Chrome 69: “www.” subdomain missing from URL
691–700 of 919 posts
Re: Chrome 69: “www.” subdomain missing from URL
#692Earlier quoted context omitted.
Isn't this a security risk? What if someone malicious takes control of the www.com domain?
This entire change is a security risk - there is no guarantee that any subdomain has the same owner as the primary, and that's not even getting into subdomain hijacking.
Re: Chrome 69: “www.” subdomain missing from URL
#693Earlier quoted context omitted.
> "Many people can't tell you the difference between a modem, router, OS, browser, or website." They don't care, nor should they. How many people know how many spark plugs are in their car? You're correct. We, the more tech-literate, take too much for granted; and most experiences and learning curves are too far over the head of the "average" user. It's not them. It's us.
I think the comparison to spark plugs is misleading when we talk about URLs and security. It's more like looking in the mirror before changing lanes. It's something you need to check in order to stay safe. Mirrors, like URLs, are just an implementation detail. But since currently driving works with mirrors, you have to learn how to use them.
We have enough historical context to realize that things like parsing URLs by eye is unsafe for the general population, and always will be. The solution is to engineer that need out of existence.
You might want to consider that manufacturers have added blind spot detectors to cars as people are bad at changing lanes safely, even with all the training in the world.
Re: Chrome 69: “www.” subdomain missing from URL
#694Re: Chrome 69: “www.” subdomain missing from URL
#695Re: Chrome 69: “www.” subdomain missing from URL
#696Re: Chrome 69: “www.” subdomain missing from URL
#697Earlier quoted context omitted.
A proposal for better security with domain names: The domain name system has been around for decades and it's a clever and proven system. It can – and should be – taught in school and, arguably, knowledge of it is, while not difficult to obtain, essential in our times. Additional ambiguity in this is probably not what we want. Arguably, the most sincere problems arise from mixed alphabets with Unicode domains and loo…
How about displaying an identicon, that is rendered from the domain, in the address bar? People might soon learn what the icons of their important sites look like and will easily detect if somebody is trying to phish their bank account.
Re: Chrome 69: “www.” subdomain missing from URL
#698Earlier quoted context omitted.
I don't even know how many cylinders I have!* Why should I care? Put key in. Press gas down. Car goes forward. Works for me. "How do you not know that?" Why would I need to know this? Why do I need to know what a cylinder is to drive? Is this even a logical question with electric cars now? You are arguing what should be vs. what is. * Well, I don't currently drive but I couldn't tell you with 100% accuracy the number…
I guess, the simile isn't entirely on the same level. You may not know how many cylinders there are in your car, like you may not know the number of cores in the CPU of your computer. They are both essentially hidden. But you do know how many pedals there are in the car and probably, how many switches there are for the lights, and that the wiper has different steps of speed etc. You even manage to control these few e…
I bring up in a previous reply that mirrors, and now lights, pedals, and other controls, that these are directly user-facing and must be interacted with in order to get anything done. Even knowing there is an engine that might need engine-y things like water and oil.
But where is the requirement a user knows about URLS in order to use the web?
Way back when we had AOL keywords. Now we have Google and apps and other tools that make URLS unnecessary.
My grandmother that I I mentioned before. She browses solely through bookmarks and via Google results. That a URL exists is not only an implementation detail but completely unneeded and unused in her case.
Then something like an SSL cert? Where it will work just fine without? I don't even want to imagine trying to explain that to my grandmother before sending her off to her decades old AOL mail inbox.
Only recently with Chrome displaying "Not Secure" have I even noticed any concern or interest amongst non-technical friends and aquaintances.
Re: Chrome 69: “www.” subdomain missing from URL
#699> This is a dumb change. No part of a domain should be considered "trivial". As an ISP, we often have to go to great lengths to teach users that "www.domain.com" and "domain.com" are two different domains... What ISPs teach their users anymore these days? Why the heck do we want to go back to that? Time for a modicum of historical perspective. If you care about usability this is clearly an improvement. This is part o…
> They don't see the positives because they're technically advanced enough and don't benefit from simplification (or so they think). I'm noticing despite the invocation of vague concepts of progress and usability... you haven't articulated any particular case for how this represents either. No model for why it's simpler or more usable. "Safari does this too" or imprecise aspersions about the supposed "whining and gri…
I literally began my comment by citing this:
‘As an ISP, we often have to go to great lengths to teach users that "www.domain.com" and "domain.com" are two different domains...’
It takes only a very small amount of thought and empathy with the average user to understand how the extraneous www prefix can be confusing. It can lead to failures like thinking you have to use it with every website. It enables fraud by making “wwwexample.com” look more normal. Etc.
Your comment is a textbook example of “the principle of it all” argumentation. You cite no concrete examples of problems caused by hiding www from the UI. Not that we should expect none, but the right conversation to have is whether the usability benefits outweigh them. Not technical pedantry or “vague and imprecise” warnings about what may come if we let this pass.
Re: Chrome 69: “www.” subdomain missing from URL
#700Earlier quoted context omitted.
You lack the compassion that comes with experience. My $dayjob has our AD root domain the same as our public root domain. Because we implemented AD in the year 2000, and this was Microsoft’s recommendation for domain naming way back then. And if you use Exchange, you can’t rename your AD domain, you have to rebuild your forest and migrate piecemeal. So we’re stuck with it. The practice of using Corp.example.com did n…
This one is kind of a "religious" topic for me, I guess. I'm sorry that it is, but it makes me exceedingly defensive. I trained on Active Directory (AD) with a group of veteran sysadmins in 1999. I don't have access to the "Microsoft Official Curriculum" book from my class in '99 (long-since thrown away), but I have a distinct memory of a lively conversation in class re: the pitfalls of using a public domain name as…