{"id":14513,"date":"2019-02-06T11:10:06","date_gmt":"2019-02-06T19:10:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/02\/06\/news-8263\/"},"modified":"2019-02-06T11:10:06","modified_gmt":"2019-02-06T19:10:06","slug":"news-8263","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/02\/06\/news-8263\/","title":{"rendered":"Google Chrome announces plans to improve URL display, website identity"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 06 Feb 2019 18:16:47 +0000<\/strong><\/p>\n<p>\u201cUnreadable gobbledygook\u201d is one way to describe URLs today as we know them, and Google has been attempting to redo their look for years. In their latest move to improve how Chrome\u2014and of course, how the company hopes other browsers would follow suit\u2014displays the URL in its omnibox (the address bar), Google\u2019s Chrome team has made public two projects that usher them in this direction.<\/p>\n<p>First, they launched <a href=\"https:\/\/github.com\/chromium\/trickuri\" target=\"_blank\" rel=\"noopener\">Trickuri<\/a> (pronounced as \u201ctrickery\u201d) in time for a talk they were scheduled to present at the <a href=\"https:\/\/www.usenix.org\/conference\/enigma2019\/program\" target=\"_blank\" rel=\"noopener\">2019 Enigma Conference<\/a>. Second, they\u2019re working on creating warnings of <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/06\/somethings-phishy-how-to-detect-phishing-attempts\/\" target=\"_blank\" rel=\"noopener\">potentially phishy URLs<\/a> for Chrome users.<\/p>\n<h3>Watch out! Some trickery and phishing ahead<\/h3>\n<p>Trickuri is an open-source tool where developers can test whether their applications display URLs accurately and consistently in different scenarios. The new Chrome warnings, on the other hand, are still in internal testing. Emily Stark, Google Chrome\u2019s Usability Security Lead, confesses that the challenge lies in creating heuristic rules that appropriately flag malicious URLs while avoiding false positives.<\/p>\n<p>&#8220;Our heuristics for detecting misleading URLs involve comparing characters that look similar to each other and domains that vary from each other just by a small number of characters,&#8221; Stark said in an <a href=\"https:\/\/www.wired.com\/story\/google-chrome-kill-url-first-steps\/\" target=\"_blank\" rel=\"noopener\">interview with WIRED<\/a>. &#8220;Our goal is to develop a set of heuristics that pushes attackers away from extremely misleading URLs, and a key challenge is to avoid flagging legitimate domains as suspicious. This is why we&#8217;re launching this warning slowly, as an experiment.&#8221;<\/p>\n<p>These efforts are part of the team\u2019s current focus, which is the detection and flagging of seemingly dubious URLs.<\/p>\n<h3>Google Chrome\u2019s bigger goal<\/h3>\n<p>The URL is used to identify entities online. It is the first place users look to assess if they are in a good place or not. But not everyone knows the components that comprise a URL, much less what they mean in the syntax. Google\u2019s push for website owners to use HTTPS has rippled across browser developers and consequently changed user preferences to favor such sites. In effect, by pushing HTTPS, Google changed the game to give the user a generally safer online experience.<\/p>\n<p>However, Google wants to go beyond this, and are set on raising user awareness of relevant parts of the URL (so they can make quick security decisions). As a result, they are refining Chrome to present these parts while keeping users\u2019 view away from the irrelevant gibberish.<\/p>\n<p>In a separate interview with WIRED, Adrienne Porter Felt, Google Chrome\u2019s Engineering Manager, has this to say about <a href=\"https:\/\/www.wired.com\/story\/google-wants-to-kill-the-url\/\" target=\"_blank\" rel=\"noopener\">how users perceive the URL<\/a>: \u201cPeople have a really hard time understanding URLs. They\u2019re hard to read, it\u2019s hard to know which part of them is supposed to be trusted, and in general I don\u2019t think URLs are working as a good way to convey site identity. So we want to move toward a place where web identity is understandable by everyone\u2014they know who they\u2019re talking to when they\u2019re using a website and they can reason about whether they can trust them. But this will mean big changes in how and when Chrome displays URLs. We want to challenge how URLs should be displayed and question it, as we\u2019re figuring out the right way to convey identity.\u201d<\/p>\n<p>While these may all sound good, no one\u2014not even Google\u2014knows what the final, new URL will look like at this point.<\/p>\n<h3>A brief timeline of Google\u2019s efforts in changing the URL<\/h3>\n<p>Below is a brief timeline of attempts Google has made to how Chrome displays the URL in the omnibox:<\/p>\n<ul>\n<li>April 2010: Google <a href=\"https:\/\/www.cnet.com\/news\/should-your-browser-address-bar-show-http\/\" target=\"_blank\" rel=\"noopener\">removes &#8216;HTTP&#8217;<\/a>&#8216; from the address bar.<\/li>\n<li>May 2014: Google began testing a feature that is known internally as <a href=\"https:\/\/www.extremetech.com\/computing\/181657-google-moves-to-kill-off-the-url-entirely-in-new-version-of-chrome\" target=\"_blank\" rel=\"noopener\">the \u201corigin chip\u201d<\/a>, its first attempt at evolving (or \u201ckilling&#8221; the URL as we know it) the display of the URL. However, this was <a href=\"https:\/\/www.pcworld.com\/article\/2362123\/google-chromes-origin-chip-experimental-feature-appears-to-be-on-hold.html\" target=\"_blank\" rel=\"noopener\">put on hold<\/a>.<\/li>\n<li>January 2017: Google starts marking <a href=\"https:\/\/www.zdnet.com\/article\/chrome-56-google-starts-slapping-not-secure-on-http-payment-and-login-pages\/\" target=\"_blank\" rel=\"noopener\">some HTTP websites<\/a> as \u201cnot secure.\u201d<\/li>\n<li>October 2017: Google starts marking <a href=\"https:\/\/www.zdnet.com\/article\/google-tightens-noose-on-http-chrome-to-stick-not-secure-on-pages-with-search-fields\/\" target=\"_blank\" rel=\"noopener\">HTTP websites with a search box<\/a> as \u201cnot secure.\u201d<\/li>\n<li>July 2018: Google starts marking <a href=\"https:\/\/www.bleepingcomputer.com\/news\/software\/chrome-68-released-with-warnings-on-http-sites-but-also-other-security-features\/\" target=\"_blank\" rel=\"noopener\">all HTTP websites<\/a> as \u201cnot secure.\u201d<\/li>\n<li>September 2018: Google <a href=\"https:\/\/www.zdnet.com\/article\/google-to-remove-secure-indicator-from-https-pages-on-chrome\/\" target=\"_blank\" rel=\"noopener\">removes the &#8216;Secure&#8217; indicator<\/a> from HTTPS pages.<\/li>\n<li>September 2018: Google <a href=\"https:\/\/www.bleepingcomputer.com\/news\/google\/chrome-69-removing-www-and-m-subdomains-from-the-browsers-address-bar\/\" target=\"_blank\" rel=\"noopener\">removes \u2018www\u2019 in URLs and the \u2018m\u2019<\/a> (which indicates that it\u2019s a website address geared for mobile users).<\/li>\n<li>September 2018: Google <a href=\"https:\/\/www.bleepingcomputer.com\/news\/google\/googles-removing-the-file-scheme-from-chromes-address-bar\/\" target=\"_blank\" rel=\"noopener\">removes the &#8216;file:\/\/&#8217;<\/a> scheme.<\/li>\n<li>September 2018: Google <a href=\"https:\/\/www.zdnet.com\/article\/google-to-remove-secure-indicator-from-https-pages-on-chrome\/\" target=\"_blank\" rel=\"noopener\">begins showing a red \u201cNot secure\u201d warning<\/a> to users when they start entering data on HTTP pages<\/li>\n<li>January 2019: Google introduces Trickuri for developers<\/li>\n<li><em>[still unknown date]: Google will introduce new phishing warnings to Chrome users.<\/em><\/li>\n<\/ul>\n<h3>\u201c\u2026it just raises too many questions.\u201d<\/h3>\n<p>With Google\u2019s new effort, how will it affect redirection schemes? SEO? Shortened URLs?<\/p>\n<p>Will this, in time, affect the behavior of new Internet users entering URLs in the address bar? For example, what if they don\u2019t know that certain URL elements are (by default) elided but should now be typed in (such as entering \u2018www\u2019) to go to their desired destination? Will they understand the meaning of .com or .org if these elements are erased from view?<\/p>\n<p>How can web developers, business owners, and consumers prepare themselves for these URL changes?<\/p>\n<p>Right now, there&#8217;s more uncertainty than there are answers, as Google admits there is still a lot of work to be done. And based on the tone of several spokespersons in interviews, the company also expects some pushback and a degree of controversy that may arise from their efforts. Change is never easy.<\/p>\n<p>Let\u2019s keep an eye on <a href=\"https:\/\/www.wired.com\/story\/google-wants-to-kill-the-url\/\" target=\"_blank\" rel=\"noopener\">this URLephant in the room<\/a>, shall we? And let\u2019s also keep giving feedback and raising questions. After all, this is Google\u2019s way of keeping Chrome users away from URL-based threats. If changes are not implemented with thoughtful precision, then threat actors can easily find a way around them, or at least bank on the confusion resulting from a poor rollout of new processes.<\/p>\n<p>While the future of URLs is still murky, one thing&#8217;s for certain: the bad guys know how to exploit weaknesses. So we hope, for Google and all its users&#8217; sake, changes in URL display only serve to strengthen everyone&#8217;s security posture online.<\/p>\n<p>Further reading:<\/p>\n<ul>\n<li><a href=\"https:\/\/chromium.googlesource.com\/chromium\/src\/+\/master\/docs\/security\/url_display_guidelines\/url_display_guidelines.md\" target=\"_blank\" rel=\"noopener\">Google Source: Guidelines for URL Display<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/02\/google-chrome-announces-plans-improve-url-display-website-identity\/\">Google Chrome announces plans to improve URL display, website identity<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/02\/google-chrome-announces-plans-improve-url-display-website-identity\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 06 Feb 2019 18:16:47 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/101\/2019\/02\/google-chrome-announces-plans-improve-url-display-website-identity\/' title='Google Chrome announces plans to improve URL display, website identity'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/shutterstock_1218889750.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>The search giant isn\u2019t \u201ckilling\u201d (a.k.a. getting rid of) the URL, unlike some sensationalist and eye-rolling headlines have put it. They are slowly giving it a facelift.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/\" rel=\"category tag\">101<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/fyi\/\" rel=\"category tag\">FYI<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/chrome-improvement-timeline\/\" rel=\"tag\">chrome improvement timeline<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google\/\" rel=\"tag\">Google<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-changes-url-presentation\/\" rel=\"tag\">google changes url presentation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-chrome\/\" rel=\"tag\">Google Chrome<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-kills-the-url\/\" rel=\"tag\">google kills the url<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/url-display\/\" rel=\"tag\">url display<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/101\/2019\/02\/google-chrome-announces-plans-improve-url-display-website-identity\/' title='Google Chrome announces plans to improve URL display, website identity'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/02\/google-chrome-announces-plans-improve-url-display-website-identity\/\">Google Chrome announces plans to improve URL display, website identity<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10519,20862,10520,1670,20863,11427,20864,3924,20865],"class_list":["post-14513","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-10519","tag-chrome-improvement-timeline","tag-fyi","tag-google","tag-google-changes-url-presentation","tag-google-chrome","tag-google-kills-the-url","tag-phishing","tag-url-display"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14513"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14513\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14513"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}