Live data from Hacker News

Chrome's experiment of hiding the URL is great for security

jakearchibald.com

61–70 of 211 posts

Re: Chrome's experiment of hiding the URL is great for security

#61

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

I agree that this experiment isn't demonstrating a perfect mitigation, but it's important to appreciate that it's currently vastly easier for a phisher to permute paths and subdomain components than it is to create a convincing ETLD+1. There are various reasons for this, including less text for a phisher to work with and registration requirements for ETLD+1 domains (which means they can't be iterated and dumped as qu…

What about doing something more like this: https://twitter.com/aripalo/status/462942544007929857

The issue isn't users recognizing path, it's the domain. It's also that they aren't taking special care while logging in.

Additionally, what about addressing insecure forms that fail to utilize https. Chrome is already detects login forms. So just warn users by turning the origin chip to a red background when they are on a login page.

On the whole, supporting secure logins would be better for the internet.

Re: Chrome's experiment of hiding the URL is great for security

#62

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

respectfully ... chrome is already breaking half of the copy/pastes i do because it's from my history and not a page that's already loaded. do you have any idea how many people actually use copy/paste? i would venture that ctrl-c/ctrl-v is probably the only key binding that the majority of computer users of all walks of life use. half of the places i seem to be pasting links into don't pick up the links without the h…

Something similar happened with various other of Google's properties a while back — Google's use of intermediate redirector URLs that broke cut-and-paste.

I'd prefer to reference the destination URLs and wsites in the documentation and related materials I was creating, and the only way to do that with various Google web properties was to visit the destination site and cut and paste from the browser from there — otherwise I'd end up with a Google "link shortener" obfuscating the domain, and possibly also eventually interrupting the connection if (when?) Google decided to discontinue or update the redirector service.

Further, this Google practice filled the browser history with intermediate URLs, which rendered the browser history far less useful.

I would not expect Google to stop these behaviors, though. Switch search engines. Vote with your clicks and with the data you (don't) expose to Google.

Re: Chrome's experiment of hiding the URL is great for security

#63

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Good summary, basically the inter web linking will become: google:// keyword or better google keyword or even simply keyword

Reminds me of AOL

Re: Chrome's experiment of hiding the URL is great for security

#64

As a member of the Chrome security team and one of the original instigators for this experiment, yes the whole point is to prevent phishing. The fact is that phishing is one of the most common attack vectors for most people, and the way the URL is currently displayed does very little to protect them. So, we're experimenting with ways of displaying the essential information (origin and TLS state) as clearly as possibl…

Does the kind of person who falls victim to a phishing attack pay attention to anything on the URL bar anyway? Are they going to have any idea what the green padlock thing or "secure connection" even mean in the context?

Re: Chrome's experiment of hiding the URL is great for security

#65
post #42

Earlier quoted context omitted.

So phishers buy domains with a levenshtein distance of 1 or two. It solves one problem, but creates an entire class of users that don't understand what a URL is. Who benefits? Google and search engine providers because now they can manipulate future internet users to believe that search engines are the internet. We've reverted to AOL in 1995. There is nothing more that can be productively argued about this topic. The…

Well, if www and .com become meaningless then advertisers will use "type xxx yyy into you bar" instead (which goes to the search engine) or hash tags (already doing this). Then Google could come up with "associate permanent keywords with your URL" (for a small fee of course) to guarantee that those keywords won't shift under you when your Google ranking changes.

That's sort of been happening in the UK. Instead of some companies giving out a URL, they'll just say "Search xyz for more information"

Re: Chrome's experiment of hiding the URL is great for security

#66

I don't understand all the resistance to this. It's doing the work that currently all non-programmer users of the web (the vast majority) have to do themselves every time they look at a URL - parse out the meaning. For example, when my wife is checking our credit card charges, she isn't using " https://online.americanexpress.com" . She's using "Amex's website". That's how she would tell me what she's doing; that's ho…

I like how myself and my (not all technical) friends know what URLs are and can copy them if they want to link me to something. Now they probably won't be able to figure out how.

Have you even tried using this feature? You can enable it in chrome://flags. You can still copy and paste the URL just fine. Thanks for the downvote. I'd love to hear you refute my argument, rather than spew nonsense complaints.

Re: Chrome's experiment of hiding the URL is great for security

#67

I followed the link, entered my username and was about to enter my password. This is the problem demanding a real solution, not some cosmetic change around the URL. Your browser should be entering the credentials. The computer is not fooled by an ugly URL. If the domain doesn't match, no password for you. If the protocol is different from the one you used the first time (https hopefully), no password for you. Yet ins…

I don't understand why do banks often have autocomplete=off. (At least my bank does.) What is the reasoning?

Luckily, LastPass ignores that.

Re: Chrome's experiment of hiding the URL is great for security

#68
I was a little surprised by this. I bet most people here refrain from clicking in urls in emails, and would instead enter the company's url themselves in the browser, and follow the path to renew the domain or whatever needed to be done. If I do follow a url in an email like this, I at least look at the email headers, or actually look at the url first. I'm not saying I'm immune from any possible phishing attack, but these defensive behaviors have become just a reflex by now, and I guess I assumed that anyone with this kind of knowledge and experience shared these reflexes.

Re: Chrome's experiment of hiding the URL is great for security

#69
There are a number of people in this thread posting things like "the average user should be educated" and "why break things for us technically savvy people just to please people who can't be bothered to read a whole url".

I really con't stand this behavior. Not everybody, not even most people, want to understand "how to web works", "how urls work" or anything else along those lines. Insisting that people are somehow wrong to not want to understand this is just ridiculous - as ridiculous as if I had said "we're not going to let anyone drive a car unless they know how to tune an engine" or some such.

I for one am very happy that the creators of automobiles have bothered to make the process so simple, even a moron at automobiles like me can drive in car and have it work 99.9% of the time, and the rest of the time - it's clear I need to take it to an expert.

We as the software developers, product designers and UX experts of the world should stop trying to tell the world what it should and shouldn't care about, but rather, use that as input to decide how to build our software so actual people can use it.

Do I love this Chrome experiment? I don't know. But I know that I'm willing to trade a few seconds of discomfort of my own, which can probably be stopped by tweaking one configuration setting, in order to save the majority of the population who aren't tech savvy from the problems of phishing and just generally giving them a better user experience.

Re: Chrome's experiment of hiding the URL is great for security

#70

Earlier quoted context omitted.

I agree that this experiment isn't demonstrating a perfect mitigation, but it's important to appreciate that it's currently vastly easier for a phisher to permute paths and subdomain components than it is to create a convincing ETLD+1. There are various reasons for this, including less text for a phisher to work with and registration requirements for ETLD+1 domains (which means they can't be iterated and dumped as qu…

What about doing something more like this: https://twitter.com/aripalo/status/462942544007929857 The issue isn't users recognizing path, it's the domain. It's also that they aren't taking special care while logging in. Additionally, what about addressing insecure forms that fail to utilize https. Chrome is already detects login forms. So just warn users by turning the origin chip to a red background when they are on…

The problem with that is you can't detect all login forms. If you cannot detect all of them, there's a way to hide them from the browser.
Post reply on HN