Live data from Hacker News

Chrome’s address bar will use https:// by default

blog.chromium.org

461–463 of 463 posts

Re: Chrome’s address bar will use https:// by default

#461

Earlier quoted context omitted.

i'm not sure i follow, what does split DNS have to do with DoH? i don't want my internal DNS addresses public, there is no need + security and for some addresses i have different IPs internal vs external.

Browsers send to external provider like google, rather than the network provided server which has the internal addresses (and which may override external addresses for various reasons)

split-dns will never die, it would kill far to many internal corp environments where there is no public DNS entries.

Re: Chrome’s address bar will use https:// by default

#462

Earlier quoted context omitted.

An instant messaging client shouldn’t be executing arbitrary remote code, no.

It's not really possible to prevent that. E.g. a well crafted image can easily trigger an RCE on some older versions of Android: https://nakedsecurity.sophos.com/2019/02/08/android-vulnerab... Issues like this exist at all layers of the stack, so anything touching the internet needs regular security patches.

I agree completely. But, I also think that in most cases, if a simplistic piece of software like an IM app needs a security patch every three months, regularly, it's a sign the attack surface is too large.

Re: Chrome’s address bar will use https:// by default

#463

Earlier quoted context omitted.

Https existed before icon, it shows in url. What's the point of icon when it's already written before?

The icon is arguably more accessible to the casual user.

Hiding a important part of anyhting is not ok. It even comes while copy paste. This is also not a either or case, both can be shown same time.
Post reply on HN