F6>CTRL+C

The F6 functionality is the reason I welcome this, Chromium devs aren't really taking control from us more tech savvy users, they're making it easier for regular users to spot the relevant part of a URL.

I already use F6 for all interaction with the omnibar as it is. Also, I'm not sure which browser it was (Opera or Firefox), but I distinctly recall either of those a few years ago having the exact same functionality discussed here, where only the domain was shown unless the URL field was active.

Re: Chrome's experiment of hiding the URL is great for security

#124
post #48

Earlier quoted context omitted.

I already see this happening in Japan. Rarely do I see ads include URLs, they have a search term.

Which IMO is a smart idea. URLs are too often hard to remember and/or type correctly if not too long anyway.

Agreed. It also solves another problem in Japan, namely that brand names etc are usually written in Japanese letters, but URLs in ASCII (yes, I'm aware of IDN, but haven't ever seen it used). This is obviously not limited to Japan, I wouldn't be surprised if other countries used the same trick.

Re: Chrome's experiment of hiding the URL is great for security

#125

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

So this came from the same genius who came up with the "checkbox to show all your passwords in clear text without any further safeguards" feature? Man, you're a menace to the web.

Personal attacks are not allowed on HN.

Re: Chrome's experiment of hiding the URL is great for security

#126
Phishing is an attack vector promoted by email. Email clients should not create automatic hyperlinks from email content and email senders should not be providing links in the body of the email.

This is entirely a problem that should not be solved by breaking the web. This is basically an attempt by Google to insert itself between the primary connecting mechanism of the web and should be rejected wholesale.

The URL contains everything the user needs to determine the origin of the web site they are visiting. This doesn't provide users tools to ensure their safety only the illusion of safety.

Re: Chrome's experiment of hiding the URL is great for security

#127
post #117

I don't understand all the resistance to this. It's doing the work that currently all non-programmer users of the web (the vast majority) have to do themselves every time they look at a URL - parse out the meaning. For example, when my wife is checking our credit card charges, she isn't using " https://online.americanexpress.com" . She's using "Amex's website". That's how she would tell me what she's doing; that's ho…

I got it about a week and a half ago in Canary, and I stuck with it for about a week until it was disabled. I didn't like the idea but I'm interested in new UI experiments. I hated it. Not only for the reasons other people mention (it makes copying and pasting cognitively more difficult, and even after a week it didn't really get any easier) but also because I would argue that on sites with halfway-decent URLs, it's…

> but also because I would argue that on sites with halfway-decent URLs, it's a navigation device

I agree, but I will argue that websites that suddenly seem disorienting without a URL are poorly designed. If we take away the crutch they will have to stop relying on it and improve.

Re: Chrome's experiment of hiding the URL is great for security

#128
post #111
post #69

There are a number of people in this thread posting things like "the average user should be educated" and "why break things for us technically savvy people just to please people who can't be bothered to read a whole url". I really con't stand this behavior. Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. Insisting that people are somehow…

> Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. There are also a surprising number of people that don't want to be literate . In the modern world, we have generally regarded such views as wrong . Basic literacy is such an important skill to have, we have even created various mandates to provide the necessary education to all children. T…

Just as it would be unreasonable to require that anyone who drives a car roughly understands how an engine works, it would be similarly unreasonable to require that anyone who uses the internet roughly understands how addressing works. It is of course true that your car ownership experience will be greatly enriched by understanding roughly how an engine works, and that your internet experience will be greatly enriched by understanding how addressing works. But neither should be a prerequisite.

You underestimate how subtle the concepts underlying addressing are, probably because, like many technical people, you have understood how URLs work for so long that you can no longer remember what it is like to not understand them.

Re: Chrome's experiment of hiding the URL is great for security

#129
Surely I can't be the only one here who has dealt with actual flesh and blood average users?

This would do nothing form them. It requires that you pay attention to the tab, which most don't do, read where they are, again something the majority don't do, and be savvy enough to realize that "site.com" is now different to "https://www.site.com/somthing$%else/and&&a+lot_of[]crud" something that I doubt 1 in 100 will figure out.

Unless it's in red, has a klaxon attached to it and flashes enough to give you a seizure either the majority or a very large minority of your users will ignore it.

Post reply on HN