For better or worse, the URL scheme is what we have to identify websites and pages. Hiding that on larger screens doesn’t make much sense. It also hinders learning for the next generation.
For better or worse, the URL scheme is what we have to identify websites and pages. Hiding that on larger screens doesn’t make much sense. It also hinders learning for the next generation.
Personally, for my own purposes, I think hiding any bit of the URL is incredibly inconvenient. Already hiding the www. is seriously annoying. I will switch this new behaviour off and hope they don't remove that option.
If AMP didn't exist I might be slightly more inclined to believe them.
Which is exactly what they do at the moment.
The non-domain information in a URL is useless for making security decisions for virtually 100% of users. If anything, it has negative utility since you can make URLs nearly arbitrarily confusing as part of a phishing attack.
The point is that "the UI should express everything a power user could ever want to know about some security-adjacent property" is not the status-quo and people should not act like it is. Dropping to just domains is like shifting from a big blob of text including a ton of request information to just the lock icon. It distills it to something that covers basically all the information you'd ever actually need and is comprehensible to typical users.
Hopefully it remains this way _forever_, even with these newer changes as well.
The real protection against this is making it impossible for me to send credentials to the wrong party. Normally my password manager helps with that, but I had just switched managers a couple days before and it wasn't recognizing all sites properly (likely due to the lack of a database of known equivalent URLs). If the site was using WebAuthn, there wouldn't have been any issue because the imperfect URL checks by me and the password manager would not be necessary.