Live data from Hacker News

Chrome 69: “www.” subdomain missing from URL

bugs.chromium.org

41–50 of 919 posts

Re: Chrome 69: “www.” subdomain missing from URL

#41
post #24

This isn't entirely without precedent. Firefox does something similar by greying out the `www` in the UI, Chrome just decided to take things a step further by hiding it entirely.

FF greys out all the subdomains, not just www. Good for anti-phishing, I guess.

Re: Chrome 69: “www.” subdomain missing from URL

#42
post #10

Is this really a big deal? Don't many websites either redirect the www to the non-www, or the other way around?

It's about the principle. www is a valid subdomain. Browsers are supposed to be as unopinionated as possible since they are browsers , not mediators, and their job is to implement the standards of the web.

It's still there though. You just have to click on the address bar and it appears (along with the scheme). This is not an issue.

Re: Chrome 69: “www.” subdomain missing from URL

#43
This and many other changes over a course of a short period of time have caused me to go to Firefox exclusively now. I heard Firefox is going to stop third party cookie tracking altogether. Why not give Google the big finger and use a different browser? Vote with your cold hard actions if you feel so strongly about something.

Re: Chrome 69: “www.” subdomain missing from URL

#44
post #24

This isn't entirely without precedent. Firefox does something similar by greying out the `www` in the UI, Chrome just decided to take things a step further by hiding it entirely.

Firefox's behaviour is that is makes everything except the eTLD+1 grey, because that's what's normally useful for evaluating authenticity. There's no distinction made between `www` and any other subdomain.

Re: Chrome 69: “www.” subdomain missing from URL

#45
post #30

This is idiotic and harmful. We already lost information about the protocol, because somebody believed it is "too complex" for users. Now we're losing other parts of the URL. It's making a joke of the SSL/TLS padlock, too — what exactly is the padlock supposed to tell me? It used to signify that a "known authority" certified that I'm connected to whatever I see in the URL bar. But now that browsers take liberties wit…

The padlock was already meaningless.

Re: Chrome 69: “www.” subdomain missing from URL

#46
Google attempted a more extreme version of this four years ago: https://www.extremetech.com/computing/181657-google-moves-to...

So they're doing it again, just slower: https://www.extremetech.com/computing/276454-google-wants-to...

I'm pretty sure the eventual plan is to force everyone to browse the web using a version of the App Store, which we all know is incredibly secure, and never difficult to use.

Re: Chrome 69: “www.” subdomain missing from URL

#47
Since everyone is wondering why, and since I happened to stumble across a reason during my time as a pentester, here you go:

Spearphishing is still one of the most common ways of breaching a corporate network. If I target you, you will likely fall for one of my attempts. If you are a company rather than a person, my odds go way up, because I have N chances to trick someone rather than 1 (where N is roughly the number of people at the company with email access).

This is one of those things that everyone says "Ha, I'm smart. I'd notice. You can't trick me."

And maybe you are. But you're also distracted. And that's my greatest advantage against you. All I need is to sneak in an unexpected Github prompt that looks completely authentic, and now I have your Github password. Wanna bet you don't have 2FA turned on, even though you know you really ought to? And even if you do, it's getting easier to social engineer your way past AT&T's lovely customer support: https://www.youtube.com/watch?v=caVEiitI2vg

Ok, what's the point?

This: Every character in the URL bar unrelated to the apex name is a deadly distraction.

Right now, how do you know you're actually on HN instead of some knockoff? "ycombinator.com".

How many characters do you have to read unrelated to that? "https://news. /item?id=17927972"

The most vital part of a URL for vetting identity is also, usually, the hardest to see.

Now, I don't know whether google made this change in order to assist with this. But it's one possible justification, and a step in a good direction.

We may not like it, just like we didn't like when Google removed the clickable "cached" links from search results, but in this case consumer protection outweighs our urges as a power user.

Re: Chrome 69: “www.” subdomain missing from URL

#49
post #30

This is idiotic and harmful. We already lost information about the protocol, because somebody believed it is "too complex" for users. Now we're losing other parts of the URL. It's making a joke of the SSL/TLS padlock, too — what exactly is the padlock supposed to tell me? It used to signify that a "known authority" certified that I'm connected to whatever I see in the URL bar. But now that browsers take liberties wit…

Given the adoption rate of SSL, I imagine the padlock itself will become useless even without Chrome's changes. Does it mean anything if almost every website has it?

Re: Chrome 69: “www.” subdomain missing from URL

#50
post #12

Yo, this is... going too far, c'mon now. While sure, www seems odd now, it's still a subdomain and we're inching into territory of obscuring things that matter for small gains in end-user perception that aren't _that_ impactful.

Yeah this is weird. Which users are bothered enough by the leading www enough to justify messing with semantics?
Post reply on HN