It also makes my blood boil that Safari both hides the full path of the URL you're currently visiting and doesn't implement the standard practice of giving you a preview of the full URL you're about to visit when you hover over a link. These are horrible choices for usability and security, especially at a time when phishing is so productive.
Safari has both of these. Safari > Settings > Advanced > Show full website address, and View > Show status bar.
Moreover, I don't think either of them help out with phishing. The intention behind not showing the full website address is specifically to stop phishing, since it puts the emphasis on the domain name. (Is there a phishing situation where someone could spoof the domain name? Maybe, but I imagine in that case, they could spoof the rest of the URL as well). As for the status bar, I don't think anyone would look at it even if it was enabled by default.
And frankly, the Settings window and the View menu are not obscure places to put these options. Those are the first places you should look if you're in a Mac app and want to configure the UI.
If Safari was a 1:1 clone of Chrome but without (probably) sending my stuff to Google, I'd be all over it. Millions of other Mac users too. Instead I'm using Chrome on Mac just to get many websites to even work.
Uh, which part of my comment do you agree with? Clearly you disagree with something, because that's the opposite conclusion I came to.
In regards to the https problem specifically, while safari will say you are browsing an insecure page if using http, they do it in a horrible way - by adding text to the beginning of the url bar. Certainly if you were trying to reduce url confusion, you would add a separate symbol and label! I can click insecure icon on chrome and other browsers to read more about how, but I cannot do so on safari -- so much for trying to reduce confusion.
The move to hide the full URL is to make the URL readable for the average user. People on this site might know how to parse URL components in their head, but the average user does not inherently understand the DNS hierarchy nor do many completely understand URI delimiters.
https://secure.bankofamerica.com.0-0.pw/login/securelogin.aspx
might look okay to a lot of people 0-0.pw
would be a little better indicator that it isn't their bank.The padlock is mostly useless in today's world. It was useful in a time when ecommerce was young and otherwise legitimate sites were collecting information via http. There was an attempt to make it more useful with extended validation certs, but that solution didn't really end up being effective. Phishers could still register EV certs that spoofed other names, and adoption was too low to change user behavior.
Criminals today phish people, use HTTPS, and people have a false sense of security because of those who told them “padlock = good”. The padlock served a purpose to drive http adoption. It does more harm than good today.
Browsers should instead upgrade to https automatically on all connections.
What's the problem with this?
> Certainly if you were trying to reduce url confusion, you would add a separate symbol and label!
Why? I'm not following what's wrong with Safari's approach. You're stating your conclusions but not your reasoning.
> I can click insecure icon on chrome and other browsers to read more about how, but I cannot do so on safari
Read more about what?
In the second, Safari inlines the "not secure" to the URL but not in a visually clear way. It looks like "not secure" is part of the domain.
Read more about what the "not secure" and the padlock actually means.
You don’t have to name names if that’s a problem, but there should at least be something credible we can look into.
Pretty explosive allegation imo.
If it is “near impossible to turn that off” it means it is possible. How?
Reference?