Live data from Hacker News

Google adds experimental setting to hide full URLs in Chrome 85 address bar

androidpolice.com

701–710 of 733 posts

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#702

Earlier quoted context omitted.

As someone who has worked on the front line of the fight against phishing and account takeover in the past, I can assure you and others that you're dead wrong. Making this change was a recommendation I made to the Chrome team years ago because the number of people who would reliably type in their username and password to a site hosted on hacked web servers (supershop.co.hk/account_login.php etc) was just so high. And…

As someone who has had to teach grumpy old high school teachers how to not fall for phishing and mitm attacks, I really can't see the problem here. The way I used to teach was very simple and very effective: there are 3 parts to a URL - the first part tells you if the connection is secure, the second part tells you who you're connected to and the third part tells you where on that site you are. The first part needs t…

Sure, absolutely. People understand domain names, they're found on billboards, adverts, business cards, all over the place. And it's a simple text match. Does the bar say "google.com" or "google.co.uk"? Yes? Then you're on Google. So when it's simple people get used to checking and can be reasonably told they're expected to do it.

The greying out and replacement of padlocks etc, the anti-phishing training, it's all just working around a historical design problem in browsers. There's no need for it to exist. Notably, mobile apps don't have this problem.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#703

Earlier quoted context omitted.

While you argue your case, that one has to vocalise if one wants something, well, you are still ignoring the basic want of not having your privacy violated and the fact that you can vocalise something willfully, without it being spied away from you. I'm also extremely suspicious of the suggestion that this is something only power users would want.

You can certainly vocalize something willfully. But the people who don't have to do any vocalization at all and are generating megabytes to gigabytes of data on how the application is used by their mere use of it are going to always have a default stronger voice than people who bother to show up on message boards to voice specific concerns.

I actually agree that if you are willing to ignore privacy concerns and a potentially large part of your userbase, then you can simply send megabytes to gigabytes of telemetry and pretend that is the best you could have done and that you have the best data. I'm simply saying that's not a good idea.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#704

Earlier quoted context omitted.

That's exactly what Firefox does. I am typing this on Firefox and in the address bar "ycombinator.com" is in black and the rest of the address is in grey.

Well chrome has been doing that for a while too but what I mean is more like significant parts of the url for trust like say the user in github.com/ / , because the user represents a significant silo similar to if it were instead organized like .github.com/ For example if I were to go to something like / / " rel="nofollow">https://raw.githubusercontent.com/ / / or the most relevant parts of the url as far as security…

Well, whilst that is a nice idea I can't see it happening anytime soon. Attempting to work out if a part of a URL represents a user name seems like a bit if an impossible task to me. I guess you could encode rules for specific well known sites but I doubt you could ever create a general solution, and if a site changed its URL you would become unstuck until you rolled out a fix.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#705
post #62

While this might be useful for a casual user, hidden URLs are a huge problem for web developers. Asking for a screenshot from client is not enough, now I'll have to provide additional instructions how to copy/paste full URL when reporting issues. Not to mention all possible problems with misconfigured servers when www and www-less domains lead to same website, but some script refuses to work on one of those. While it…

I'm already annoyed by the hassle it has become to copy a substring of the URL into the clipboard, due to the schemes being hidden. Nothing has been won by hiding http(s):// as well as the www subdomain.

I had a frustrating experience with this only yesterday.

I was trying to search for the word "aquarium" but chrome kept filling in "https://aquarium.org", I would delete the ".org" and only the word "aquarium" was shown in the search bar, which was the word I was trying to search.

Of couse "https://" was hidden, so I was actually submitting "https://aquarium" which was not a valid domain and it took many frustrated clicks and enters to actually google the word that was shown. Absolutely infuriating as the true state of the search bar was hidden.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#706
post #408

Earlier quoted context omitted.

That's reasonable. The thing that makes me wary of people like that also make me wary of some people on my "side." A lot of them use language and tactics to attack people deemed evil by their in-group that they would criticize if used by the out-group.

If I were to pick a single litmus test for rejecting a group or movement, outgrouping might be it. It's self-deluding, unprincipled, and easily turns hateful. If there's no path toward reconciliation or peace, what are the remaining outcomes? Utter dominance? Fizzling out? Segregation? I expect more.

It depends on the movement. Are there jerks among people in the LGBTQ+ movement? Sure. Am I going to quit fighting for equality because of them? Nope. There are much worse people who would prefer it if I rolled over and died.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#707

Earlier quoted context omitted.

You can certainly vocalize something willfully. But the people who don't have to do any vocalization at all and are generating megabytes to gigabytes of data on how the application is used by their mere use of it are going to always have a default stronger voice than people who bother to show up on message boards to voice specific concerns.

I actually agree that if you are willing to ignore privacy concerns and a potentially large part of your userbase, then you can simply send megabytes to gigabytes of telemetry and pretend that is the best you could have done and that you have the best data. I'm simply saying that's not a good idea.

a) It's not a large part of the user base who switches off telemetry and they have the telemetry to know that

b) for being "not a good idea", it's pretty much industry standard now for everything from business software to video games.

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#708
post #696

Earlier quoted context omitted.

> the first thing that strikes you about ~juan-ramirez/financial-aid is that something is wrong because you are not Juan Ramirez User studies indicate that the first thing a user notices is... Nothing. The gobbledygook in the path is so much noise for the average user that they don't notice if the path seems off. In fact, it makes sense to hide it from a security standpoint to decrease the odds that users go informat…

> User studies indicate that the first thing a user notices is... Nothing. There are a thousand ways to screw up a user study, but one of the best ways to detect a screw up is if they say that users either always or never do something. > In fact, it makes sense to hide it from a security standpoint to decrease the odds that users go information blind to the domain, because we already know that improper domain routing…

You're using concrete numbers but you don't have the statistics or analysis to know what the numbers are. I'm going to assume the company that has telemetry on its own product does.

... but probably more importantly, nobody likely needs to hack together an extension after all. Older news story about how Chrome will add an option to show the full URL bar as non-default.

https://www.zdnet.com/article/googles-chrome-will-give-you-a...

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#709
post #550

Earlier quoted context omitted.

To improve browser experience all you have to do is use a computer that doesn't suck. The fact that your primary browser is on a tiny phone display is a problem with phones, not with browsers. Browser for phones can evolve to match the disabled nature of their device's but lets hope such gimpings don't filter back into actual desktop computers.

"Spend more money on your computer" is a fine solution for a bay area software engineer. It's not a solution at all for the half of America that would have to sell their car to cover a $400 ER visit.

I make under $12k/year. I live in the midwest. I would have to sell my car for a $1k ER visit.

It's still cheaper to build a $450 real desktop computer (that lasts decades+) than it is to buy a $800 4 year life gimped smart phone that can't do any productive work any isn't in my control.

(And my $20 nokia dumb phone has worked perfectly since 2006 for phone calls/text.)

Re: Google adds experimental setting to hide full URLs in Chrome 85 address bar

#710

This, along with the inability of disabling the async dns feature in the latest Chrome for desktop versions (thus making pihole/adguard irrelevant), makes me accelerate the change to another browser.

I hate to be the person who's like "you're holding it wrong" but your usage of DNS is incorrect according to the RFCs. All configured DNS servers are assumed to serve the same content. The idea of every DNS request "trying" the first server, timing out, and then the next, and the next is a calcified implementation detail.

A DNS client looking at the list of servers, and marking the speed and reachability of each server is the most basic optimization. It makes no sense for clients to add n seconds to every request for every unreachable DNS sever.

The async DNS feature using Chrome's internal DNS client which behaves differently than glibc and so pihole appears to not work. Chrome is not injecting its own DNS servers into the mix or whitelisting anything, it always uses your system's DNS servers, it just looks them all up in parallel which it is allowed (and encouraged) to do by the RFC.

Make sure all your configured DNS servers are pihole and everything will work.

Post reply on HN