Re: ACTION6: URL display as anti-pattern

"Close, Tyler J." <tyler.close@hp.com>, 2006-12-04 13:51 -0600:

> Domain names can be very deceptive: www.bankofthevvest.com,
> paypal.secure.com, paypa1.com, etc.  We need to provide the user
> with a site identifier which will not attempt to deceive the
> user. This means we can't use text that came from the potential
> attacker.
> 
> Frankly, I think we would be better off removing the Location bar from
> the default browser user interface. I think it does more harm than good.
> 
> Thoughts? Would Konqueror seriously consider dropping the Location bar
> from the default user interface? Or is it too big a change? Pushing in
> this same direction, I'd like to see the browser move all potentially
> misleading data out of the chrome area, providing a graphically clear
> dividing line between what is reliable and what is suspect.

The URL information in the location bar is useful for more than
just providing security-context information, and I think users
might lose more if it were suppressed than they gain by having it
displayed. I think in general that in deciding what should and
should not be displayed in the browser chrome, the criteria that
need to be considered are more than just whether the data can be
abused to provide potentially misleading data.

  --Mike

Received on Wednesday, 6 December 2006 12:47:41 UTC