Chrome to test hiding full url , defense against phishing

Google will subject Chrome users to a large-scale test in the next version of its browser to discover how people respond to just seeing a site’s domain name without the full URL for pages on that site. 

Google’s new experiment will involve some “randomly assigned” users of Chrome 86. These users will have two choices when the full URL (Uniform Resource Locator) is concealed. Those in the experiment would, for example, only see en.wikipedia.org rather than the full address of the specific Wikipedia page.  

As a first step, users in the experiment can hover over the limited URL to display the full URL. The other option is to right-click on the URL, and choose ‘Always show full URLs’ in the context menu. This will make Chrome show the full URL for all future sites being visited.

The purpose of the experiment is to see whether this approach helps people spot phishing URLs.

There are a bunch of ways scammers and attackers can tweak a URL to trick users into thinking they’re opening a legitimate and authentic page.  

Apple Safari is one browser that already only shows the domain name by default and like Chrome, no longer shows the HTTPS

“In Chrome 86, we’re likewise going to experiment with how URLs are shown in the address bar on desktop platforms. Our goal is to understand – through real-world usage – whether showing URLs this way helps users realize they’re visiting a malicious website, and protects them from phishing and social-engineering attacks,” the Chrome security team states. 

Chrome users can test the approach Google is exploring in the Chrome Canary and Dev channels. Users will need to open chrome://flags in Chrome 86 and enable several flags before relaunching Chrome.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s