Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…
Google resumes its attack on the URL bar, hides full addresses on Chrome 86
361–370 of 497 posts
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#362Earlier quoted context omitted.
The only difference is that Google has endlessly more clout and depth than AOL and my fear is that where AOL failed, Google may succeed. With Firefox succumbing this week, this is pretty horrible. I’m not a Richard Stallman type, but I think it’s come to the point where if you have even the slightest pretense of being a “free web” person, using Chrome or a Chromium-based browser has become unconscionable. This compan…
I've been using Firefox/Safari on my personal devices for a couple years now, but as a web developer I unfortunately can't not use Chrome at work because of its dev tools. I try to test on other browsers when I have time - I've always made a point to push for supporting at least Firefox, as an organization - but when I'm iterating I really just need the Chrome tools. Firefox's tools always remained one or two steps b…
Why? I’m a full time developer at a Fortune 100 company and I have no issues just using the Firefox dev tools. I literally never use the Chrome dev tools. Though, this might soon change now that Mozilla has laid off the dev tool team.
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#363Earlier quoted context omitted.
Do you or anyone else have a video or screenshots of what you're talking about? Or is there a specific name of the product where AOL was doing this?
Instead of browsing via URL, companies could buy "AOL keywords". A user could just put in a keyword, like "dog food", and AOL would send them to a particular dog food page. In the days before good search engines, this was very convenient even though it was obviously pay-to-play. https://www.youtube.com/watch?v=1npzZu83AfU
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#364Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#365Earlier quoted context omitted.
The only difference is that Google has endlessly more clout and depth than AOL and my fear is that where AOL failed, Google may succeed. With Firefox succumbing this week, this is pretty horrible. I’m not a Richard Stallman type, but I think it’s come to the point where if you have even the slightest pretense of being a “free web” person, using Chrome or a Chromium-based browser has become unconscionable. This compan…
I've been using Firefox/Safari on my personal devices for a couple years now, but as a web developer I unfortunately can't not use Chrome at work because of its dev tools. I try to test on other browsers when I have time - I've always made a point to push for supporting at least Firefox, as an organization - but when I'm iterating I really just need the Chrome tools. Firefox's tools always remained one or two steps b…
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#366Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#367Earlier quoted context omitted.
All of the TLS handshake configurations are hidden from your UI. It is hard to see "what's going on". You aren't shown a cert signature each time you request a page. Yet the lock icon doesn't get hate. The non-domain information in a URL is useless for making security decisions for virtually 100% of users. If anything, it has negative utility since you can make URLs nearly arbitrarily confusing as part of a phishing…
I don’t understand, the lock icon gives you exactly the information you could want from that though? It tells you immediately if the site you are on is HTTPS, you don’t have to hover or anything. And if you want even more details (which is not something anyone does while they browse the internet, FWIW) you can also get that information too. This change hides the information that people actually expect that UI to have…
The point is that "the UI should express everything a power user could ever want to know about some security-adjacent property" is not the status-quo and people should not act like it is. Dropping to just domains is like shifting from a big blob of text including a ton of request information to just the lock icon. It distills it to something that covers basically all the information you'd ever actually need and is comprehensible to typical users.
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#368Earlier quoted context omitted.
It need not be malice. It maybe because the design people think people are too stupid to understand URLs. As other comment mentioned, Safari does it too. The trend seems to be abstracting away stuff like filesystem. Many people I know don't even organize stuff into folders on their phones. Everyone seems to dump everything in Download or something like that. The existence of separate applications for Music, Video and…
> It maybe because the design people think people are too stupid to understand URLs You may be right, but it's hard to see why this would be a concern in 2020. The number of users who have actually grown up with URLs in their childhood increases all the time.
With ubiquitous computing, the ratio of children who understand to children who don't is a little higher than when I grew up, but not that much. Clearly, some children grew up with me who were willing didn't get the skills because they had no access, but lots of kids are either need directed instruction to attain technical literacy, or are unwilling or incapable of attaining it.
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#369Earlier quoted context omitted.
My first thought when reading this was relief... For my mother. I've spent most of my adult life trying to teach my parents to look at the address bar to make sure they're on bankofamerica.com and not some random phishing domain. That kind of falls apart though when it's... bankofamerica.comm.phishingdom.com/{random filler}/bankofamerica/user/login HN users are fantastic at thinking all technologies should revolve ar…
The root domain is highlighted in FF. This must be enough for visual testing. If you want a more reliable approach then you need to work with a whitelist and clear warnings.
https://storage.googleapis.com/pub-tools-public-publication-... https://kumarde.com/papers/urls.pdf
Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86
#370Earlier quoted context omitted.
A layperson wouldn't know what the "7394" in "7394 Foobar Road" means or why "Foobar Road" is a road called "Foobar" but that does not mean we should give Google the right to eliminate street addresses. A URL is an address. All your mom needs to know is that if she goes to https://news.ycombimator.com/item?id=24156986 , she will end up at something and she will be able to come back to it later, that's what's useful a…
The average person knows exactly what the "7384" means, they understand it as a number that uniquely identifies a house along that street
There are some cases, like with Facebook/Google/YouTube, where they add a bunch of tracking info onto the URL, obscuring which segments of the URL are optional vs. required.
But I think that's exactly the point, isn't it? To make it a lot less noticeable when you're being tracked. This change will enable a lot of URL funnybusiness that harms users.