Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I respect that Google is disciplined about shipping features like this only after extensive testing, but it troubles me that despite obvious problems with this approach - like the external appearance of funneling users to Google search for all their web navigation (regardless of whether this was an intentional purpose behind the design) - it made it all the way through design, implementation, testing, and code review without anyone realizing what the reaction would be. It seems likely that if a noisy user hadn't noticed and blogged about it, this could have made it through multiple channels and gotten close to the release channel.

It's great that you vet these changes on Canary and do user testing, but it's troubling that a change like this isn't first extensively vetted from a perspective of 'does this hurt our users? does it compromise their privacy? does it increase the odds that they will get sent to the wrong websites? does it hide important information in some cases?'

I suspect that this UI change is actually going to make people more vulnerable to phishing in cases where the domain is not a guarantee of identity; for example, an XSS on a google-controlled domain (where the full URL would make the attack obvious, but only showing domain hides it), or an attack hosted on a 'user content' domain that uses subdirectories to distinguish between different users/sites.

A more straightforward example is that all my gmail accounts have 'mail.google.com' as the domain in my browser, regardless of whether one of them is an Apps domain (thus security sensitive) and another one happens to belong to a sibling or significant other or something.

This feature just seems intrinsically misguided and poorly considered. I appreciate that your UX team is trying to aggressively improve things, but they seem to be acquiring a long track record of poor decisions.



Note that in the case of "XSS on a google-controlled domain," the malicious actor could just use JavaScript's pushState or replaceState APIs to modify the path in the address bar to "renew_subscription" or whatever.


I'm currently discussing the issue of vetting and "user-first" committments with a Google employee on G+, though concerning issues other than this. To put it mildly, I'm not at all convinced by developments I've seen at the company over the past 2+ years, if not longer. Actually, I'd pin this on when Gmail was first released. Prior to that, Google was simply something you used, but not as a registered user.

I've since elected out of Google search as my browser's defaults.


it made it all the way through design, implementation, testing, and code review without anyone realizing what the reaction would be.

Oh I don't think that's true at all. They just know that they're big enough that it doesn't matter what a bunch of internet weenies think when most of their audience doesn't know or care enough to understand the UI change, let alone grasp the business interests that drive it.


So XSS attacks and phishing scams don't matter? People who don't want their family's credit card details and passwords stolen by thieves are weenies?


I'm including myself in that group. And yes? Or at least will-be-dismissed-by-google-as-weeines-once-they-decide-what-is-right-for-everyone. But that doesn't roll off the tongue very well.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: