Live data from Hacker News

Chrome 69: “www.” subdomain missing from URL

bugs.chromium.org

821–830 of 919 posts

Re: Chrome 69: “www.” subdomain missing from URL

#821

Most comments assume that this is for solving user confusion, or security, or building a better URL scheme, et al. It's not, that is all smokescreen. As ivs wrote[1] They are going to hide amp subdomain, so you don't know if you're looking at AMP or the actual destination. And then suddenly the whole world funnels through AMP. And for that reason, it won't be reversed until people call them for what they are actually…

Yeah... no. That's just baseless FUD. They _are_ indeed planning to get rid of AMP cache URLs, but they'll be doing it through open W3C standards anyone can use, not through special-casing their own domains: https://amphtml.wordpress.com/2018/05/08/a-first-look-at-usi...

No, this Chrome update is about hiding the "amp." subdomain from the original URL. What Google wants to achieve, is to make it impossible for the average user to tell when the entire website is being served from Google Cache.

Re: Chrome 69: “www.” subdomain missing from URL

#822
post #796

Earlier quoted context omitted.

firefox has both profiles (for actual different users) and containers for isolating stuff (i.e. a sub-profile) for a single user. The containers have a great UI/UX. I'm looking at the profile stuff now (after having not in years) and it seems counterintuitive and clunky https://support.mozilla.org/en-US/kb/profile-manager-create-... https://support.mozilla.org/en-US/kb/containers Anyway, "forced" is a strong word whe…

the containers are great thanks for sharing, will definitely use those at home! You're right I should have emphasized the feel part of my comment since the dev tools especially are just a matter of preference. However I stand by my point that the profiles are definitely not on par with chrome, since there doesn't seem to be a way to have multiple profiles open at once.

I’m sure there are other ways to do this, including specifying a profile when you initially launch the browser, but you can enter about:profiles in the address bar to see a UI to manage the profile. One of the options is to launch that profile in a new browser.

Re: Chrome 69: “www.” subdomain missing from URL

#823
post #809

Earlier quoted context omitted.

I think re-ordering like that would actually benefit technical users more, but it's probably too late to make such a change. I don't think we'd need that change for browsers to put the parts they consider most relevant in bold. That logic is simple enough right now.

really we are talking about rendering, right? not actually changing the protocol itself? (:lock: = lock unicode/emoji = secure http) :lock:/com/GOOGLE/www/maps/hawaii I am a strong proponent of the URL being part of the user interface. I should be able to manipulate what i request of a service by modifying the url. The text in the url should mean something.

Making the rendering that different from the actual URL would be very confusing, especially if it varied from program to program or within programs. Links would look one way on websites and then have a completely different form in the url bar after clicking them.

That particular rendering choice would also have the downside of being the same for both https://www.google.com/maps/hawaii and https://google.com/www/maps/hawaii

Re: Chrome 69: “www.” subdomain missing from URL

#824

Suddenly "www.com"'s value has skyrocketed in the eyes of scammers. How about: * login. .www.com -> login. .com * members. .www.com -> members. .com Even some carefully chosen .www.com's will now be valuable: * login.www. .www.com -> login. .com What a stupid idea...

That's just a bug which I'm sure will be fixed in the next release. For this to actually help scammers (after the bug is fixed) they'd need to own www.example.com but not example.com, which is unlikely to say the least.

Yes, it is a bug, but until it's fixed it's a potential attack vector.

Re: Chrome 69: “www.” subdomain missing from URL

#825

Earlier quoted context omitted.

A proposal for better security with domain names: The domain name system has been around for decades and it's a clever and proven system. It can – and should be – taught in school and, arguably, knowledge of it is, while not difficult to obtain, essential in our times. Additional ambiguity in this is probably not what we want. Arguably, the most sincere problems arise from mixed alphabets with Unicode domains and loo…

> Arguably, the most sincere problems arise from mixed alphabets with Unicode domains and look-alike characters/glyphs. No way. The most sincere problem is that hostnames do not enforce any binding to a real world identity that users can understand (nobody inspects certs) and that the most trustworthy component of a hostname is the second to the last section (right before ".com"). Humans tend to look at the front of…

Both techniques are deceptively effective; I know the following might be only anecdotally relevant, but it's the most recent case of a successful phishing attack I know of:

Recently a friend of mine didn't see the lower dot on the 'e' in a URL [0], and promptly ended up inadvertently broadcasting messages to everyone on her WhatsApp contacts list.

[0] www [dot] hẹb [dot] com/coupon/

Re: Chrome 69: “www.” subdomain missing from URL

#827
post #797

Earlier quoted context omitted.

This one is kind of a "religious" topic for me, I guess. I'm sorry that it is, but it makes me exceedingly defensive. I trained on Active Directory (AD) with a group of veteran sysadmins in 1999. I don't have access to the "Microsoft Official Curriculum" book from my class in '99 (long-since thrown away), but I have a distinct memory of a lively conversation in class re: the pitfalls of using a public domain name as…

Microsoft has provided mechanisms for split-horizon DNS service since Server 2003. views are not the only way of providing split-horizon DNS service. * http://jdebp.info./FGA/dns-split-horizon.html#SeparateConten...

Windows 2000 didn't support stub zones, however. At the time that Active Directory was new there wasn't a good way to do split-horizon DNS with the Windows DNS server.

As an aside: I really enjoy your writing about using SRV lookups. It makes me sad that SRV records aren't being as much as they could / should be.

Re: Chrome 69: “www.” subdomain missing from URL

#828

Earlier quoted context omitted.

> If you care about usability this is clearly an improvement. This is part of a long-running industry trend -- Safari does this too -- to improve the usability of the Internet and technology in general. I am genuinely interested in knowing if this is a usability improvement. Citing "Apple does it too" is not convincing to me. It seems to me if URLs are meaningless to you, hiding part of them is meaningless to you so…

The comment you are responding to (mine) literally cites this answer: "As an ISP, we often have to go to great lengths to teach users that 'www.domain.com' and 'domain.com' are two different domains" It takes only a little bit of thought and empathy with the common user to imagine how this could be confusing. Are you supposed to type in www with every site? Why did it not work when I typed it in? Etc... It's just con…

They're not changing whether you have to type it in. They're making it look like you didn't type it in when you did. This adds to the confusion you're complaining about, as the URL bar will look the same when you type in domain.com and it works as it does when you type in www.domain.com and it doesn't work.

Re: Chrome 69: “www.” subdomain missing from URL

#829
post #773

Earlier quoted context omitted.

I think this is exactly right. All the letters of the name are important and cannot be left off. If people want to equate www.domain to domain they can put a 301 redirect on the www address but the browser has no business making assumptions about what the owner of the name space thinks are equivalent.

Once upon a time, back in the middle 1990s when it was a major WWW browser, Netscape Navigator assumed that it could wrap domain names in URLs within "www." and ".com".

Interestingly, in Firefox, you can type a word into the URL bar and hit ctrl+enter to add "www" and "com". Shift+enter adds "www" and "net".

Re: Chrome 69: “www.” subdomain missing from URL

#830
This is such bullshit. They call it a "trade off", but a trade off between what exactly? On the one side there's a non-trivial number of negative consequences to this change, and on the other hand, the maintainer person literally is unable to give any other reason besides, "this isn't information that most users need to concern themselves with in most cases".

No other reason given besides that very vague assumption about .. I'm not even sure, say if most users need not concern themselves with information that isn't there, does that mean they would otherwise be concerned about it? And what does that mean? And how is it bad? And why don't you just say so?

I'm calling bullshit. If there is a reason why they decided this, it is not that. My bet it's something political.

Post reply on HN