18 ms·
Chrome abandons 'simplified domain experiment' in omnibar
- Saris 5y agoIt's such a weird thing to change in the first place, who benefits from it?? Lots of negatives and not really any positives I can think of.
- judge2020 5y agoIt seems that they were combating phishing sites. A comment from the field trial's code: // Hostnames using sensitive keywords (typically, brandnames) are often social // engineering, and thus should only show the registrable domain.
- bentcorner 5y agoI suppose this implies that the average non-technical user pays no attention to the contents of the address bar? Perhaps for Google to improve security metrics maybe the user needs a new canonical UI element indicating what site they're on, since to most people the address bar is just computer noise.
- whoknowswhat11 5y agoIf you support a larger / older user base you'd understand immediately what they are trying to deal with. microsoft.scamsite.com amazon.scamsite.com would turn into scamsite.com that said users click on stuff pretty easily so not surprised it didn't move metrics that much.
- duskwuff 5y agoOr, worse, "amazon.com.contact-support.something-else-to-confuse-the-user.shadytld". Even with the path part of URLs dimmed, users are really bad at identifying the authoritative part of a hostname.
- whoknowswhat11 5y agoNo question - outlook users struggle here particularly especially if bit behind a Google class filter for email etc (legacy email)
- slver 5y agoUsers are bad at it because English is ordered left to right. The path also is. The domain is right to left. It was designed by morons.
- sixothree 5y agoSounds to me like they see their users as idiots.
- userbinator 5y agoThey are sheep to be gently herded and monetised. Google's primary business is advertising. Regardless of what propaganda it spreads, the ultimate motivation of making a browser is to make more money for itself. Almost all the changes that it has done make perfect sense in that context.
- 1stranger 5y agoWhy did everybody lose their minds over this? It seems Safari does this without much drama.
- websitejanitor 5y agoI like to know which page I'm on
- slver 5y agoThe current one
- spicybright 5y agoThe next change Google will try is replacing the URL with just "The current one".
- slver 5y agoThat’s basically what this experiment was. Show the origin only. The current page is obvious from the page itself.
- meibo 5y agoI was wondering about exactly the same thing, had to use Safari for work recently and not seeing the URL was extremely confusing.
- hashkb 5y agoYes, as someone who only occasionally uses a Mac, I always think Safari is broken until I remember Apple tries to hide everything from you for your own good.
- craftinator 5y agoIf you can't do anything, you also can't do anything bad!
- dataflow 5y agoWhat do they mean by "we're not going to launch it"? Doesn't Chrome already hide the URL scheme and www subdomain?
- judge2020 5y agoThis is the commit: https://chromium.googlesource.com/chromium/src/+/180e57971e7cabc0a15c76112f8d37a942bc8d61 https://chromium.googlesource.com/chromium/src/+/180e57971e7... // Called by omnibox code (when enabled) to check whether |url| should be elided // to show just the eTLD+1 due to failing any number of heuristics. The heuristics: https://chromium.googlesource.com/chromium/src/+/322283e5085b12fa9ad7feab857b167c44b72549/chrome/browser/reputation/url_elision_policy.cc#18 https://chromium.googlesource.com/chromium/src/+/322283e5085...
- klodolph 5y agohttps://www.androidpolice.com/2020/06/15/google-confirms-experiment-to-remove-full-address-from-url-bar-in-chrome-details-opt-out-mechanism/ https://www.androidpolice.com/2020/06/15/google-confirms-exp... It was only showing the domain.
- jackson1442 5y agoThis would have removed the path from the omnibox until the user hovers, much like mobile browsers or Safari.
- habibur 5y agoSimplified domain was supposed to hide the path too. Display only the domain name so that the user can focus there only which really mattered.
- unclekev 5y ago> This experiment didn't move relevant security metrics, so we're not going to launch it. :( Interesting, I wonder what exact 'security metric' they were measuring this against to determine if this feature would make the cut.
- jimbojet 5y agoIf I were to guess, conversion rate on phishing sites
- advisedwang 5y agoFrom the bug: > we'll have study participants exploring the prototype in lab/survey studies, and we will also roll it out to a small % of real Chrome users to understand if it helps protect them from phishing. If the results show that this simplified domain display does help protect users from attacks, then we'll make a decision about whether to ship it to all users, balancing user feedback with the security considerations.
- Yizahi 5y agoProbably financial security of C-suite :)
- asquabventured 5y agoAnyone what the "security metrics" they referenced in the commit message were that they thought would be impacted by making this unrequested change to how the web works?
- jimbojet 5y agoProbably conversion rate on phishing sites
- armchairhacker 5y ago"simplified domain" = address bar only shows domain name. e.g. "https://www.ghacks.net/2020/06/15/google-to-test-simplified-domain-display-in-chrome/ https://www.ghacks.net/2020/06/15/google-to-test-simplified-..." -> "ghacks.net" > The reason for running the experiment, according to a developer, is that the display of the full URL makes it difficult for the average user to distinguish between legitimate and malicious sites. From https://www.ghacks.net/2020/06/15/google-to-test-simplified-domain-display-in-chrome/ https://www.ghacks.net/2020/06/15/google-to-test-simplified-...
- cookiengineer 5y agoNot only that. On mobile, it meant that AMP delivered pages by google's domain were stripped out in a way that the publisher's domain was displayed, effectively MITMing the website from a user's point of view. Maybe the next iteration of it will use SSL certificate hijacking, who knows? I mean, this feature can be argued with from both sides: protection against scam and "UX MITM". What I don't understand is why a web browser doesn't already include scam websites into their malware/badware reporting feature. It could have been so much easier. In Germany we have a very restrictive law when it comes to imprints on websites, which makes it easy to spot scamming websites if you care to look for the legibility of the imprint (and required tax law identification numbers). Of course that doesn't apply for international law, but initially I didn't understand the importance of it...meanwhile I do.
- Case81 5y ago“UX MITM” is the funniest thing I’ve heard all week
- cookiengineer 5y agoI don't even know how to call this to be honest. I mean, it's not scam, it's not MITM, it's not fraud but it's still trying to deceive users...so what is it? The only parallel that comes to mind are all the "helpful" clickjacking toolbars in Internet Explorer that tried to push every search and every link to their own results page.
- imjustsaying 5y agoAlways wondered when this, removing the path after the domain, would be put in. It's visually simpler and would probably improve the metrics recording perceived sleekness of user experience. But removing the path would be a burden to those discovering how the web really works.
- sixothree 5y agoWhy not just take out the address bar altogether.
- staticassertion 5y agoOh well, was worth a shot.
- turminal 5y agoI'm all for making phishing less effective, but this was just bad UX.
- rusk 5y agoAh sense prevails for once
- amanzi 5y agoAt least Chrome let you right click the URL field and choose to view full URLs. Firefox has also started messing with the way URLs are displayed and you have to trawl through the about:config settings to stop the insanity.
- unclekev 5y agoJust right clicked a URL in chrome and saw the "Always show full URLs" option. Mind blown! Never noticed that there. Amazing! Thanks for the tip. I would have guessed the situation would be the opposite, easy to set in FireFox, obscured/hidden in Chrome. But apparently not! :)
- abstractbarista 5y agoThis is fantastic, how did I not know about this before!
- Forge36 5y agoJust learned this too! I never use the mouse to type in the URL bar. Ctrl+L :)
- squaresmile 5y ago> Never noticed that there I'm quite sure this option wasn't there when this "experiment" was added.
- tbodt 5y agoIt was, they added the right click option shortly before starting the experiment.
- developer2 5y agoI remember finding this setting before, for myself and at least half a dozen other people in my life. Not seeing the full URL is something that Mozilla should have fucking understood was something their users want. Firefox is supposed to be the "Good Browser™", which includes technical users configuring the browser for other people in their lives. Every single goddamn time Firefox tries to bring themselves to being the bottom of the barrel, where "naive users need apply", they alienate their user base and all the other people associated to those users. I know that trying to grab market share seems like an "appease more people in the population", but Mozilla repeatedly seems to forget how much we are evangelical for those who don't even know that Firefox exists. The more they try to dumb down their browser, the more market share they lose. They still haven't learned this, and it completely boggles the mind. Over and over and over and over and over and over and over and over and over and over again… Mozilla makes the wrong choice in trying to dumb down their browser. I could repeat "over and over" another few dozen times. They need a change in management at some level, because we're back to this dumb crap… again, "over and over again".
- code_duck 5y agoThis is the same bad idea as hiding file extensions.
- dataflow 5y agoI'm actually not sure hiding file extensions was a bad idea. As a developer I hate it, but I'm not sure for ordinary users they should be visible or editable as easily as the file name.
- malwarebytess 5y agoWhy do we have to design for the lowest capacity users? Are they the largest demographic, or doesn't that matter?
- dataflow 5y agoWell it depends on what you're designing. For a general-purpose OS used by everyone and their grandmothers, it makes sense to have them in mind and let the more advanced users customize the settings. And I would assume non-computer-savvy folks are indeed the largest demographic too, though I don't have data on it. And also, if you believe it's a good thing for the world to become digital (say, to reduce carbon emissions), you need products and services to be accessible to most kinds of users.
- austhrow743 5y agoThey're the least able and likely to make their way to settings to change it.
- throwaway3699 5y agoI can tell you it's been a total nightmare when family members have been phished and hacked. It's happened to grandparents on both sides of the family. One of them has learned and is still getting better, but the other has been trying for 20 years and computers are turning into a phobia for her. As everything moves online there is a non-trivial portion of the population getting shut out. Government services are moving online for the most part. Imagine not being able to help your grandkids with homework, or even do video calls during the pandemic, without a fear of losing your life savings. I don't like the dumbing down of browsers and the web, but I do believe we (computer professionals, etc...) have to find a way to solve this problem for everyone.
- combatentropy 5y agoWhy not instead apply syntax highlighting to the URL?
- zestyping 5y agoThat's a good idea. Firefox emphasizes the main part of the domain name in darker text, so "ycombinator.com" is black while the rest of the URL is grey. Chrome uses slightly darker text for the whole domain name, so "news.ycombinator.com" is black while the rest of the URL is grey — but the difference is so slight that it's nearly impossible to see. I don't know why they would bother to make the distinction and then make it visually indistinguishable. Safari shows just the domain name, "news.ycombinator.com".
- bagacrap 5y agoit does
- BrandoElFollito 5y agoYou can build a very long name yo push the domain outside the visible part of the form. This way all of your text is the same color and you may not realize that what you see does not have the domain part.
- malwarebytess 5y agoSweet Jesus thank you. Whomever thought this was a good idea needs to have their hands removed from any production database. There has got to be a better way to help people realize they're on the right domain than removing information for everyone. This reeks of mobile browser features creeping into desktop software. The use cases are entirely different. And the form informs the function -- you can't usually display a full URL on a mobile browser -- that is why you don't see it on mobile browsers.
- donmcronald 5y agoI wonder if highlighting the naked domain (example.com) would be useful.
- henrikschroder 5y agoFunnily enough, that's exactly what Firefox is doing.
- zkg 5y agoIsn't this implemented on Safari for some time now?
- jaffathecake 5y agoYes. Years. I think a URL bar that sticks to the security relevent parts is a good idea. It's hard for even experienced users to figure that stuff out. I tried to explain it here https://youtu.be/0-wB1VY3Nrc https://youtu.be/0-wB1VY3Nrc
- bityard 5y agoWell I mean the whole story is that google's own evidence was that the experiment didn't bear any fruit. The web is made of URLs and hiding them would be like taking the express train back to the AOL days. This "feature" would have brought negligible (if any) security, but would have made the web many times more difficult to use for both inexperienced and power users alike.
- ahofmann 5y agoYes, and it is awful. I know no Mac user who isn't using Chrome and the hidden URL is one reason for this.
- yftsui 5y agoContra data point here, I don’t use Chrome besides at work, enjoy the simplicity
- shp0ngle 5y agoAnecdote, I am using Safari for speed, except for Google Meet (since Safari seems to have never-ending issues with that, for some reason).
- yoz-y 5y agoA lot of Mac users are using safari for other reason. If there will be a true exodus, it will be because of the horrendous “tab” redesign in macOS 12
- donatj 5y agoThank God
- szundi 5y agoJust wanted to post the same.
- zestyping 5y agoKudos to Emily Stark for letting the real data guide her decision. It's hard to let go of something you've invested a lot of effort in, and it seems like this was something she had strong feelings about. Doing the right thing even when it's not what you were hoping for deserves to be applauded.
- rektide 5y agoTreating users like idiots who must be veiled from reality is, I hope, something we can continue to find good data against.
- dsign 5y ago+1 to this.
- m463 5y agoThe maddening thing is that there is data that will always be ignored. Like the % of users who will opt IN to cookies or tracking or similar.
- devenblake 5y agoAnd how many opt in just because the choices are "Manage site permissions... / Allow all"
- camgunz 5y agoIDK if "veiled from reality" is helpful here. Our job as software engineers is to build abstractions so like, glass houses and all that.
- rektide 5y agoengineers & companies break the compact, but the truest, most compelling heart of the web is about viewing named things, and those names are urls. to erode away at the name of things is to erode away the bedrock that holds this all up. it is to make the clear and the district muddled. there's no proposed new abstraction here, no new alternative: to hide the url would be to cloak the truth that makes the web so much better than all other computing: that this is an online space, where things have universal names[1], & that by using the name we can get to that thing. [1] https://www.w3.org/DesignIssues/Axioms.html https://www.w3.org/DesignIssues/Axioms.html
- zestyping 5y agoKudos to Emily Stark for letting the real data guide her decision. It's hard to let go of something you've invested a lot of effort in, and it seems like this was something she had strong feelings about. Doing the right thing even when it's not what you were hoping for deserves to be applauded.
- platinum1 5y agoThe verbiage of this article: "Google’s experiment ... has failed" - seems to be written by someone who doesn't know what an experiment is for. It did exactly what it was meant to - provide the data needed to make the right decision. Kudos to those involved for following the data. The experiment didn't fail, it concluded.
- 1vuio0pswjnm7 5y agoDeja vu. I feel like I have seen this comment before.
- theknocker 5y agoWhy is google so fucking activistic
- echelon 5y agoThis felt like phase two of putting everything under the AMP umbrella, and I would not be shocked if Google shut this down out of fear of regulatory scrutiny. Google really wants to kill the URL. If you have to navigate through Chrome and their search engine to get to things, they'll have sunk their claws deep enough that the web doesn't even matter anymore. They want to serve and proxy all the content so they can inject more ads and tracking. The EU and US DOJ should really be asking themselves whether or not the world's biggest search engine and advertising company should be allowed to develop the world's most popular browser. Maybe Google should be told to stop development of Chrome.
- Santosh83 5y agoAlso a mobile OS don't forget. So in the less monied parts of the world, (the majority), Google supplies the dominant mobile OS, mobile browser and search engine. As well as email, voice and location services.
- mchusma 5y agoOh thank God, this was so irritating. At least it didn't last long.
- kgeist 5y ago>Showing only the domain name was considered a good way to remove the extra chaff from a complex URL and only leave the core domain visible in the URL bar. >showing full URLs makes it harder for non-technical users to distinguish between legitimate and malicious (phishing) sites, many of which use complicated and long URLs in attempts to confuse users Why not simply make the domain name visually stand out from the rest of the url?
- NorwegianDude 5y agoIt already does, but I guess they didn't think that was enough.
- yholio 5y agoYes! Bold out the domain and leave the rest of the URL in a slightly lower contrast color.
- notatoad 5y agobrowsers have tried that, and it doesn't do any good because the phishers just make a long enough domain that the bolded part gets pushed off the screen.
- parsadotsh 5y ago? just have the bolded part fixed and the long part off screen ?
- LeoPanthera 5y agoGood, now Safari next, please.
- fart32 5y agoI could also live without hiding the protocol for non-secured websites. I mean leave the label there, I don't care, but whenever I want to copy the domain of a HTTP website, it also automatically prepends it with the protocol, which more often than not is not what I want. I wish developers just stop experimenting on URL bars and leave them simple and consistent...
- mro_name 5y agothe design issues of URLs are IMO less technical and much more SEO induced. Google has a lot to say here. E.g. URL length over 80 chars (https included) should be a penalty to search rank. So should parameters. Also everything impacting read- and spellability. URLs have to be designed on their own right. Remember Aaron Swartz's 'Programmable Web' opening chapter 'Building for Users: Designing URLs'. Design had just no stake here while advertising had. Then happened what happens when candy champions bread. The technicalities have to be commonplace and must not be hidden – like the wheels of a vehicle. You may not directly interact with them but you must be aware they're what it's all about.
- slver 5y agoThe problem with your stance is that URLs don’t matter. The only thing that matters is the origin. Sad their data didn’t confirm the obvious.
- est 5y agoGood lord this one guys's mess up address bar OKR pursuit finally stops.
- Yizahi 5y agoGoogle stops malicious blablabla... due to a public outrage and temporarily, until most will forget about it.