5 ms·
I still haven't found a good answer why they do this. "Makes it harder to tell if the current site is legitimate" sounds like an excuse. If you are the perfect
by simonkafan 6y ago
I still haven't found a good answer why they do this. "Makes it harder to tell if the current site is legitimate" sounds like an excuse. If you are the perfect target for a phishing attack (= clicks on everything, enters passwords everywhere, has no clue about host names) then you also won't be able to understand what Chrome presents you in the address bar after obfuscation.
My best explanation so far is that the Chrome team doesn't know how to improve their browser anymore so they just make up work to keep the software engineers busy.
- tyingq 6y agoTrying hard not to sound like a conspiracy theorist. However, it's pretty obvious this benefits a walled garden strategy. With things like AMP, "rich snippets", etc, they keep eyeballs on Google owned properties longer. Slowly deprecating urls over time makes it less visually apparent. AOL was able to sell "keywords" this way, because it wasn't always obvious to their users how to get to the real internet.
- Liquix 6y agoIt's not a wacky far-out conspiracy theory to notice that Google is attempting to dominate the internet. It's a serious problem that we need to do something about before it's too late.
- themacguffinman 6y agoIt is, however, a wacky far-out conspiracy theory to claim that Google is developing this feature for the purpose of internet domination. The given purpose is phishing prevention, which is the same reason why this exact feature has been part of Safari for years yet no one pointed out that it was a nefarious attempt by Apple to takeover the web and further their walled garden.
- feanaro 6y ago> It is, however, a wacky far-out conspiracy theory to claim that Google is developing this feature for the purpose of internet domination. No, it's not. Are you aware that Google is mangling AMP URLs to make them look like original URLs and hide the fact that they are hosted by Google?
- themacguffinman 6y agoWhich has nothing to do with the feature discussed in this thread, which is to hide non-domain parts of the URL. What you're referring to is the Signed Exchanges proposal.
- tyingq 6y agoSplitting up your plan into discrete parts that seem relatively inert on their own isn't a new thing. ANFO is a good example. And it's pretty easy to do this in a way that front line and low level MGMT Googlers wouldn't know. The AMP lead, for example, has posted here, and seems credible and very competent for his own intentions. I'm not convinced he's totally aware of the intentions of his leadership chain.
- themacguffinman 6y agoYou're literally describing a conspiracy theory and dubiously speculating on malicious intentions. That's my point. I'm saying that it's a wacky conspiracy theory that Google is hiding the non-domain parts of the URL to dominate the internet, and you come back with: What if Google leadership was conspiring in such a secret, surreptitious way that middle management and possibly even the AMP lead doesn't know what's going on? What if this is just a small part of some grand plan?! Is the treachery of domain-only URLs so deep that even Apple didn't realize they were carrying out pieces of Google's ultimate plan?
- tyingq 6y agoFair enough, yes, that's a bit sensationalized version of what I said. And, despite being a generally rational person, I don't find it far fetched.
- SifJar 6y agoI think the justification is that some people will think the website is legitimate if a legit hostname appears anywhere in the URL e.g. http://scamsite.com/microsoft.com/phish http://scamsite.com/microsoft.com/phish "looks" legit because it contains the string "microsoft.com" (and most "regular" users won't appreciate the different parts of a URL); under the new scheme, that would display only as "scamsite.com" and hopefully people are less likely to enter their microsoft username/password if "microsoft.com" doesn't appear anywhere in the address bar. I'm not overly convinced of this personally, but I think that's the supposed idea behind it.
- oneeyedpigeon 6y agoI think microsoft.scamsite.com would fool most of the people that scamsite.com/microsoft would. It's a very difficult problem. Can't we have something like certificates for domains, so we can at least trust the most potentially vulnerable cases?
- judge2020 6y agoIf EV certificates were good they'd be great for showing alongside the URL, but they're both expensive for most (used to be $100/yr if you go for the cheapest vendor, now heavily discounted since the URL bar change made it lose value) and the legal entity verification doesn't work in a sense that company names aren't unique[0]. 0: https://news.ycombinator.com/item?id=15904513 https://news.ycombinator.com/item?id=15904513
- tialaramex 6y agoThey (EV certificates) also don't do as much as you probably think they do. Or, I suppose, seen from a different angle, the actual dnsName matching does a lot more than you realise. When you visit news.ycombinator.com obviously the browser confirms that the certificate presented is for news.ycombinator.com and not anything else. Because the machine does dnsName matches and machines are fast, it happens prior to every single transaction as necessary. In contrast EV information like company name can only be checked by a human, slowly, after a transaction already completed. Suppose I hit this "reply" button to post this, but bad guys have just at that moment intercepted my network connection. The browser connects to news.ycombinator.com and... their certificate either isn't trustworthy or isn't for news.ycombinator.com and so this text is never sent to the bad guys at all. But EV certificate details are only useful retrospectively. The browser can tell me after the fact that it posted the response to "Phishing Corp. Ha Ha Ha We've Got Your Data Now" but it doesn't actually know that's the wrong place so it won't abort the transaction. For this and other reasons the entire EV design doesn't really "work" from a security point of view, and wasn't ever really intended to. It's a marketing idea, not a security idea.
- texasbigdata 6y agoFrom an advertising perspective if the cost to serve amp is less than ad revenue, this makes perfect sense. Every click on google goes to google, and you’ll like it too bc you won’t have a choice.
- untog 6y ago> “Makes it harder to tell if the current site is legitimate" sounds like an excuse. Why? To me, having helped elderly relatives with computers a lot, it is very plausible. Phishing URLs use all sorts of subdomain and querystring tricks to fool users, and it can work.
- neop1x 6y agoAs someone noted, not only that. But you won't see on which subreddit you are at for example. That's quite annoying.