Live data from Hacker News

Google resumes its attack on the URL bar, hides full addresses on Chrome 86

androidpolice.com

391–400 of 497 posts

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#391

Earlier quoted context omitted.

I don’t understand, the lock icon gives you exactly the information you could want from that though? It tells you immediately if the site you are on is HTTPS, you don’t have to hover or anything. And if you want even more details (which is not something anyone does while they browse the internet, FWIW) you can also get that information too. This change hides the information that people actually expect that UI to have…

What if I want more information? I want to know what TLS version both parties negotiated. I want to know who signed the cert and when it expires. Etc. etc. The point is that "the UI should express everything a power user could ever want to know about some security-adjacent property" is not the status-quo and people should not act like it is. Dropping to just domains is like shifting from a big blob of text including…

I mean, I was upset when Google moved the certificate details from just click on the lock to click on the lock and go into developer tools and do some other bs I've forgotten since I'm no longer working where I need to confirm certificates. However, I figured that the number of people checking certificates was very small, so trying to use our weight to change Google's mind was fruitless. Fighting against hiding the URL seems a lot more tractable --- although, I just took it as a sign that Google doesn't want me to use their browsers, so I stopped.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#392
This article had a major thread two months ago: https://news.ycombinator.com/item?id=23516088.

It has been updated, apparently to mention an animation technique in the URL bar of Chrome 86, but that's apparently not SNI (https://hn.algolia.com/?query=%22significant%20new%20informa...) since the discussion here isn't mentioning it. So I think we have to call this on the dupe side. See also https://hn.algolia.com/?query=follow-up%20by%3Adang&dateRang... for how we moderate these.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#393
post #68

Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…

They could just color it differently or show it in bold text.

Hiding the rest is clearly motivated by something else.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#394
post #19

When the final version is implemented in a couple of years you will no longer see any URL, that way it won't be as evident that most sites on the web will be loaded from Google. Google is also attacking this issue from a different perspective with Signed Exchanges [1][2], to fake the URL and ensure their success in becoming the gatekeepers of the internet. If you refuse to become a content provider for Google's visio…

I wonder how bookmarking and auto-complete work with signed exchanges. I don't think they could ever remove the URL completely because it conflicts with their extortion scheme for AdWords where they'll sell your trademarked words to the highest bidder.

What happens if Chrome shows no URL and Google sells the AdWord for your bank's name to a malicious actor? That's a huge liability can of worms IMO.

I'm not sure the signed exchanges are all bad either. I'd rather have visitors seeing example.com than example.google.com/amp/ or google.com/amp/example.com. Isn't it better for your brand to be in the URL and bookmarks / auto-complete to go to your domain (assuming it works like that)?

I'm not convinced the whole web identity push is 100% bad. I don't trust Google, but as a general concept I think there's some technical merit in the idea.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#395
post #111
post #78

Earlier quoted context omitted.

They are boiling frogs: https://en.m.wikipedia.org/wiki/Boiling_frog Little changes over time, so you don't see the end game right away. Signed exchanges and further hacking up / hiding the URL will come. This change only hides some of the URL, with a hover action that shows it again.

I really don't get why people think that signed exchanges are this super nefarious plot to destroy the open web when it's exactly the thing that would make a distributed web possible. Disconnecting content authorship and publishing with hosting so that literally anyone can host web content securely is fantastic! * Want to bootstrap your IPFS network? You can safely and securely host a huge chunk of the web from big p…

All of which can be done without AMP, hiding the url, or forcing companies to use it or lose their SEO placements.

It's the SUM of the pieces that point to Google's endgame, not the individual pieces themselves.

I have an idea.

Move forward with signed exchanges, and then prohibit them from being used to obscure the content source (more specifically, require the 3rd party to reveal themselves)

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#396

Something I haven't seen anyone here bring up yet: many URLs are meaningless to humans past the domain. For an example, look at the top of this page. The only semantic meaning in the URL for this post is `news.ycombinator.com`. The rest, `item?id=24156986`, is meaningless to a human. (But, of course, meaningful to HN's backend.) A lot of (most?) of the URLs on the web are not semantic . They're naked application look…

As an example of semantic URLs, think of Wikipedia articles (ironically, featured in the article). The URL tells you directly what you're reading about. Why is it useful to show it in full? Because page titles are no longer visible during usual browsing sessions - they're shown in tab headers, which means in practice, you only get to see a favicon and maybe a word of the title if you're not a tab hoarder. So once you…

I think you've identified some meaningful next steps to try after highlighting that the origin is the most significant part of the URL. Maybe the omnibox space can show the page title?

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#397
post #227
post #219

Earlier quoted context omitted.

>The rest, `item?id=24156986`, is meaningless to a human Removing Url's is throwing the baby out with the bathwater though. Take Stack Overflow for an example: https://stackoverflow.com/questions/53302536/vue-test-utils-... The only thing you need to actually get to the question is https://stackoverflow.com/questions/53302536 , but they intentionally add an extra human readable section for laypeople. If google actual…

That extra human readable section is not added for humans. It’s added for SEO. That is, for Google.

The URL structure is usually mirrored on the actual website by way of clickable breadcrumbs or as navigational information architecture.

People understand slashes indicate folders and directories, even though database-driven CMSes do not use folder structures. They can figure out that they can go one level from from "example.com/cars/toyota" by removing the "/toyota"

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#399

Vote with your choices (use a different browser). That's the only way to address such behaviour. Yes, I know the 95% out there who don't even know what a browser is but only know Chrome's icon gives access to the web won't understand any of this and they will continue giving mega-corporations a critical mass of unquestioning users to be used, but we have no other options. We either express our voices, no matter if th…

> Yes, I know the 95% out there who don't even know what a browser is but only know Chrome's icon gives access to the web won't understand any of this I find it fascinating how some people in tech bubbles think everyone else is a stupid sheep who can't possibly understand such incredibly complex concepts like what a "browser" is.

I spent 6 months tutoring senior citizens on how to use computers (specifically it was word processing).

Believe me... some of the gaps in knowledge are alot wider than you'd imagine. None of them even knew what I meant when I mentioned the "URL bar". These are people who had previously used the web to search, pay bills, etc. To them, "the internet" was the entire computer, and had no concept that the browser was a distinct entity within it.

You're 100% right this is teachable but it is important not to understate the size of the canyon.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#400
URLs are supposed to be human-readable because they're intended to signal to users what the content is about.

What is not human-readable, although fully semantic, is all the parameter trash that comes after full URL. Stuff like "utm_source='twitter'&utm_medium='social_share" or cookie information and the like.

I can understand trimming that information, but hiding the URL to show the domain only makes no sense.

Post reply on HN