14 ms·
An Update on the Lock Icon
- chrismsimpson 3y agoApple will do this in 3 years and call it innovative
- matthewaveryusa 3y ago"You know that green lock in your browser?" used to be how I explained what I did in 5 seconds. Now what am I supposed to do?! I like this update, I think this is an excellent UX change
- jeroenhd 3y ago"Click the button that looks like two magnifying glasses pointing left and right" clearly! I get what they were going for with this design, but it's impossible to describe this over the phone. I guess they want you to use Chrome Remote Desktop if you ever need to support someone remotely.
- jackson1442 3y agoGood change imo. They didn't mention in the post but I do hope they continue to show the "Not Secure" warning for HTTP-only websites.
- billyhoffman 3y ago> We continued to mark HTTP as insecure in the URL bar.
- dfabulich 3y agoThey did mention it in the post. "On all platforms, we will continue to mark plaintext HTTP as insecure."
- dfabulich 3y agoI approve of getting rid of the lock icon, showing only a broken lock for HTTP and no lock for HTTPS. It's always been weird to have site permissions settings revealed by clicking that lock. But the replacement icon looks really strange to me. They're calling it a "tune icon," but I've never seen a tune icon like this, with just two circles and two lines. Looks weird. I'm surprised that it fared well in the experiment. I would prefer it if they'd use a gear icon, which is normally used for settings like this. You can see a gear icon at the bottom of the tune menu for "Site settings," which makes it all the weirder that they're using a tune icon in the URL bar and a gear icon in the menu for site settings.
- noja 3y agoThe icon looks like something from audio equipment. I get it.
- reaperducer 3y agoAren't we supposed to hate skeuomorphism? I forget whether it's cool or not this week.
- function_seven 3y agoWhat icons have ever not been skeuomorphic? I hate skeuomorphism when it's used wantonly, beyond the purpose of communicating how the UI works. Like that first version of the Apple Podcasts app that had a reel-to-reel animation¹, for example. But icons... it's like the definition of the term. > I forget whether it's cool or not this week. I think it might be trending upward again. We all hated it in 2012, then the pendulum swung so far toward "flat design" that I (we?) would love to have too much of it again, if the alternative is not enough of it. [1] https://www.flickr.com/photos/atmasphere/8320805931/ https://www.flickr.com/photos/atmasphere/8320805931/ EDIT: Just thought about it some more and realized some icons are good abstractions of a non-physical thing. Play, Pause, and the rest of audio controls, for example. And of course Back and Refresh are just arrows. But for something like "settings", or "info", you're going to have to draw some sort of picture for that. Gears and lists of sliders are two already-recognizable things that people know means "guts of the machine" and "control console panel thing".
- CharlesW 3y agoWhat's with the naming and visuals of the "tune" icon, which seems to be a "site settings" icon with weird left- and right-justified radio buttons?
- samtho 3y agoIt is a simple representation of those on/off toggle switch UI elements.
- djur 3y ago"Tune" as in "adjust settings".
- CharlesW 3y agoThe mental model of "and here's where you tune the website" seems so strange to me, but thank you for the credible explanation!
- deleted 3y ago[deleted]
- crazygringo 3y agoI've got to say, "tune" is such a weird word to choose, it almost sounds like a bad translation. Tuning is associated with musical notes (originally) and then with cars (optimizing performance) and engines more generally. It's a weird metaphor to use for an icon that's usually been called "settings". Because settings are not tuning, because engine/car tuning isn't about choosing your preferred settings, it's about small adjustments to maximize performance. (The visual icon makes sense since it shows the popup to toggle settings for the site.)
- politelemon 3y agoReading through this it's making a lot of sense, the lock icon was added to convey that the 'connection is secure', while making the assumption that the user understood it's talking about the transport layer behind the scenes. Of course, most users cannot be expected to know that kind of detail, so they would associate it with the thing in front of their eyes, the website itself. I am sticking to Firefox but as changes go, this wouldn't be a terrible one for non-Chrome browsers to converge upon. I don't think it's a good idea to hide the option away entirely though; a lack of available information and options for a user on a platform can often lead to the platform itself deciding it needs to become the arbiter of information, but I assume the iOS limitation is Apple's usual user-hostile behaviour.
- at_a_remove 3y agoWhen we were hosting custom websites for various university departments on the cheap, at this point it was difficult to do HTTPS on a site that shared IPs (which I gather has been corrected). One group insisted on it, despite that their form results, which weren't exactly secret squirrel knowledge, got stuffed into plain ole SMTP emails. I explained this carefully. "But it has a LOCK on it ..." It was impossible to get them to understand that SSL only protected one part of the movement of data. All they got was LOCK. So, yes, I agree that the lock offers a kind of false sense of security to people who will latch onto that symbol even as the people providing the hosting tell them otherwise.
- chowells 3y ago> (which I gather has been corrected) Indeed. In two different directions, even. First, a server can send a certificate with a large number of domain names in a field called "Subject Alternate Name" (SAN). If a server host a small number of static names, that's an easy solution. Second, the client can use a TLS extension called "Server Name Indication" (SNI) to tell the server what name it's attempting to connect to. This is more recent than the SAN approach, and allows a single host to work for truly ridiculous sets of different names, even changing them dynamically.
- userbinator 3y ago
- mattl 3y agoThink of all the webpages that tell people to look for a padlock icon in their browser? All the books, all the training materials, videos, etc. This doesn't seem like a good idea at all.
- post-it 3y agoThey'll change. Maintaining backwards compatibility with third-party training material is the least-useful form of maintaining backwards compatibility.
- computerfriend 3y agoThat advice didn't seem to be a good idea.
- mattl 3y agoIt's still true of virtually every browser other than future versions of Chrome and possibly browsers based on Chromium.
- djur 3y agoThat advice has been deprecated for years and has never been sufficient. The reverse is true now: the browser will warn about an insecure connection.
- shadowgovt 3y agoThis is forever the problem with documentation: it checkpoints a description of a system at a point in time. You can make an extremely valid similar argument regarding C++ tutorials written in 1995, but the end-response is the same: "Update your sources, learn the new thing, and most importantly don't assume anything computer-related that is more than 5 years out of date is relevant, especially for something Internet-related."
- mattl 3y agoOkay but unless other browsers make the same change now you have two sets of information and now users need to know their underlying browser's engine too?
- 8lahaj 3y ago[dead]
- 015a 3y agoI think its possible there could be a backlash against this change, as even though many peoples' understanding of the security implications of the lock icon didn't align with reality, their expectation vis a vi "lock icon means secure, no lock means insecure, be careful if there isn't a lock" could force a broad unlearning of something that the security community has tried to teach over the past ten to fifteen years. > Despite our best efforts, our research in 2021 showed that only 11% of study participants correctly understood the precise meaning of the lock icon. It doesn't seem to me that this is the right thing to be measuring. What matters more is: how many people critically misunderstand what the lock icon means, leading to the potential for trusting sites which shouldn't otherwise be trusted. The study itself goes on to better answer this, though its absent from the article: only 23-44% of respondents referred to the padlock at all when asked to evaluate the trustworthiness of a website. Its safe to say that some subset of that group would be shared with the group who critically & negatively misunderstand what the padlock represents, but its also safe to say that the entirety of the 11% "we know what the padlock means" group is also in the center of this venn diagram. In other words: not more, and likely less, than a third of users were being misled by the padlock to the point of compromise. That's still a lot of people and its worth improving, but its a far cry from the 89% the blog post advertises. When combined with the notion that the padlock's absence could cause harm; a different kind of harm, moving from "yeah this site is trustworthy I'll enter my credit card" when it isn't, to "no way this site is trustworthy I'm out of here" when it is trustworthy for some in that 23-44% group; I'm not sure this is a positive change. I get that the world of HTTPS is evolving, and its very broadly default-on instead of default-off nowadays, but it seems to me that this is something of an expedient and ineffectual solution to something much harder: education. The article says "Despite our best efforts, our research in 2021 showed that only 11% of study participants correctly understood the precise meaning of the lock icon", but I'm at a loss for what exactly Google means by "despite our best efforts". I don't intend to be mean or combative with this observation. Education is really difficult; but when viewed through a more critical lens this article and the associated change really smells like "We failed to correctly educate our users about internet security, so we're changing an icon to absolve ourselves of the responsibility of the previous icon's inferred meaning."
- minaguib 3y ago
- p1mrx 3y agoIf you're using Chrome, right-click the URL bar and check "Always show full URLs", so you can see the https:// https:// prefix like it's 1999. This also fixes a variety of UX problems with editing URLs. By the way, does anyone know of a good alternative to http://neverssl.com http://neverssl.com ? I had been using this for years, but now it supports SSL for some unfathomable reason.
- Dandy3556 3y agoI use https://nonhttps.com/ https://nonhttps.com/
- DiggyJohnson 3y agohttpforever.com is my go to.
- p1mrx 3y agoNice. I see that https://httpforever.com/ https://httpforever.com/ exists with a 301 redirect to http://httpforever.com/ http://httpforever.com/, but that's probably good enough for most practical purposes.
- notatoad 3y agothat appears to also be what neverssl is doing - they support https only for the purposes of redirecting to a non-ssl domain
- p1mrx 3y agoNope, when I go to neverssl.com, it ultimately lands on an HTTPS url, e.g. https://shinyquietbrightsong.neverssl.com/online/ https://shinyquietbrightsong.neverssl.com/online/ Edit: I'm running Chrome OS 113 beta. Maybe they changed something recently, to automatically use HTTPS unless prohibited by the server? This also happens in Guest mode with no extensions.
- 3y ago
- mholt 3y agoFor my masters thesis, I proposed replacing the security indicator with a risk indicator: "After HTTPS: Indicating Risk Instead of Security" - https://scholarsarchive.byu.edu/etd/7403/ https://scholarsarchive.byu.edu/etd/7403/ Turns out there are lots of localized, privacy-preserving cues you can observe to determine whether a user may be at some level of risk, that doesn't involve a centralized blocklist or a boolean answer; and users really appreciated the "heads up". I think a control panel like this is a good step forward after ubiquitous HTTPS. I also think user agents can do more to protect and warn users in ways that are less easily spoofed by malicious sites. Looking forward to seeing future developments!
- sedatk 3y agoMicrosoft Edge already does that. They show a quite prominent "Not secure" sign with an exclamation mark instead of the regular hollowed out (aka very indistinguishable) lock icon when the connection isn't trusted HTTPS.
- madeofpalk 3y agoAll browsers to do this now, to varying levels of severity. Firefox gets a padlock with a red slash through it, Chrome gets that warning icon with "Not secure", and Safari just says "Not secure".
- xPaw 3y agoThis is a good move for the secure-by-default move. In The Lounge IRC client, we've also opted to this approach years ago, where secure connections show no icon, and insecure connections show an insecure icon.
- jbverschoor 3y agoSuch a cryptic lock is even more confusing. I propose a very simple, easy to understand solution: http should simply be RED https should not be indicated at all A curated list, preferably by the gov. should indicate which SSL certificates are allowed to be green.
- throwawaaarrgh 3y agoSo as long as you're not color blind or vision impaired or from a country where red doesn't mean danger, sounds fine Government oversight of TLS certs? No way this could possibly go wrong
- Clamchop 3y agoTraffic lights. Everyone everywhere knows red, yellow, and green now, and how to navigate around colorblindness (both red and green lights are tinted to be distinguishable).
- deathanatos 3y agoTraffic lights are a combination of color and position; even if one is completely colorblind, the position of the lit lamp is sufficient to discern the signal. The above suggestion doesn't have that sort of double-encoding of the data. (This holds even for the odd horizontal signal, though I would expect most non-colorblind people would not be able to tell you the orientation from memory. … and … there are plenty of drivers on the road who, judging from their behavior, would appear to be incapable of determining the color of the signal.)
- Clamchop 3y agoTraffic lights still work without position, as they'd have to at night, in fog, in glare, and so on. Point is, the meaning of the colors appears to be universally understood thanks to driving, and distinguishing the colors has been addressed. If there are exceptions, I suppose localizations and accessibility modes are just the thing.
- ladon86 3y agoIt’s a continuation of the trend that led to them removing Extended Validation indicators: https://duo.com/decipher/chrome-and-firefox-removing-ev-certificate-indicators https://duo.com/decipher/chrome-and-firefox-removing-ev-cert... Here’s how they used to appear: https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg https://pbs.twimg.com/media/EBxdA7EWsAIQtc0.jpg While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easier to train employees to “look for your company’s name in the green bar” before they sign into a site, than to understand how domains work and why login.yourcompany.com is OK but login-yourcompany.com isn’t. Does anyone know if it’s possible to restore EV indicators in Chrome via MDM software or similar? Does anyone work at a company that does this?
- jve 3y agoLong ago I was reading someone registered corp in some other jurisdiction with the same company name which he wanted to impersonate with EV cert. And succeeded. So what are you proposing is of questionable value.
- X-Cubed 3y agoThat researcher was Ian Carroll, who created a new "Stripe, Inc" company in Kentucky, a clone of the one registered in Delaware, and was therefore able to get an EV certificate issued for his new company that looked very similar to one issued for the Delaware company. His original research site appears to no longer be online (https://stripe.ian.sh/ https://stripe.ian.sh/), but you can read more about it in these articles: https://www.bleepingcomputer.com/news/security/extended-validation-ev-certificates-abused-to-create-insanely-believable-phishing-sites/ https://www.bleepingcomputer.com/news/security/extended-vali... https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/ https://arstechnica.com/information-technology/2017/12/nope-...
- throwawaaarrgh 3y ago> EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. Our company puts a big red banner on the top of all emails that come from an external source or don't have DMARC/SPF/DKIM/other security protections. Literally nobody ever checks the banner. It has no effect on phishing click rates. People do not read, or think. They just look for wherever it is expected for them to click something/fill something out, or just click random things to see what something might be. The only thing that has marginally improved click rates is when we either gamify it, or put all external mails in an external mail folder marked NOT SAFE.
- layer8 3y agoI wonder how many ordinary users have any notion of what the “tune” icon [0] is supposed to indicate. [0] https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgugOcJZQTuZzMo-ker60pSIzOIfBPPIV7Gq_7nmOU9lVqJWZ-qyurLC-Pj3lrPrrh-pemoJC6Ix27Dam2LmNasddSS21m37_7YV8qbC2MPE8j1gEIcBqcMqSAvhq5WnAJ34OV3IZYoqhivJo0oN3C2A4NWA0csosSV4jFIbqhOopCrXwKPFu96oW6_Yg/s288/tune.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg...
- Spivak 3y agoIt looks odd in isolation but I was surprised how natural it looks in the bar. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh42uF3vHKMYdRxs7Pn3IWFieNo15A49lukAYJ_WzOOgfN1frqfnkh45T-pUdZdIW-caFj1tA8IGBRRjgra_jd2JQ6igjESnX2xYieuWgA3aP4E7QU4mif8OrA7XAPwyURpVQ5azwDXe8NnuxjmV_4nnVEvc-YPBq76tcCOzBAS8pjQDNt-rKM88M3q6A/s1040/new-site-controls.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh...
- happytoexplain 3y agoThis settings/configure/adjust icon seems to be in the middle of a transition between abstract and universal. Something like a magnifying glass didn't need any transition period because humans already associate it with "searching" from fiction. Other icons required reinforcement to learn (e.g. the share icon - or, even more well learned, the pause icon). One of the downsides of the modern hyper-focus on metrics in UI is that it dictates that iconography already be intuitive. Sometimes we need to ignore this rule in order to teach users a new icon, which then helps us improve interfaces by communicating more without words.
- mqus 3y agoI'm glad they continued the "An Update on X" = "X is getting axed" tradition at google. It's one of the few constants. Maybe they even have a UX guideline about it by now :D PS: I'm not writing this out of spite, btw. It just came to my mind when I saw the title and I was surprised I was right
- kmoser 3y agoBetteridge would ask, "Is X Staying?" https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headlines https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...
- dadrian 3y agoBelieve it or not, the title began as a placeholder title before I realized it was a Google-ism for shutting things down.
- rootusrootus 3y agoWhile we're fixing the UI for SSL, can we do something about unsecure connections to devices on my home network? At best I get a huge security warning that makes me jump through hoops to get past it, sometimes Chrome won't even let me get past without knowing the secret code. Surely we can figure out how to tell that a connection is only on the local network, and then give the user a one-time option to not worry about encryption for such local connections?
- yamtaddle 3y agoI think the concerns/difficulties are: 1) Business contexts. A local network maybe shouldn't be trusted, there, for security purposes. "OK, but they should set that with policies" which, yes, sure, but defaults do matter, so... I dunno, I can see why they'd prefer the safer default. 2) Lying DNS servers on a local-but-actually-public network (think: coffee shop wifi) directing you to a local address to bypass SSL protection while it proxies Amazon or your bank website or whatever, and steals your credentials. 3) IPv6 is supposed to render these distinctions rather moot (although, LOL, and also that's precisely one thing some folks don't like about it, but that's another topic)
- rootusrootus 3y agoI agree there are things that would have to be worked out, to prevent opening new exploitable holes. How about we just add some ability to the browser to remember the site (fingerprint it somehow, perhaps) so that the security policy only has to be agreed to once. Kinda sorta similar to SSH remembering known hosts. Once I've told Chrome that my Unifi Dream Router is okay, or my Iotawatt, or Home Assistant, etc ... it should stop making me jump through hoops every time until something changes. And I don't ever want it to flat out tell me no, I cannot reach something on my home network with a low quality SSL implementation unless I blindly type "thisisunsafe" into the security window. It's a pet peeve of mine, as you may have noticed. I have a lot of little random devices on my home network and many of them have no way (or no simple way, at least) of protecting with a real SSL certificate. Sometimes I'll go through the trouble of using nginx as a reverse proxy to hide the insecurity, but that isn't always easy to get working either.
- kaycebasques 3y agoIt's been interesting to watch the web landscape change over the last 8 years. Back in 205 when I joined Google's Web DevRel team, I worked with Chrome security engineers to create a persuasion article [1] about why all sites should be encrypted with HTTPS. The fact that they felt the need to create that page at all indicates that HTTPS was not that common. In 8 years the ecosystem has got to a place where HTTPS is so common that we don't even need UI for it anymore. [1] https://web.dev/why-https-matters/ https://web.dev/why-https-matters/
- GuB-42 3y agoAnd even before that, you got a popup when https was used. Something along the lines of "Warning: this site is secure".
- PaulHoule 3y agoThey just want people to be really confused, don’t they?
- Wowfunhappy 3y ago> The new icon is scheduled to launch in Chrome 117, which releases in early September 2023, as part of a general design refresh for desktop platforms. I downloaded Chrome Canary to take a look at this "general design refresh" and... sigh. The new browser UI is now 10 pixels taller than the old one. I realize 10 pixels isn't a lot. But it's also not noting—it's half the height of the top bar on Hacker News. And this is after Google already made their UI much taller in their last refresh. If you make the UI take up more and more space with each redesign, it adds up. Yes, I have a bigger monitor today than I once did. But I bought that monitor so I'd have more space for actual content, not the browser UI. Remember how Google chose the name "Google Chrome" because it was designed to have a minimal UI that gets out of your way and lets you focus on page content?
- anon3242 3y agoIt is not just about pixels... The line-height of the text in the address bar simply feels wrong to me. We now have more spaces but smaller, harder to see text. Feels like going backwards for me. Reminds me of the new Steam download UI, the elements are larger while the download speed is much harder to discrern. I rememember lying on bed checking on the game download speed in my high school years, now I have to get real close to see the current speed. The rest of the "refresh" actually seems not unacceptably bad. Some 'designers' just blatantly waste advanced technology and screen real estate. Like I finally built a PC that can open right-click menus in an instant wihout having to watch the spinner, and then windows 11 decided that having (unskippable!) transitions to open menus is a good idea. I went out of my way to make sure I have the lowest-latency mouse and monitor, and websites use these custom css scrollbars that have nearly 2 frames of more latency that the system one, also dragging windows in and out of Stage Manager make your mouse have massive latency for a while. I am at least happy with macOS though, at least the line-height is not going wild. Seems Apple have some of their soul left, though they may be lost soon. Even just being a novice macOS user I can immediately tell whether any animation is done pre or post 2020.
- Dalewyn 3y agoIt's been the trend for the past decade or so to use as little of the available rendering power as possible. 32-bit color? Naw, we're going two tone: Black and white. 8k screen resolution? Naw, we can't waste precious screen real estate on such frivolous things like borders and shading. 240Hz screens? Naw, we can't waste precious processor cycles and power on frivolous animations. As for fonts, I get the impression that designers behind it are all in their 20s, maybe even fresh out of their late 10s. One's eyesight is usually still top notch in that age range, I know mine was; and I too dabbled in font sizes for ants because they looked cooler. But I'm in my 30s now, and I can't stand tiny fonts anymore. My eyes aren't what they used to be, and designers by either their ignorance or naivety can't seem to respect the fact that people fucking age. I don't entirely blame them, I was that ignorant and naive bastard too once upon a time; I've grown wiser with age. Newer/younger designers really ought to be shown how their seniors use their designs, it'll be an eye opening (pun intended) learning moment for the ones who were just naive. The ignorant ones probably can't be helped, but who knows.
- absentmoon 3y agoThey updated it but as soon as you click it the old icon and UX is there?
- astrea 3y agoFirst they remove the protocol, then the www subdomain, red lock meant http, now this. Are we going to remove the TLD while we're at it?
- cobbal 3y agoRemoving the TLD was the point of AMP. All sites shall be Google.
- awinter-py 3y agochrome lock icon announces proposed offering of common stock + mandatory convertible preferred
- cyclotron3k 3y agoI never understood why a website served using a self-signed (and untrusted) certificate would throw up more warnings than a website served without any encryption at all. Even today, a page served over HTTP just gets an unobtrusive bit of text saying "Not secure", but if a page is served over HTTPS with a cert that expired yesterday you will get a very scary full-page warning that entirely blocks you from accessing the underlying page. It seems totally backwards to me.
- aewens 3y agoAn analogy may help, imagine the website as a door. A website using HTTP is a normal door and using HTTPS is a door with a lock, where the keyring in this analogy are the trusted CAs by your browser. A website using HTTPS with an expired certificate is a door that should have a lock, but the lock no longer latches; and a self-signed certificate is a locked door with a key left in the doorknob. From a security perspective, a door without a lock has no expectation of protecting anything. But a door that should lock but doesn’t, or is supposed to be locked but has the key left in the latch is not providing the security expected, and should be given pause when anticipating security from the lock. This is what the browser is trying to translate with its UI.
- cyclotron3k 3y agoThat makes sense in theory, but you need to think about how the average user is going to perceive these UI choices: we're posting smaller warning for less-safe things. Put another way, the average user is going to be much more concerned about using a website with an expired certificate than a website that has no protection at all. Put a third way: to the average user, a website behind an SSL-stripping MITM proxy is going to look more trustworthy than a website that forgot to renew their cert.