4 ms·
Maybe this is a bit naive of me, but has anyone been of the impression that keystrokes in an address bar are not public (or at least un-private)? I have been u
by kortex 5y ago
Maybe this is a bit naive of me, but has anyone been of the impression that keystrokes in an address bar are not public (or at least un-private)?
I have been under the operating assumption since circa 2006 that anything done in a browser is potentially sent of somewhere to somebody's server. If I want privacy, I use tor.
Anything that's not the body of an https request is at minimum going to be logged somewhere.
- jhhh 5y agoI still use a split address bar and search bar with "Show search suggestions in the address bar" toggled off, so until this version the address bar suggestions were only from bookmarks and history items.
- Yoofie 5y agoYou are not alone. I operate under the assumption that any application that connects to the internet indeed sends back my activity in that app back home. What frustrates me is that everyone goes out of their way to make fragile, internet connected and internet dependent applications when there basically no need to.
- t-writescode 5y agoThis was not previously the case and shows an evolution of this tragedy from the past to the present. There was pandemonium back when Ubuntu first started doing that in its search line, for example. Now, no one cares and thinks it's "just how it is", except for some privacy holdouts, like myself. This isn't the way the world used to be.
- Gigachad 5y agoMy thoughts. I have never once in my life typed something in to the browser search bar that I intended to be local or private.
- _Anima_ 5y agoFirefox has been using Google's safe search since version 6. So unless you disable or block it, Google knows about your whereabouts, even if you used Bing.
- smsm42 5y ago> anyone been of the impression that keystrokes in an address bar are not public They shouldn't be. Logs containing URLs are commonly considered private information, and while it's a bad practice to put passwords, etc. in the URLs, people still do it, and even more often things like tokens, keys, object IDs etc. are part of the URLs. Disclosing this to a third party is essentially a MITM attack, and even though we're talking only about user input, this still includes stuff like URLs copies from emails, terminals, documentation files, etc. - and those may contain very un-public thing. Simplest example - do you consider the password reset URL many sites send to be public or private? Of course, not many people would type it - but people would copy-paste it and then maybe type something else - and who can guarantee the whole URL isn't then sent to an untrusted party?