Earlier quoted context omitted.
Good summary, basically the inter web linking will become: google:// keyword or better google keyword or even simply keyword
I've already experienced this with a vendor who sends me links to his own site as parameters of a Google search. e.g. google.com/search?q=http%3A%2F%2Fexample.com%2Fdemo3.html I don't even know how he generates those URLs and he didn't respond when I asked why he does it.
Chrome's experiment of hiding the URL is great for security
191–200 of 211 posts
Re: Chrome's experiment of hiding the URL is great for security
#192Earlier quoted context omitted.
> What about doing something more like this: https://twitter.com/aripalo/status/462942544007929857 The team may choose to do something like that in the end. That's really the point of experimenting with different approaches; they use them to get feedback, run user studies, and get a sense of what works best. > Additionally, what about addressing insecure forms that fail to utilize https. Chrome is already detects log…
But `input[type="password"]` would cover the majority of login forms. At the least, it would force the con-artist have to mimic a native password box, which is more likely to get caught by the end-user.
It's not as simple as peolpe think of it. It never is.
Re: Chrome's experiment of hiding the URL is great for security
#193One of the most secure places to live in is a prison. Is that really the direction we want software to go in? I can't help but be reminded of that infamous quote: "Those who give up freedom for security deserve neither."
As for this hiding of the URL, I'm not so convinced it'll help the situation any better. From the article itself: "To the average user, the URL is noise." In other words, if you assume that they already can't understand URLs/aren't bothering to, then what's to say they'd be able to notice the difference between a real URL and a phishing URL in those examples? To this average user, one is shorter, the other is a bit little longer. "The page looks real, that bunch of stuff up there I don't normally pay attention to anyway, so I wouldn't mind if it changed length." The one with the EV cert vs regular HTTPS is more obvious to me too since it's a different colour, but once again if you "assume illiteracy", anything could happen.
The other aspect of this is that it's only protecting "cross-domain" phishing; this is probably the majority of cases, but consider the situation where the real login page is at somehost.com/site1 while someone is trying to phish and creates another account at somehost.com/site2 . Now hiding the path to "prevent phishing" has the completely opposite effect! You could argue that this is an edge case, but it still seems to be an awfully discriminatory practice to me; I personally have password-protected accounts on various servers where the login is located at somehost.com/~myusername , and a phisherman with somehost.com/~otheruser could do this quite easily with hidden URL paths.
The real solution to preventing phishing? Education. Educate the users. Empower them with the knowledge to understand what URLs are and how they relate to where they are on the Internet. We should not continue to keep them ignorant, as they will become even more so, and that will have negative effects on the future of the Web and continue to propagate the notion that computers are "impossibly difficult to understand". I have worked with people who are otherwise very intelligent and sensible, but whose brains appear to completely leave their skull the moment they need to use a computer; and feel that this attitude may be partly responsible for that.
Re: Chrome's experiment of hiding the URL is great for security
#194Earlier quoted context omitted.
Yeah, part of me wonders how bad it would be / what would break if email clients banned outside links (e.g. beyond fragments in the email). My suspicion is that the only useful use of a link is a confirmation email which have other potential implementations...
This would effectively break email verification, which would be pretty bad.
To verify your email, please login at SiteYouHaveJustRegisteredAt
and enter the following information:
User ID: 1234
Verification code: 12345678Re: Chrome's experiment of hiding the URL is great for security
#195Earlier quoted context omitted.
I'm very surprised at that statistic, so thanks for bringing it to my attention. "They don't have to actually parse it as a query string. The fact that some URLs reveal a lot more information (like your CNN example) is a bonus." Well, what you're saying is exactly what Chrome is doing - make people only care about the domain, don't bother with the rest of the information as it's "only there to make a page unique". Wh…
I think grandparent's point was that the part after the domain serves simply as identification of the information that is requested from the domain. Just like the foo in foo@bar.com identifies the user at that email domain. The user doesn't need to understand the particular implementation of the identification, just the principle "same string, same page". This is important to understand that URLs can be copied and us…
Re: Chrome's experiment of hiding the URL is great for security
#196Earlier quoted context omitted.
> Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. There are also a surprising number of people that don't want to be literate . In the modern world, we have generally regarded such views as wrong . Basic literacy is such an important skill to have, we have even created various mandates to provide the necessary education to all children. T…
That's a really great point, thank you. My only possible objection is to observe that clearly some things are important/necessary to teach, others aren't, and all we're arguing about is which of these URL's fall into. Nobody here is (currently) arguing against such basic things as login's and passwords, or that "foo@example.com" should obviously to everyone be an email. The reason I think URL's are over the line is b…
Here is evidence that shows a lot of "average users" do have some understanding of what URLs are, and even if not the technical details, then at least the concept (which is definitely more important than the details):
Re: Chrome's experiment of hiding the URL is great for security
#197Earlier quoted context omitted.
Which IMO is a smart idea. URLs are too often hard to remember and/or type correctly if not too long anyway.
Until a competitor's SEO outranks your site for those keywords or buys similar Google AdWords.
Re: Chrome's experiment of hiding the URL is great for security
#198I get the whole "it's for preventing phishing, etc." but I believe that it shouldn't be done by hiding the URL from the user.
Furthermore, it's a real pain to have to click to see it. And guess what happen if you go to another tab and then go back to the first one? The URL is gone. You can't even compare 2 tabs URLs.
IMHO: good problem, wrong solution.
Re: Chrome's experiment of hiding the URL is great for security
#199Earlier quoted context omitted.
As I said in another comment: Try and explain to the average user why URLs on HN look like this: news.ycombinator.com/?id=123123 Whereas on CNN they look like this: http://edition.cnn.com/2014/05/04/world/africa/nigeria-abduc... Whereas on another news site (Israeli) they look like this: http://www.ynet.co.il/articles/0,7340,L-4516118,00.html Whereas on Reddit they look like this: http://www.reddit.com/r/pics/comment…
> Try and explain to the average user why URLs on HN look like this: > > news.ycombinator.com/?id=123123 Easy. All most people need to get out of that is the fact that there's a domain name there, and something to make each page unique. I suspect most people would also quickly recognize that each page has it's own number, similar to street addresses or the serial number found on just about everything these days. They…
Re: Chrome's experiment of hiding the URL is great for security
#200I followed the link, entered my username and was about to enter my password. This is the problem demanding a real solution, not some cosmetic change around the URL. Your browser should be entering the credentials. The computer is not fooled by an ugly URL. If the domain doesn't match, no password for you. If the protocol is different from the one you used the first time (https hopefully), no password for you. Yet ins…
I don't understand why do banks often have autocomplete=off. (At least my bank does.) What is the reasoning? Luckily, LastPass ignores that.