24 ms·
Google resumes its attack on the URL bar, hides full addresses on Chrome 86
- AnonHP 6y agoI get emails from some banks with instructions to spot phishing. One of those is to look at the full URL in emails or on websites to know if it’s authentic or not. For better or worse, the URL scheme is what we have to identify websites and pages. Hiding that on larger screens doesn’t make much sense. It also hinders learning for the next generation.
- mkl 6y agoActually, that's their argument for doing it. Most users don't understand the different bits of a URL, to know whether it's from the site they think it's from. See (huge) previous discussion from two months ago: https://news.ycombinator.com/item?id=23516088 https://news.ycombinator.com/item?id=23516088 Personally, for my own purposes, I think hiding any bit of the URL is incredibly inconvenient. Already hiding the www. is seriously annoying. I will switch this new behaviour off and hope they don't remove that option.
- HumblyTossed 6y ago> Actually, that's their argument for doing it. If AMP didn't exist I might be slightly more inclined to believe them.
- mkl 6y agoThey have a plan for that, too, a proposed standard (SXG: Signed HTTP Exchanges, currently only supported in Chrome and derivatives) that lets them hide the fact that AMP is being used: https://developers.google.com/web/updates/2018/11/signed-exchanges https://developers.google.com/web/updates/2018/11/signed-exc... and more background: https://www.eff.org/deeplinks/2020/07/googles-amp-canonical-web-and-importance-web-standards-0 https://www.eff.org/deeplinks/2020/07/googles-amp-canonical-...
- aquova 6y agoIf that's really their justification, then I wish they would take the approach that Firefox does - show the full URL but have the domain name in white and the rest of the URL in a muted color. It provides the full information as well as highlighting the most important info for spotting a phishing scheme.
- oefrha 6y ago> show the full URL but have the domain name in white and the rest of the URL in a muted color Which is exactly what they do at the moment.
- thadjo 6y agowow I've never noticed this. it's pretty subtle.
- _underfl0w_ 6y agoMeaning that the need for the new hiding feature is... what, exactly?
- untog 6y agoPresumably that a number of users still don’t get it and the value to the remaining users is very small.
- mkr-hn 6y agoI didn't notice Firefox does this before your comment. On my screen the domain is black and the rest of it is gray. Maybe it's because I don't have any kind of night mode thing on. I'm sure the colors would be inverted with that enabled.
- dwheeler 6y agoIt is not just inconvenient, hiding or modifying URLs is a lie and is a security problem. Hiding part of the URL means that you don't really see what's going on, and that is the first step towards a security problem, not away from it.
- athenot 6y agoI agree. But I'm afraid Google's solution is going to be along the lines of showing a green mark for anything served from their own servers, with the subtle implication that anything else is less trustworthy.
- UncleMeat 6y agoAll of the TLS handshake configurations are hidden from your UI. It is hard to see "what's going on". You aren't shown a cert signature each time you request a page. Yet the lock icon doesn't get hate. The non-domain information in a URL is useless for making security decisions for virtually 100% of users. If anything, it has negative utility since you can make URLs nearly arbitrarily confusing as part of a phishing attack.
- saagarjha 6y agoI don’t understand, the lock icon gives you exactly the information you could want from that though? It tells you immediately if the site you are on is HTTPS, you don’t have to hover or anything. And if you want even more details (which is not something anyone does while they browse the internet, FWIW) you can also get that information too. This change hides the information that people actually expect that UI to have–that’s why there’s an option to in-hide it!
- UncleMeat 6y agoWhat if I want more information? I want to know what TLS version both parties negotiated. I want to know who signed the cert and when it expires. Etc. etc. The point is that "the UI should express everything a power user could ever want to know about some security-adjacent property" is not the status-quo and people should not act like it is. Dropping to just domains is like shifting from a big blob of text including a ton of request information to just the lock icon. It distills it to something that covers basically all the information you'd ever actually need and is comprehensible to typical users.
- jpt1 6y agoI didn't know there is an option to change it back, thanks for pointing that out. I've found it really frustrating when trying to copy different parts of the URL.
- ffwd 6y agoJust fyi, the google chrome plugin "Suspicious Site Reporter" reverts the url back to how it always was, with http:// http:// and www and everything else. It's very lightweight and you can just leave it on, don't have to report anything or do anything with it. Hopefully it remains this way _forever_, even with these newer changes as well.
- tbodt 6y agoOr you can right click the omnibox and choose "Always show full URLs"
- dayjobpork 6y agoCountdown until scammers figure out a way to screw up the parsing code and get Chrome to show the incorrect fake url
- eli 6y agoThe bank may say that, but it's not actually good or practical advice.
- ziml77 6y agoEmbarrassingly I let checking the URL bar give me a false sense of security and got phished for the first time just a few days ago. They put a fake URL bar into the page and made it look like a proper OAuth2 URL. (My 2nd factor saved me from giving them access since it slowed me down enough to notice some subtle oddities, but I still had to change the password since that was already submitted) The real protection against this is making it impossible for me to send credentials to the wrong party. Normally my password manager helps with that, but I had just switched managers a couple days before and it wasn't recognizing all sites properly (likely due to the lack of a database of known equivalent URLs). If the site was using WebAuthn, there wouldn't have been any issue because the imperfect URL checks by me and the password manager would not be necessary.
- rnet85 6y agoThis has been the standard on safari for years. Are you saying that people who use safari suffer from those problems?
- draw_down 6y agoReally wish they would stop trying to do this.
- asimpletune 6y agoIt’s sort of surreal to feel so disenfranchised about it too. Like, no one wants this, I’m sure they know that, but they just don’t care.
- Liquix 6y agoThey know that no matter what they do they're too big to be stopped. We cannot rely on on any of the five eyes governments to break their monopoly because their data collection programs are of immense value to these nations. If they ever are broken up, it'll be a 30 year smoke and mirrors campaign like when we 'broke up' Ma Bell [0]. Disenfranchised is right. [0] https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcdn.vox-cdn.com%2Fthumbor%2FrdfoBiH9qvDVtnW9-lwvPOOLN7U%3D%2F0x202%3A2376x1539%2F1600x900%2Fcdn.vox-cdn.com%2Fuploads%2Fchorus_image%2Fimage%2F51495523%2FScreen_20Shot_202016-10-24_20at_202.21.23_20PM.0.png&f=1&nofb=1 https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2F...
- cdmckay 6y agoHasn’t Safari already been doing this for ages with no issues?
- asimpletune 6y agoNo
- jefftk 6y agoI just confirmed that desktop Safari has exactly the behavior this post describes. If I visit any Wikipedia page, what I see in the URL bar is "[lock icon] en.wikipedia.org". The path is entirely removed.
- deleted 6y ago[deleted]
- s_dev 6y agoMy Safari has the full path 13.1.1 (15609.2.9.1.2)
- jefftk 6y agoWeird! I see: https://i.imgur.com/6r73iFt.png https://i.imgur.com/6r73iFt.png (v13.1.2) Is there any chance you've checked "Preferences > Advanced > Show Full Website Address"?
- s_dev 6y agoCan confirm, it is checked. This does seems like something that should be a user configured option.
- pehtis 6y agoIts an option under Safari/Preferences/Advanced called Show Full Website Address.
- 6y ago
- smlckz 6y agoSigh. Now browsers are as powerful as OSes. Why do you need OSes? Address bars? People don't need them. Google should tell you which website you're visiting is good or which is bad if they hide the address bar.
- asimpletune 6y agoI’m not sure why this is being downvoted, this is an accurate albeit sardonic description of what’s happening. People don’t want to visit AMP sites, they want to visit the site that’s the original source for their news, etc...
- daveed 6y agoI mean, depends who you mean by people? I'm pretty happy to go to amp sites. The thing I care about is the content.
- asimpletune 6y agoYeah, well maybe after they have this power, we can leave it to google to fix all the content next ;)
- achn 6y agoThen you've not used many AMP sites - many do not function properly and try to 'stream' the content as you scroll leading to a garbage experience and missing content.
- avasthe 6y agoThey are faster than average webshit. That matters to user, even if the bootcamp webshit and his accountant manager doesn't think so.
- lern_too_spel 6y agoI have never had that experience. Maybe there's something wrong with your browser.
- amiga-workbench 6y agoA nice side effect for them is that it makes it less obvious you are viewing an AMP site.
- khaledh 6y agoIMO this is the real reason why they're pushing hard towards this: However, it's also worth considering that making the web address less important, as this feature does, benefits Google as a company. Google's goal with Accelerated Mobile Pages (AMP) and similar technologies is to keep users on Google-hosted content as much as possible, and Chrome for Android already modifies the address bar on AMP pages to hide that the pages are hosted by Google.
- bitexploder 6y agoWe are going back to AOL days. That didn’t work out so well for AOL in the long run. It’s kind of crazy to me you can’t do marketing now without at least discussing Google and Facebook these days. Edit: at least you knew you were the customer with AOL and paid them with clear terms for access.
- inopinatus 6y agoThe comparison to AOL was my first thought also. Basically, Google have lived long enough to see themselves become the villain.
- magicalist 6y ago> The comparison to AOL was my first thought also It doesn't really make sense, though. The AOL thing was always things like "visit AOL keyword lord of the rings" at the end of trailers, and that would take you to the marketing site. If Chrome wanted to do that, in the example gif the keyword wouldn't be just "en.wikipedia.org" for the URL article, it would be something like "wikipedia URL" that would bring you back to the page you're on through a google search.
- eatmygodetia 6y agoI'd say that it's just as common to hear "google Our Brand" as "www.brand.com" at the end of television adverts now. That's entirely anecdotal, but Google (or other search engines, but basically Google) has been for a long time the way to access sites. I see people every day searching for a brand and clicking rather than appending ".com". It's more convenient. If Google can profit off laziness, they will.
- bambax 6y agoFor now I'm quite happy to have finally switched to Firefox a few months ago. If Firefox disappeared though, as it seems it might, that would be horribly frustrating.
- criley2 6y agoFirefox/Mozilla is largely funded with the search deal which is usually paid by Google. Google has a vested interest in Firefox staying alive for competitive/monopoly reasons, especially now that IE is official a Chrome skin. e.g. https://www.forbes.com/sites/barrycollins/2020/08/13/mozilla-extends-critical-firefox-search-deal-with-google/#5bd73bdb6ea2 https://www.forbes.com/sites/barrycollins/2020/08/13/mozilla...
- distances 6y agoWasn't the last days' layoffs direct consequence of that deal expiring later this year?
- NikolaeVarius 6y agoNobody knows, since we dont know if the deal will renew
- Ndymium 6y agoThe deal has already been renewed: https://www.theregister.com/2020/08/14/mozilla_google_search/ https://www.theregister.com/2020/08/14/mozilla_google_search...
- hu3 6y ago> our source told us Moz will likely pocket $400m to $450m a year between now and 2023 from the arrangement Why in hell did they lay off MDN, Rust/Servo and Dev Tools teams?
- 6y ago
- TedDoesntTalk 6y ago> “Showing the full URL may detract from the parts of the URL that are more important to making a security decision on a webpage," Chromium software engineer Livvie Lin said in a design document earlier this year. I’m a software engineer, too, but I would never make such an important UX decision because I know that is not my area of expertise. I hope they’ve gotten significant user feedback on this before rolling it out. Personally, I hate it.
- eplanit 6y agoIt's Nanny State rationale at best, or cynical condescension -- I hate it, too. I switched from chrome back to firefox a year ago, with no loss of anything.
- solarengineer 6y agoI wonder if Livvie Lin and other Google engineers read such HN threads. What might be their internal discussions, I wonder. How do they justify such design decisions? Are they asked by someone else to figure out how to make such wierd things happen as they just do as ordered?
- avasthe 6y ago"Asked by marketing" or something like that. Fucking suits spoil everything. Engineers are in general, more ethical than suits.
- dessant 6y agoWhen the final version is implemented in a couple of years you will no longer see any URL, that way it won't be as evident that most sites on the web will be loaded from Google. Google is also attacking this issue from a different perspective with Signed Exchanges [1][2], to fake the URL and ensure their success in becoming the gatekeepers of the internet. If you refuse to become a content provider for Google's vision of the web, then they currently won't feature you at the top of search results in the Top Stories carousel, and perhaps demote you entirely from the first page in the future, depending on how their hijacking strategy works out. [1] https://news.ycombinator.com/item?id=19678693 https://news.ycombinator.com/item?id=19678693 [2] https://www.iab.org/wp-content/IAB-uploads/2019/06/mozilla.pdf https://www.iab.org/wp-content/IAB-uploads/2019/06/mozilla.p...
- est31 6y agoYeah the endgame would involve a play-store like 30% cut of any revenue, subscription, ads, anything. 30% cut from non-Google ad network revenue as well. At that point publishers won't have a choice any more because of the Chrome and Google search monopolies.
- dessant 6y agoBy that time it will be warranted to limit user freedom on the web to make security and privacy accessible for everyone, just like Apple does today on their devices. The scary open web and the meaning of a general purpose computing device will be easily forgotten.
- refulgentis 6y agoOff-topic hysterics
- donmcronald 6y agoI think the easier version of that is AMP gets favored and AMP only serves Google ads. I never really thought of that being the endgame, but it makes a lot of sense now that you say it.
- avasthe 6y ago
- simonkafan 6y agoI still haven't found a good answer why they do this. "Makes it harder to tell if the current site is legitimate" sounds like an excuse. If you are the perfect target for a phishing attack (= clicks on everything, enters passwords everywhere, has no clue about host names) then you also won't be able to understand what Chrome presents you in the address bar after obfuscation. My best explanation so far is that the Chrome team doesn't know how to improve their browser anymore so they just make up work to keep the software engineers busy.
- tyingq 6y agoTrying hard not to sound like a conspiracy theorist. However, it's pretty obvious this benefits a walled garden strategy. With things like AMP, "rich snippets", etc, they keep eyeballs on Google owned properties longer. Slowly deprecating urls over time makes it less visually apparent. AOL was able to sell "keywords" this way, because it wasn't always obvious to their users how to get to the real internet.
- Liquix 6y agoIt's not a wacky far-out conspiracy theory to notice that Google is attempting to dominate the internet. It's a serious problem that we need to do something about before it's too late.
- themacguffinman 6y agoIt is, however, a wacky far-out conspiracy theory to claim that Google is developing this feature for the purpose of internet domination. The given purpose is phishing prevention, which is the same reason why this exact feature has been part of Safari for years yet no one pointed out that it was a nefarious attempt by Apple to takeover the web and further their walled garden.
- feanaro 6y ago> It is, however, a wacky far-out conspiracy theory to claim that Google is developing this feature for the purpose of internet domination. No, it's not. Are you aware that Google is mangling AMP URLs to make them look like original URLs and hide the fact that they are hosted by Google?
- gitgud 6y agoWell it does make the host domain clearer which could making phishing attempts harder. But it must be weird when navigating around a website, while the url remains static... ugh creepy
- trishankkarthik 6y agoI was just thinking about this the other day: at the same time, they keep adding weird, inscrutable nonsense at the end of every Google Search URL, so what's the point of hiding the protocols and www and whatnot?
- atoav 6y agoI will from now on consider Chrome as a malware.
- Santosh83 6y agoVote with your choices (use a different browser). That's the only way to address such behaviour. Yes, I know the 95% out there who don't even know what a browser is but only know Chrome's icon gives access to the web won't understand any of this and they will continue giving mega-corporations a critical mass of unquestioning users to be used, but we have no other options. We either express our voices, no matter if they're fringe (and hope it catches on) or we can just give up and not even write these articles any more.
- revnode 6y ago> Vote with your choices (use a different browser). You almost don't even have to. Microsoft's Edge is basically a rebranded Chrome with all of the Google stuff stripped out. You can keep using the same extensions, etc.
- filleduchaos 6y ago> Yes, I know the 95% out there who don't even know what a browser is but only know Chrome's icon gives access to the web won't understand any of this I find it fascinating how some people in tech bubbles think everyone else is a stupid sheep who can't possibly understand such incredibly complex concepts like what a "browser" is.
- avasthe 6y agoDepends. I have seen a lot of people who don't understand such things. And I have seen teachers who think using a different editor to write a program might affect output.
- mkr-hn 6y agoThis expectation probably comes from seeing how even Word->Word can break things. It's reasonable to try and develop a heuristic from that.
- youngNed 6y ago> I have seen teachers who think using a different editor to write a program might affect output. Isn't this fairly common for Notepad for windows though? Weirdness and unexpected output due to ansi encoding rather than utf-8 IIRC - it may be fixed now, but i vaguely remember something about this
- eric4smith 6y agoI’m gonna go out on a limb here and say this might actually be a good thing for people who are looking for domains. But also a great thing for google as they are going to reinforce searching instead of typing in a domain.
- davidmurdoch 6y agoJake Archibald (a Googler) presents some decent points on this on the HTTP 203 podcast: https://youtu.be/0-wB1VY3Nrc https://youtu.be/0-wB1VY3Nrc I still don't agree with the removal of URLs, but I do still recommend watching the entire video if you want to get more perspective on the issue (beyond just the conspiracy theories about AMP and control).
- throwaway6288 6y agoThis is why we should jump over to Firefox. Today! And by us I mean we who know that this is a bad idea. Mozilla is suffering and this is our last chance to not let Google and chrome have total dominance over the web. Mozilla copies Chrome a lot, but they need more market share to be able to get a say here and take the point of us power users. I have been using and contributed to Firefox for years, and it is a great browser! Come on, we know better! Use Firefox or watch Google destroy the open web. It's up to us! Mozilla has flaws, yes, but this is important! That technical users continue to use Chrome is beyond me.
- hu3 6y agoGoogle renewed their deal [1] and Mozilla is still going to get 400-450mil per year until 2023 at least. Yet they gutted firefox servo, devtools and MDN teams. Using Firefox from now on is just feeding the troll called Mozilla management. We need to seek another open source privacy oriented browser or have a serious foundation like Apache fork Firefox. [1] https://www.theregister.com/2020/08/14/mozilla_google_search/ https://www.theregister.com/2020/08/14/mozilla_google_search...
- rbinv 6y agoPushing Google one step closer to becoming Alphabet's AOL. Instagram and friends must be stealing quite some traffic and ad revenue.
- donor20 6y agoWow - top posts are conspiracy theories. "The only reason to do this..." "This is a security issue..." Google has millions / billions of users. From a security standpoint the focus should be entirely on the root domain, that is the only really meaningful root of trust. If you are talking about a security issue - the KEY security issue is ANY lack of clarity around root domain. "Showing the full URL may detract from the parts of the URL that are more important to making a security decision on a webpage." is a statement they have around this change. I think I agree - I suspect other browsers will have to copy chrome (again) in de-emphasizing the leading URL (often used for fishing). Folks seem to miss the fact that google chrome was a minor competitor initially it IE - and their focus on things like ... security ... helped them become absolutely dominant. A fair number of enterprises have (finally) started slow slow switch to mandating chrome.
- trekrich 6y agoat what point is not any longer? Once the URL bar has gone?!
- MaxBarraclough 6y ago> their focus on things like ... security ... helped them become absolutely dominant I don't think Chrome's security features had anything to do with its ascension. Chrome took off because it was fast and had a good UI (iirc it had the ability to drag a tab from one window to another, a while before other browsers did). The average user knows nothing of the security features of their browser.
- chillfox 6y agoAlso you couldn’t use google search in a different browser without constantly getting harassed to install chrome
- acheron 6y agoChrome took off because Google leveraged their position in another area (search engine) in order to push it. Exactly what people were concerned about with Microsoft and Windows/IE.
- magicalist 6y agoThe Chromium blog post (which points out that like Safari on the Mac there's a setting now (not just a flag) to disable it): https://blog.chromium.org/2020/08/helping-people-spot-spoofs-url.html https://blog.chromium.org/2020/08/helping-people-spot-spoofs...
- p1mrx 6y ago"Always show full URLs" is such a breath of fresh air. It eliminates all the URL butchering (e.g. inconsistent hiding of http/https) that Chrome had been doing for more than a decade. Though I'm not seeing the option by default on a fresh install of Chrome 86; hopefully that's just a rollout glitch.
- RonanTheGrey 6y agoWhat would be even more honest is that when people first install that version, they're asked what they want that setting to be. It would be interesting to see the results.
- thrownaway954 6y agoso... is this a chromium thing or a chrome thing? if it is just exclusive to chrome, then maybe it's time to finally give the new microsoft edge a try.
- Wowfunhappy 6y agoThe official build of Chromium tracks Google Chrome quite closely, so I feel confident assuming that the change is there as well, even though I haven't checked. But since Chromium is open source, I'm not sure anyone can really answer that question. Whether the change is in Microsoft Edge depends on how far Microsoft is willing to diverge from mainline (and where specifically they want to spend their resources).
- alexmingoia 6y agoThis is how Safari for iOS (and desktop?) has worked for a long time... the domain is shown unless the URL field is selected. I like it.
- monadic2 6y agoThey're just BEGGING for an anti-trust suit.
- non-entity 6y agoThe URL hiding thing is what finally pushed me to use Firefox full time last year.
- crazypython 6y agoOne of my favorite macOS/iOS features is URLs. Most good native apps-- Things, Drafts, DEVONThink, etc.-- support URLs. URLs such as `things://` and `drafts://`. Some accept POST as well as GET. There's even a specification of an iOS/macOS protocol very reminiscent of webhooks. http://x-callback-url.com/ http://x-callback-url.com/
- scott_s 6y agoSomething I haven't seen anyone here bring up yet: many URLs are meaningless to humans past the domain. For an example, look at the top of this page. The only semantic meaning in the URL for this post is `news.ycombinator.com`. The rest, `item?id=24156986`, is meaningless to a human. (But, of course, meaningful to HN's backend.) A lot of (most?) of the URLs on the web are not semantic. They're naked application look-ups. I claim that for this current page, there's no meaningful loss of information by just showing the domain. But some URLs are semantic. I think losing those would lose useful information for human readers. If we could perfectly know which URLs have useful semantic information for users and which don't, and then only present those with full semantic meaning, I wouldn't mind much. Main point: I see people saying things like "these designers think people are too stupid to understand URLS." But that ignores that some URLs are not actually meaningful to anyone. Anticipated responses: 1. You are losing information by taking off the "application lookup" part: the information that an application lookup was made. Fair enough. But I claim it's a small loss. 2. We can never perfectly separate out the URLs with useful semantic information. Which, also probably true. But I think we can do a decent job, and as long as the full URL is present when I mouse-over it, I probably wouldn't object.
- ArmandGrillet 6y ago"many URLs are meaningless": many, but not important ones such as URLs from Reddit and GitHub.
- scott_s 6y agoExcellent point. But the information I want before going to a URL is different from the information I want while there. But if we could reliably separate the two, I don't think I would object to this kind of a UI change in principle.
- Mathnerd314 6y agoThe 24156986 is semantic though; the ids are assigned sequentially to submissions. Early submissions have tiny ids like 495. So they are at least as meaningful as bug tracker ID's or version numbers. Now, it is true that version numbers etc. could be more meaningful. Jeff Atwood wrote an old article about the "infinite version" in Chrome, where the version number basically doesn't matter until you're checking to see if you're up-to-date. Personally I've switched to using dates / times in my ID's. HN could do that too; an ID like 2020-08-14-10-12-13-99 is longer than the current ID's but not by much. But overall it seems hard to draw a line in the sand where dates are semantic and version numbers aren't.
- polote 6y agoThe title is misleading and people don't read the article. Chrome is not hiding the bar address, it is only showing the domain in normal times, and showing the full url when you hover the bar Personally I find it better for non technical people, because they can focus on the domain only. For tech people you have the option to keep the full url visible at all time, which fixes the issue. As for people complaining about AMP, this is something different, which has nothing to do with displaying only the domain, but instead "showing the real domain when you are on a google AMP page"
- lowlevel 6y agoSounds about right... I am still cheesed that they're treating the address bar like where you search. For me, if the address bar does happen to go away, so does chrome.
- xemdetia 6y ago> Personally I find it better for non technical people, because they can focus on the domain only. For tech people you have the option to keep the full url visible at all time, which fixes the issue. I think a large part of my repulsion to this change is mostly because Chrome has a history of removing options constantly. A weird default with a setting to get to more expected behaviour is fine, but I have no faith in them to not remove the full url visible at all time option at this point.
- abrowne 6y agoI already have the "Always show full URLs", so you know what I prefer, but isn't this the same or similar to Safari's default behavior for a while? I don't hear anyone still complaining about that.
- sschueller 6y agoSorry but if you can't teach non technical users new things they shouldn't be 100 meters near a computer. It will result in even more technical dept and people with over confidence thinking that they know what they are doing. We don't need to idiot proof the world. We need to educate the idiots.
- stunt 6y agoI prefer what Firefox. Just keep the domain name black/highlighted and the rest of URL gray. But, for average user this might be more effective to detect phishing attacks since they never check full URL anyway. (Unless when a website does something stupid with query string parameters)
- 0xUser 6y agoIf you like chromium ecosystem, I suggest trying the Vivaldi browser. https://vivaldi.com https://vivaldi.com It won me over with (1) the ability to split the window into multiple tabs (2) ability to turn any webpage into a side-bar "applet-thingy" -- great for having whatsapp, todoist, always on the side while you switch tabs. It also has plenty of other features aimed at power-users.
- _underfl0w_ 6y agoCan confirm. Vivaldi is absolutely fantastic for the reasons you named, plus its ability to use all common Chrome extensions such as uBlock Origin, uMatrix, Dark Reader, etc.
- DSingularity 6y agoHow do google engineers stand for this shit?
- crawsome 6y agoThis is why I use and support Firefox. It's so sad to see Mozilla doing so badly right now when Google gets away with Evil.
- crazygringo 6y agoRemember folks, Apple has been doing this in Safari since 2014. And there's been zero uproar over it at all. I don't understand why people suddenly hate this just because it's Google. For most users, total focus on the domain name is a security feature. For 99% of users, what comes after the domain name might as well be gibberish. I mean, it is a majority of the time.
- EarthLaunch 6y agoGoogle has been doing this since 2010 [0]. Weird strawman. 0: https://bugs.chromium.org/p/chromium/issues/detail?id=41467 https://bugs.chromium.org/p/chromium/issues/detail?id=41467
- thethethethe 6y agoThat’s only hiding the protocol part of the URL. Parent is referring hiding everything but the domain, which the article in question is about. Weird strawman.
- EarthLaunch 6y agoFair enough, thanks for the correction.
- GrinningFool 6y agoThe first time I used Safari and didn't see a full URL was the last time I used Safari. I didn't raise a fuss or take to twitter, I just stopped using it. I'm probably not alone. In addition, Safari has a very small slice of browser usage in the overall scheme of things. I suspect the uproar would be just as vocal if their usage numbers were in the range of Chrome's.
- kcb 6y agoSame here. Recently I though I'd try out Safari again. Started browsing reddit and kept forgetting what subreddit I was on. It was then I noticed something was wrong.
- Wolfenstein98k 6y agoWhat are they gaining from this that possesses then to fight such consistent opposition? I don't see anyone stumping for this or any groups making any arguments for it beyond aesthetics, which is nice but surely doesn't outweigh all the vociferous opposition. What gives? Cui bono?
- mroche 6y agoHaving looked at the intended design implementation, I'm not _super_ against this change, but I'm not fully onboard. And the concept of AMP here isn't lost on me, either. I understand the stated goal of this is for simplicity for users and enhancing generic security. I feel Firefox already does this better. Let's take the following URL for example: https://code.visualstudio.com/docs/ https://code.visualstudio.com/docs/ On my work MBP with FF 79 and GC 81, this is what I see ([] signifies contrasted text color): Firefox: https://code.[visualstudio.com]/docs/ https://code.[visualstudio.com]/docs/ Chrome: [code.visualstudio.com]/docs/ Chrome (after clicking twice in the address bar: https://[code.visualstudio.com]/docs/ https://[code.visualstudio.com]/docs/ Chrome 86 (uses above formatting on hover): code.visualstudio.com In both apps, the dark themes provide more contrast that the light ones. I don't think we need to hide URL's from users, because what really matters is the very beginning of the URL which is always shown, and noting the root domain in a more contrasted, apparent way (like Firefox does) is to me a better solution to this problem. Spending time to improve the appearance of the important part of the URL will help everyone in the end, rather than taking the easy road of just isolating it. Time would be better spent on solving horrible looking URLs in the first place and how URLs get represented in sharing (e.g. email clients, SMS, etc), which is where arguable most visual URL security concerns take place. If anything, I think I'm less likely to trust a URL like this (a simple Google search for "example url") when taking a glance in an email (removed https so full URL would show): "://www.google.com/search?source=hp&ei=IJ82X6DoINCJytMP75Cn6As&q=example+url&oq=example+url&gs_lcp=CgZwc3ktYWIQAzICCAAyAggAMgIIADICCAAyAggAMgIIADICCAAyAggAMgIIADICCAA6CAgAELEDEIMBOgUIABCxAzoCCC46CwguELEDEMcBEKMCOgUILhCxAzoECAAQCjoLCC4QsQMQxwEQrwE6CggAELEDEEYQ-QFQkDJYxEdg3khoAnAAeAGAAbsBiAHBBpIBBDEyLjGYAQCgAQGqAQdnd3Mtd2l6&sclient=psy-ab&ved=0ahUKEwig-Nis85rrAhXQhHIEHW_ICb0Q4dUDCAg&uact=5" than "://www.google.com/search?query=example+url" If on mobile, go into landscape for the larger URL, unless there’s a better way to format it I’m not aware of. Didn’t think a code block was best for a massive oneliner. A possible middle ground could be taking a look at limiting token visibility. But a larger discussion would be needed for that as well.
- treebornfrog 6y agoThis is exactly why I forced myself to switch to FF quantum around 2 years ago. Chrome is going downhill.
- DodgyEggplant 6y agoMozilla move to cut so many people involved in an alt browser doesn't help
- avodonosov 6y agoEven today's protocol hiding is so inconvenient, who is making these decisions, do the use computers regularly?
- kmeisthax 6y agoThe average user sees http://123.45.67.89/~sk/microsoft.com/techsupport http://123.45.67.89/~sk/microsoft.com/techsupport as a legitimate Microsoft website. That's what this change is intended to fix: users that see a domain in any part of the URL as being valid. They want to change it to only show the part that's actually security relevant. If you tell the average user "Look for Microsoft in the URL", and they find it in the path, they're going to fall for a phishing scam.
- RonanTheGrey 6y agoHIDING the URL doesn't seem to be the most obvious solution to this, to me.
- p1mrx 6y agoProtocol hiding was recently fixed, via the "Always show full URLs" option. The default is still an inconsistent mess, but checking this option makes the URL bar so much better than it's been in years.
- deleted 6y ago[deleted]
- jasonjayr 6y agoThere are a lot of comments about hiding the URL "because the user doesn't understand" -- has there been any research into user education directly in the address bar? Like, fresh install page points @ google.com. Why not A little browser popup highlighting the parts of the URL and explaining it, with a link + tutorial on how to understand parts of the URL? Rather than dumbing the interface down, why not inform users so they can use these platforms more effectively?
- brianzelip 6y agoStop using chrome. Use Firefox, https://www.mozilla.org/en-US/firefox/developer/ https://www.mozilla.org/en-US/firefox/developer/.
- swader999 6y agoThis is about censorship and control. Just type in what you want and we'll get what's best for you.
- exabrial 6y agoDon't cry when anti-trust nukes come Google.
- known 6y agoFirst url shortner (goo.gl) now this;
- butz 6y agoAnd that's why we need more competing browsers, not built from chromium source.
- jungletime 6y agoThis is the same company that will selectively censor leaked information, as election interference. https://techxplore.com/news/2020-08-facebook-google-election-efforts.html https://techxplore.com/news/2020-08-facebook-google-election... At this rate, China will be a more free country.
- curiousllama 6y agoI wonder to what degree Google becoming increasingly a Walled Garden provides an opportunity for a new type of search engine. Instead of having to grapple with the breadth of services on the Internet, it grapples with the depth of each Walled Garden - Apple, Google, WeChat, etc. I simply can't imagine that any one platform, however large, can truly grapple with the full range of use cases for the consumer internet.
- ComputerGuru 6y agoAll of a sudden, I’m cheering for Microsoft’s decision to make Edgium available for Linux.
- ehutch79 6y agoThis has nothing to do with amp, and everything to do with users thinking http://printer001.cpalawyer.bz/mircosoftoneline.acutallogindomain.here/ http://printer001.cpalawyer.bz/mircosoftoneline.acutallogind... is a legit office 365 login page. Not that they're going to notice that the url bar says something random anyways.
- clairity 6y agogoogle is not attacking the url bar, it's attacking dns, just like aol and verisign (and others) before it. google wants to replace the decentralized dns system with a centralized google lookup service, powered by their principle competitive advantage, search. google wants to control the internet itself. they're banking on the idea that the average user wants to type (or speak) "macdonalds" and end up engaging with mcdonald's in some form. google wants to be the gatekeepers of the whole internet, not just the browser. the browser is small peanuts in comparison. the simple narrative of this title/story is the kind of distraction we need to see right through with large organizations everywhere, whether it be a corporation, a government, or anything else. we the people must keep these entities in check so that they serve the greater good for all of us, not just the narrow and corrupt.
- thepete2 6y agowe're getting there [0] [0] https://xkcd.com/2105/ https://xkcd.com/2105/
- wwwwwwwww 6y agoSwitched to Vivaldi. One click, and Vivaldi shows the entire URL, as it should be, including scheme and everything. (Vivaldi browser was founded by employees of Opera, when Opera was sold to a Chinese company. Vivaldi is owned entirely by it's employees)
- staticassertion 6y agoI don't believe this is an attack. It hides the full address, but you can hover over it to see the whole thing, or even enable full addresses easily. I believe this is legitimately done to improve UX for users who may be phished. Tying this to AMP is a mistake.
- RonanTheGrey 6y ago"Won't somebody please think of the children?!"
- staticassertion 6y agoThis is a really weak response. The post announcing the feature makes an extremely strong case for why this is a good thing.
- makecheck 6y agoI’ve wondered why we continue to display URLs as painfully-long single lines of text. Tradition? Why is this helpful anymore? (e.g. On an iPhone it’s not easy to edit the end of a URL.) If it’s so damn hard to display full URLs on one line, let’s display them on several lines (at least after tapping on them), broken on dots to wrap. Spaces aren’t valid in URLs anyway.
- deleted 6y ago[deleted]
- ramosu 6y agoMy life is much better with Firefox. I don't miss Chrome at all.
- unixhero 6y agoFuck. That means it ends my love affair with Chrome. I had such high hopes for us.
- kats 6y agoThey're just trying to prevent phishing. Remember when the DNC was hacked? Employees at the DNC were linked to sites that looked exactly like the Google sign-in page, except that the URL was "myaccount.google.com-securitysettingpage.tk". picture of the phishing website: https://security.stackexchange.com/questions/189688/does-google-check-for-unicode-characters-to-determine-spam-now-in-gmail https://security.stackexchange.com/questions/189688/does-goo... From interviews, it seems like there's two features Chrome developers are working on try to prevent these kinds of attacks. One is to hide the subdomain so that people can't make such tricky looking URLs. Another is feature to identify lookalike URLs and let users know about the anomaly. sources: https://www.nytimes.com/interactive/2017/01/06/us/russian-hack-evidence.html https://www.nytimes.com/interactive/2017/01/06/us/russian-ha... https://p3isys.com/p3isys-tech-blog/153-podestahack https://p3isys.com/p3isys-tech-blog/153-podestahack https://www.wired.com/story/google-chrome-kill-url-first-steps/ https://www.wired.com/story/google-chrome-kill-url-first-ste...
- _ink_ 6y agoHow exactly does it help to prevent fishing from domains like my-google-account.tk?
- kats 6y agoIf they hide the subdomain, then if users see google.com at the start of the URL it will actually be google.com. Tricky URLs like "myaccount.google.com-securitysettingpage.tk" would get displayed as "com-securitysettingpage.tk" instead.
- jkrems 6y ago(Disclaimer: Work at Google but not affiliated with our security team or with Chrome.) Those URLs have to actually contain the name of the brand in the thing that is being registered with the domain registrar. Which is a _lot_ easier to find and proactively shut down than things in subdomains which may only be visible once a specific URL gets resolved (wildcards etc.).
- benatkin 6y agoIt's a problematic change, but is actually more usable. Now as a developer, I don't have to worry about changing the URL too much, in order to enable deep linking and the back button. I also don't have to worry about the unsightly but useful query parameters on a search page. This should become the new standard. It's not like the mailboxes that the USPS is removing, ostensibly in response to declining mail volume. The mail boxes weren't in the way. They were built according to the city codes. Removing them before an election is all downside, and no upside. The path and query params in the URL are in the way. If you're making a page that's a list of data that gets filtered, each time you change one of the filters, and call replaceState when it changes, it would change the URL bar. That's visual noise. I used to be against this, because I'm against Google's overall agenda with the web. I thought about it and couldn't deny the usefulness of being consistent across mobile and desktop, and letting the URL change as frequently as is useful from the developer perspective.
- RonanTheGrey 6y ago> I don't have to worry about changing the URL too much, in order to enable deep linking and the back button. I also don't have to worry about the unsightly but useful query parameters on a search page. This should become the new standard. I've been a web developer for both small and large companies for over 20 years and can assure you I have never worried about such things. This is a false flag.
- benatkin 6y agoCurrently I'm on https://news.ycombinator.com/reply?id=24161699&goto=item%3Fp%3D2%26id%3D24156986%2324161699 https://news.ycombinator.com/reply?id=24161699&goto=item%3Fp... Is that optimal? Safari hides it on desktop now. Like I said I didn't want to admit it at first, but it's better. It would certainly be noticeable on mobile if they word wrapped the entire URL so you could see it.
- laichzeit0 6y agoStop using Google products. They are evil. Switch to duckduckgo and Firefox or Brave and block all ads. Fuck these guys.
- shadowgovt 6y agoThis seems like a problem that is easily solved by ceasing to use Chrome. How does the URL bar look in Firefox these days?
- pkamb 6y agoThe example url in the article is: > https://en.wikipedia.org/wiki/URL#Internationalized_URL https://en.wikipedia.org/wiki/URL#Internationalized_URL which is shortened in the address bar to: > en.wikipedia.org at the VERY least, I wish they would instead use: > en.wikipedia.org/wiki/URL Same for Twitter and Reddit URLs, specifically. Don't hide the username or the subreddit.
- RonanTheGrey 6y agoThose are two examples where the URL is canonical and shouldn't be shortened. There are probably many, many more. Very often the only place you can find the date of a news story is in the URL due to them using some version of Wordpress but not putting the date in the article past a certain age (F YOU, Guardian). Google has clearly thought this through and decided that whatever they're getting out of this is FAR MORE IMPORTANT than the best interests of their users. And that should make everyone suspicious.
- pkamb 6y agoThey should fix this bug first: > Issue 1084406: Reappearance of "HTTPS://" causes URL text to move as you are selecting it > https://bugs.chromium.org/p/chromium/issues/detail?id=1084406 https://bugs.chromium.org/p/chromium/issues/detail?id=108440...
- p1mrx 6y agoThe new "Always show full URLs" option fixes that, because http/https is always visible.
- causality0 6y agoI'm not going to use a browser that lies to me about what web page I'm on.
- iamleppert 6y agoIf URLs get hidden in such a way, developers are going to stop caring about them. This is going to result in experiences like we get with apps like Facebook, which doesn’t have any conceivable way to get back to certain content. Think single page apps that never have any URL changes. Of course the brass at Google is incredibly short sighted and clumsy in their approach. All the good people at Google are gone and we’re left with the dredges and it’s starting to show.
- sheinsheish 6y agoDon’t use it :)
- anm89 6y agoCouldn't be happier that I switched to firefox about a year ago.
- iamaziz 6y agoGreat news! Can’t wait to use, Ive been trying to hide the whole address bar altogether for so long
- wodenokoto 6y agoIs this different than safari?
- dang 6y agoThis article had a major thread two months ago: https://news.ycombinator.com/item?id=23516088 https://news.ycombinator.com/item?id=23516088. It has been updated, apparently to mention an animation technique in the URL bar of Chrome 86, but that's apparently not SNI (https://hn.algolia.com/?query=%22significant%20new%20information%22%20by%3Adang&dateRange=all&page=0&prefix=false&sort=byDate&type=comment https://hn.algolia.com/?query=%22significant%20new%20informa...) since the discussion here isn't mentioning it. So I think we have to call this on the dupe side. See also https://hn.algolia.com/?query=follow-up%20by%3Adang&dateRange=all&page=0&prefix=true&sort=byDate&type=comment https://hn.algolia.com/?query=follow-up%20by%3Adang&dateRang... for how we moderate these.
- cryptonector 6y agoPlease please stop this, Google.
- rchaud 6y agoURLs are supposed to be human-readable because they're intended to signal to users what the content is about. What is not human-readable, although fully semantic, is all the parameter trash that comes after full URL. Stuff like "utm_source='twitter'&utm_medium='social_share" or cookie information and the like. I can understand trimming that information, but hiding the URL to show the domain only makes no sense.
- binarray 6y agoIf the domains were written from left to right / highest to lower level (example: com.ycombinator.news/... or com/ycombinator/news/...), this (particular) phishing problem would go away and there would be no reason to do this. Out of ignorance, any proposals were made to change the order of (writing) domains levels? Or to create an alternative one (if that is even possible)?
- apricot 6y agoThis reminds me of that time when Microsoft started hiding file name extensions from the user, because reasons.
- baby 6y agoOmg. I believe safari does that and I freaking hate it. I see how it makes every website act like an app, but these have real user values: you wouldn’t design a folder explorer by hiding where you are in the tree. Oh wait, actually that’s what macOS does already... On the other hand, this is the default behavior on mobile browsers and it doesn’t seem to disturb anyone.
- JulianVModesto 6y agolol “attack,” your mobile browser already does this
- newbalance 6y agoFeel like this is similar to a future self-driving Google car depositing me at my destination, but without telling me the address itself. We're here. For me personally, this makes it official, I need to keep my guard up at all times when using anything Google.
- bobbydreamer 6y agoNaaa. They are making up space for ads and chrome extensions. URLs are important, to the difference between a home page and other pages or will never know if you are redirected.
- rixtox 6y agoHiding the full URL will redirect a lot of traffics back to Google's search engine because people can't easily figure out the source from a screenshot anymore.
- Gibbon1 6y agoIf google can get enough people to stop using url's then they can start building a walled garden.
- dkdk8283 6y agoI often modify URLs when sharing with friends - stripping utm and other parameters especially when sharing amazon links My search terms are not relevant to sharing a product ASIN It seems that Google may view the web browser as an engine that is trying to reinvent native desktop apps. What’s old is new again just with some fancy words and a new generation
- ariyadi 6y agoApple has been doing it for a long time