Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even today's protocol hiding is so inconvenient, who is making these decisions, do the use computers regularly?


The average user sees http://123.45.67.89/~sk/microsoft.com/techsupport as a legitimate Microsoft website. That's what this change is intended to fix: users that see a domain in any part of the URL as being valid. They want to change it to only show the part that's actually security relevant. If you tell the average user "Look for Microsoft in the URL", and they find it in the path, they're going to fall for a phishing scam.


HIDING the URL doesn't seem to be the most obvious solution to this, to me.


Protocol hiding was recently fixed, via the "Always show full URLs" option. The default is still an inconsistent mess, but checking this option makes the URL bar so much better than it's been in years.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: