Live data from Hacker News

An Update on the Lock Icon

blog.chromium.org

91–100 of 169 posts

Re: An Update on the Lock Icon

#91
post #9

I approve of getting rid of the lock icon, showing only a broken lock for HTTP and no lock for HTTPS. It's always been weird to have site permissions settings revealed by clicking that lock. But the replacement icon looks really strange to me. They're calling it a "tune icon," but I've never seen a tune icon like this, with just two circles and two lines. Looks weird. I'm surprised that it fared well in the experimen…

It represents a vertical list of toggle icons, commonly seen these days in preferences panes, including the flyout shown in the same image: https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh... A gear icon would work as well, but the intent was immediately obvious to me.

Good luck describing that icon in words over the phone.

Re: An Update on the Lock Icon

#92
post #16

If you're using Chrome, right-click the URL bar and check "Always show full URLs", so you can see the https:// prefix like it's 1999. This also fixes a variety of UX problems with editing URLs. By the way, does anyone know of a good alternative to http://neverssl.com ? I had been using this for years, but now it supports SSL for some unfathomable reason.

My latest annoyance with the Chrome URL bar is when certain things autofill (it might be bookmarks, but I think I see it in other frequently-visited addressed too), instead of it populating with the full URL so I can edit it, it just pops up as a piece of text to the right of where I'm typing, so I can see the URL that will fill if I hit enter but I can't edit it. It just started doing this a few months ago maybe?

Re: An Update on the Lock Icon

#93

Earlier quoted context omitted.

Traffic lights. Everyone everywhere knows red, yellow, and green now, and how to navigate around colorblindness (both red and green lights are tinted to be distinguishable).

Traffic lights are a combination of color and position; even if one is completely colorblind, the position of the lit lamp is sufficient to discern the signal. The above suggestion doesn't have that sort of double-encoding of the data. (This holds even for the odd horizontal signal, though I would expect most non-colorblind people would not be able to tell you the orientation from memory. … and … there are plenty of…

Traffic lights still work without position, as they'd have to at night, in fog, in glare, and so on.

Point is, the meaning of the colors appears to be universally understood thanks to driving, and distinguishing the colors has been addressed.

If there are exceptions, I suppose localizations and accessibility modes are just the thing.

Re: An Update on the Lock Icon

#94
post #9

Earlier quoted context omitted.

It represents a vertical list of toggle icons, commonly seen these days in preferences panes, including the flyout shown in the same image: https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh... A gear icon would work as well, but the intent was immediately obvious to me.

Good luck describing that icon in words over the phone.

"See the 2 people with all their limbs cut off, staring up at the clouds?"

Re: An Update on the Lock Icon

#95
post #16

If you're using Chrome, right-click the URL bar and check "Always show full URLs", so you can see the https:// prefix like it's 1999. This also fixes a variety of UX problems with editing URLs. By the way, does anyone know of a good alternative to http://neverssl.com ? I had been using this for years, but now it supports SSL for some unfathomable reason.

Same thing happened to ross-tech: https://www.ross-tech.com/ Chrome adding HTTPS for whatever reason.

Re: An Update on the Lock Icon

#98
post #51
post #50

It’s a continuation of the trend that led to them removing Extended Validation indicators: https://duo.com/decipher/chrome-and-firefox-removing-ev-cert... Here’s how they used to appear: https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easie…

Long ago I was reading someone registered corp in some other jurisdiction with the same company name which he wanted to impersonate with EV cert. And succeeded. So what are you proposing is of questionable value.

That researcher was Ian Carroll, who created a new "Stripe, Inc" company in Kentucky, a clone of the one registered in Delaware, and was therefore able to get an EV certificate issued for his new company that looked very similar to one issued for the Delaware company.

His original research site appears to no longer be online (https://stripe.ian.sh/), but you can read more about it in these articles:

https://www.bleepingcomputer.com/news/security/extended-vali...

https://arstechnica.com/information-technology/2017/12/nope-...

Re: An Update on the Lock Icon

#99
post #15

I think its possible there could be a backlash against this change, as even though many peoples' understanding of the security implications of the lock icon didn't align with reality, their expectation vis a vi "lock icon means secure, no lock means insecure, be careful if there isn't a lock" could force a broad unlearning of something that the security community has tried to teach over the past ten to fifteen years.…

We have collectively taught all the non-tech folks not to enter sensitive information, such as credit card numbers, in non-secure forms that don't show the lock.

This used to mean a lot when certificates were harder and more expensive - the rationale was fly-by-night bad actors wouldn't bother. This is most definitely not the case now.

Realistically as well, it's mostly to guard against man-in-the-middle interception - as we all know once it hits the server handling the SSL termination, all security bets are off.

FWIW Chrome does (and I assume will continue) saying "Not secure" where the padlock used to be, for HTTP sites. So there is at least that as a warning.

Re: An Update on the Lock Icon

#100
post #25
post #22

Earlier quoted context omitted.

It should always be possible to reach http://example.com (also .org and .net) over HTTP.

Chrome redirects to https://example.com , so that's no bueno for testing http:// in your URL bar. Edit: I'm running Chrome OS 113 beta. Maybe they changed something recently, to automatically use HTTPS unless prohibited by the server? This also happens in Guest mode with no extensions.

In (50%) of Beta, Chrome attempts HTTPS and silently falls back to HTTP on all HTTP links. We're still poking around with opt-outs, currently if you allow insecure content via Page Info / Site Controls, we stop upgrades.
Post reply on HN