Thanks, but could you please stop trying to control the web Google?
Thanks, but could you please stop trying to control the web Google?
"People have a really hard time understanding URLs," says Adrienne Porter Felt, Chrome's engineering manager. "They’re hard to read, it’s hard to know which part of them is supposed to be trusted, and in general I don’t think URLs are working as a good way to convey site identity. So we want to move toward a place where web identity is understandable by everyone—they know who they’re talking to when they’re using a website and they can reason about whether they can trust them. But this will mean big changes in how and when Chrome displays URLs. We want to challenge how URLs should be displayed and question it as we’re figuring out the right way to convey identity."
And one of their incentives in doing so is that Google is an alternative to URLs. Already many users Google ‘facebook’ and click on the first link rather than just typing ‘facebook.com’ (or ‘face’ TAB ENTER).
Although I don’t believe I saw it in the article, it’s in Google’s interest to mediate all access to the Internet for consumers — this isn’t fundamentally different from Facebook’s VPN. It’s not in users’ interest, of course.
If they cared about security they could do something like display the domain & the path separately, maybe on different lines (with maybe colour used to distinguish HTTPs vice HTTP):
news.ycombinator.com
reply?id=…They've tried experiments but it's not as easy as it might seem at first thought. Consider what happens with someone setting up a hostname like bankofamerica.secureuserportal.com or www.gmail.personaluserinbox.biz – a fair number of people will look at the left part rather than reading from the right so even displaying it separately won't help, especially if they don't have a huge window with tons of room and all they see is the first part of "www.bankofamerica.comsecurecardholderservices.ru".
Only displaying the domain name will help with that problem but it has usability issues for any company which handles user data under subdomains since it'd be harder to tell user1.example.com from user2.example.com if there's any possibility of spoofing.
In fact, if I was Google (and I was less scrupulous), that's the kind of behavior I would encourage: train users to type destinations into Google, serve up the results using AMP, obfuscate the whole thing by eliminating URLs, then users will just stay in Google's ecosystem and never leave.
I will be surprised if URLs go away completely in the next 50+ years, but a new way to verify the identity of the website will probably be developed, if it's necessary.
They are trying to solve an issue which isn't even part of the responsibility of the URL. The domain is the truthteller here. If you can find a way to display to the user what actual domain he or she is on,you have solved the issue.
I don't understand why we should view computer illiteracy as something we must cater to. You don't have to know everything about how URL works, but being able to change ?page=1 to ?page=2 and knowing what is probably going to happen and similar tasks is knowledge probably needed today and should be teached.
Why does people never learn this? If you teach people to be uneducated this is exactly what they will become.
Unfortunately the easy solution to that seems to be more walled gardens. I'm pretty sure we'll start seeing Google-certified websites. Registering your website with the Google Search Console will start to become mandatory to appear in the top results. Or implement AMP.
So I'm with you but I think it's important to understand that URLs are broken for most people. When you see a perfectly legible piece of text, their brain is automatically blurring it like some piece of flesh in a Japanese Hentai.
This is a truism, but I'm not certain it's true. Is there actual data to back this up? What definition of "normal" is being used here.. the average person using the internet, or non-technically trained people?
The web has been around for decades now, and everyone including my nearly 70 year old mother uses it, and URLs have been pretty ubiquitous for a long time. Not knowing what a URL is seems about as likely as not knowing what a TV channel is, or that they have a bank account number.
It seems more likely to me that normal people do know what they are, but find avoiding them to be more convenient than using them.
The arrogance coming off of this company is unreal at times.
I strongly disagree. I do tend to think that they're useful and not obviously replaceable, but claiming they have no issues is dubious.
Spoofing, with or without the added level of sophisticated enabled by unicode. Special character handling (e.g. whitespace) is sometimes problematic. URL longevity is a real issue. Server-side security has been compromised in the past using "../" in URLs.
I'm sure I could come up with more, and I imagine there's a "top 10 fallacies programmers believe about URLs" list out there that would provide more examples.
punycode, similar-domain name squatting, SSRF/ generally parsing urls properly, parsing uniformly
probably 100 others but this was just off the top of my head. Some of these they intend to deal with, some they do not.
Also, due to the way DNS works you really are trusting ICANN, then the com registrar, then facebook (CAs add an overlay, but then CAs like Let’s Encrypt ultimately trust … DNS). Making that explicit would probably be a good thing (and might even be a first step towards a rootless, decentralised future).