> anyone been of the impression that keystrokes in an address bar are not public
They shouldn't be. Logs containing URLs are commonly considered private information, and while it's a bad practice to put passwords, etc. in the URLs, people still do it, and even more often things like tokens, keys, object IDs etc. are part of the URLs. Disclosing this to a third party is essentially a MITM attack, and even though we're talking only about user input, this still includes stuff like URLs copies from emails, terminals, documentation files, etc. - and those may contain very un-public thing. Simplest example - do you consider the password reset URL many sites send to be public or private? Of course, not many people would type it - but people would copy-paste it and then maybe type something else - and who can guarantee the whole URL isn't then sent to an untrusted party?