Live data from Hacker News

Google resumes its attack on the URL bar, hides full addresses on Chrome 86

androidpolice.com

421–430 of 497 posts

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#421
post #68

Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…

"Conspiracy theory!" has become a term for dismissing genuine concerns.

So the theory is that this is part of Google's evil plan to make it impossible to tell the difference between an AMP page and the real page because the next step is to remove the URL bar.

Given that this change makes it plainly obvious what domain you're on... Now tell tell me if this is a genuine concern or a conspiracy theory.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#422
If the domains were written from left to right / highest to lower level (example: com.ycombinator.news/... or com/ycombinator/news/...), this (particular) phishing problem would go away and there would be no reason to do this.

Out of ignorance, any proposals were made to change the order of (writing) domains levels? Or to create an alternative one (if that is even possible)?

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#423

Earlier quoted context omitted.

item?id=24156986 is readable and meaningful

Not to laypeople. Most people have no idea what query params are, or even what part of the url the top level domain is. You can explain what they are easily, but it still wouldn't be useful to laypeople. What can my mom do with "item?id=24156986"? Outside of developing something that interfaces with HN, I don't know what I would do with that info either.

Don't think for laypeople, think for yourself, you're an expert in computers, you know what is better. The laypeople will benefit from your expertise.

The laypeople are not idiots, they understand things, in particular referencing an item by ID.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#424
post #111

Earlier quoted context omitted.

I really don't get why people think that signed exchanges are this super nefarious plot to destroy the open web when it's exactly the thing that would make a distributed web possible. Disconnecting content authorship and publishing with hosting so that literally anyone can host web content securely is fantastic! * Want to bootstrap your IPFS network? You can safely and securely host a huge chunk of the web from big p…

All of which can be done without AMP, hiding the url, or forcing companies to use it or lose their SEO placements. It's the SUM of the pieces that point to Google's endgame, not the individual pieces themselves. I have an idea. Move forward with signed exchanges, and then prohibit them from being used to obscure the content source (more specifically, require the 3rd party to reveal themselves)

I mean I don't disagree with you that I should be able to look and see what entity actually served me the content in the same way I can see who signed the sites SSL cert but I'm still 100% in favor of having browsers present display the bundle's URL in the browser because that's the site your viewing.

A site that uses Cloudflare as a CDN isn't cloudflare.com/site/nyt.com. The whole point of these things is that if you have some vested interest in being a CDN for chunks of the web for your users you don't have to set up a partnership with them and proxy their site or have their certs you just download the bundle and go.

I detest AMP, but I'm very much looking forward to signed exchanges.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#425
post #194
post #68

Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…

The strange part there is that this is mobile Chrome following the mobile Safari UX which has never been criticised like this. It's just bizarre.

Apple users choose to get a system that does different things that restrict them in non-obvious ways. Those people are not going to complain much.

Chrome is the default option for browsers. People don't really choose it anymore.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#426
post #68

Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…

> Folks seem to miss the fact that google chrome was a minor competitor initially it IE - and their focus on things like ... security ... helped them become absolutely dominant. Security is a very small factor, if a factor at all, for Chrome to have become dominant. The main reason is because they keep/kept pushing everyone to install Chrome when you visited https://google.com (by showing you a small popup window).

Do you have evidence?

Because I remember trying Chrome and immediately switching because it was miles ahead. So did my friends. It was faster and had slicker UI.

Nobody keeps using a shittier browser no matter how many times you shove it on their faces.

Btw Chrome is still faster than Firefox for stuff that matters and often by a considerable amount:

https://www.phoronix.com/scan.php?page=article&item=chrome83...

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#427

Earlier quoted context omitted.

Google has not only become dominant because their product is good. First and foremost, they leveraged their market power through android and their search engine to get people to use chrome.

As another said -- chrome was dominant before Android was a player. Firefox blew a hole in the IE wall. Then chrome came along and was more acid compliant, leaner (Ux/ui), faster, and it's approach of per-tab processes was superior to a lock-up prone Firefox, or IE.

Firefox required admin rights to install on Windows, what locked most of the user base out of its reach.

Chrome got his market by silently installing as the IE rendering engine, and by being bundled with other software.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#428
post #111

Earlier quoted context omitted.

I really don't get why people think that signed exchanges are this super nefarious plot to destroy the open web when it's exactly the thing that would make a distributed web possible. Disconnecting content authorship and publishing with hosting so that literally anyone can host web content securely is fantastic! * Want to bootstrap your IPFS network? You can safely and securely host a huge chunk of the web from big p…

> I really don't get why people think that signed exchanges are this super nefarious plot to destroy the open web My biggest concern is that the request will go to a google-owned server, where google can fully track me, and my browser would be lying to me about being on a non-google estate I might assume be free from Google’s tracking. Site-owners will now also be forced to buy into Google Analytics since they have n…

> My biggest concern is that the request will go to a google-owned server, where google can fully track me.

I'm not exactly sure what the fear here is. You're only getting to the page by clicking a link in Google Search and then your browser fetches a bundle from Google's servers.

In your ideal world you would click a link in Google Search, telling Google what you're looking at, and then connect to the site via Cloudflare, and the source site's servers telling them too?

The flip side to these is that your browser can actually act as your agent with this. If you find yourself a nice privacy-respecting CDN then your browser can try to pull from there when you click any link and you now have way less exposure.

Re: Google resumes its attack on the URL bar, hides full addresses on Chrome 86

#430
post #68

Wow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from t…

They could emphasize the FQDN without removing the URL.

They've been doing this (showing the rest in grey) for a long time.
Post reply on HN