TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

An Update on the Lock Icon

283 pointsby semenkoabout 2 years ago

23 comments

p1mrxabout 2 years ago
If you&#x27;re using Chrome, right-click the URL bar and check &quot;Always show full URLs&quot;, so you can see the <a href="https:&#x2F;&#x2F;" rel="nofollow">https:&#x2F;&#x2F;</a> prefix like it&#x27;s 1999. This also fixes a variety of UX problems with editing URLs.<p>By the way, does anyone know of a good alternative to <a href="http:&#x2F;&#x2F;neverssl.com" rel="nofollow">http:&#x2F;&#x2F;neverssl.com</a> ? I had been using this for years, but now it supports SSL for some unfathomable reason.
评论 #35792149 未加载
评论 #35793280 未加载
评论 #35794596 未加载
评论 #35792549 未加载
评论 #35793411 未加载
评论 #35792290 未加载
评论 #35793245 未加载
评论 #35802108 未加载
评论 #35792639 未加载
评论 #35879081 未加载
评论 #35792458 未加载
评论 #35794355 未加载
评论 #35792277 未加载
评论 #35792141 未加载
评论 #35794748 未加载
评论 #35798418 未加载
评论 #35792158 未加载
评论 #35792427 未加载
评论 #35797079 未加载
评论 #35792236 未加载
politelemonabout 2 years ago
Reading through this it&#x27;s making a lot of sense, the lock icon was added to convey that the &#x27;connection is secure&#x27;, while making the assumption that the user understood it&#x27;s talking about the transport layer behind the scenes. Of course, most users cannot be expected to know that kind of detail, so they would associate it with the thing in front of their eyes, the website itself.<p>I am sticking to Firefox but as changes go, this wouldn&#x27;t be a terrible one for non-Chrome browsers to converge upon. I don&#x27;t think it&#x27;s a good idea to hide the option away entirely though; a lack of available information and options for a user on a platform can often lead to the platform itself deciding it needs to become the arbiter of information, but I assume the iOS limitation is Apple&#x27;s usual user-hostile behaviour.
评论 #35794351 未加载
评论 #35795989 未加载
评论 #35796532 未加载
dfabulichabout 2 years ago
I approve of getting rid of the lock icon, showing only a broken lock for HTTP and no lock for HTTPS. It&#x27;s always been weird to have site permissions settings revealed by clicking that lock.<p>But the replacement icon looks really strange to me. They&#x27;re calling it a &quot;tune icon,&quot; but I&#x27;ve never seen a tune icon like this, with just two circles and two lines. Looks weird. I&#x27;m surprised that it fared well in the experiment.<p>I would prefer it if they&#x27;d use a gear icon, which is normally used for settings like this. You can see a gear icon at the bottom of the tune menu for &quot;Site settings,&quot; which makes it all the weirder that they&#x27;re using a tune icon in the URL bar and a gear icon in the menu for site settings.
评论 #35791895 未加载
评论 #35793437 未加载
评论 #35792511 未加载
评论 #35791795 未加载
评论 #35792852 未加载
评论 #35793200 未加载
mholtabout 2 years ago
For my masters thesis, I proposed replacing the security indicator with a risk indicator: &quot;After HTTPS: Indicating Risk Instead of Security&quot; - <a href="https:&#x2F;&#x2F;scholarsarchive.byu.edu&#x2F;etd&#x2F;7403&#x2F;" rel="nofollow">https:&#x2F;&#x2F;scholarsarchive.byu.edu&#x2F;etd&#x2F;7403&#x2F;</a><p>Turns out there are lots of localized, privacy-preserving cues you can observe to determine whether a user may be at some level of risk, that doesn&#x27;t involve a centralized blocklist or a boolean answer; and users really appreciated the &quot;heads up&quot;.<p>I think a control panel like this is a good step forward after ubiquitous HTTPS. I also think user agents can do more to protect and warn users in ways that are less easily spoofed by malicious sites. Looking forward to seeing future developments!
评论 #35795318 未加载
mqusabout 2 years ago
I&#x27;m glad they continued the &quot;An Update on X&quot; = &quot;X is getting axed&quot; tradition at google. It&#x27;s one of the few constants. Maybe they even have a UX guideline about it by now :D<p>PS: I&#x27;m not writing this out of spite, btw. It just came to my mind when I saw the title and I was surprised I was right
评论 #35795010 未加载
评论 #35794105 未加载
ladon86about 2 years ago
It’s a continuation of the trend that led to them removing Extended Validation indicators: <a href="https:&#x2F;&#x2F;duo.com&#x2F;decipher&#x2F;chrome-and-firefox-removing-ev-certificate-indicators" rel="nofollow">https:&#x2F;&#x2F;duo.com&#x2F;decipher&#x2F;chrome-and-firefox-removing-ev-cert...</a><p>Here’s how they used to appear: <a href="https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;EBxdA7EWsAIQtc0.jpg" rel="nofollow">https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;EBxdA7EWsAIQtc0.jpg</a><p>While I buy the reasoning that consumers simply ignore them, EV indicators would be really useful in a corporate setting to mitigate phishing attempts against employees. It’s much easier to train employees to “look for your company’s name in the green bar” before they sign into a site, than to understand how domains work and why login.yourcompany.com is OK but login-yourcompany.com isn’t.<p>Does anyone know if it’s possible to restore EV indicators in Chrome via MDM software or similar? Does anyone work at a company that does this?
评论 #35793291 未加载
评论 #35795672 未加载
评论 #35793138 未加载
评论 #35793542 未加载
Wowfunhappyabout 2 years ago
&gt; The new icon is scheduled to launch in Chrome 117, which releases in early September 2023, as part of a general design refresh for desktop platforms.<p>I downloaded Chrome Canary to take a look at this &quot;general design refresh&quot; and... sigh.<p>The new browser UI is now 10 pixels taller than the old one.<p>I realize 10 pixels isn&#x27;t a lot. But it&#x27;s also not noting—it&#x27;s half the height of the top bar on Hacker News. And this is after Google <i>already</i> made their UI much taller in their last refresh. If you make the UI take up more and more space with each redesign, it adds up.<p>Yes, I have a bigger monitor today than I once did. But I bought that monitor so I&#x27;d have more space for actual content, not the browser UI.<p>Remember how Google chose the name &quot;Google Chrome&quot; because it was designed to have a minimal UI that gets out of your way and lets you focus on page content?
评论 #35797360 未加载
评论 #35796160 未加载
layer8about 2 years ago
I wonder how many ordinary users have any notion of what the “tune” icon [0] is supposed to indicate.<p>[0] <a href="https:&#x2F;&#x2F;blogger.googleusercontent.com&#x2F;img&#x2F;b&#x2F;R29vZ2xl&#x2F;AVvXsEgugOcJZQTuZzMo-ker60pSIzOIfBPPIV7Gq_7nmOU9lVqJWZ-qyurLC-Pj3lrPrrh-pemoJC6Ix27Dam2LmNasddSS21m37_7YV8qbC2MPE8j1gEIcBqcMqSAvhq5WnAJ34OV3IZYoqhivJo0oN3C2A4NWA0csosSV4jFIbqhOopCrXwKPFu96oW6_Yg&#x2F;s288&#x2F;tune.png" rel="nofollow">https:&#x2F;&#x2F;blogger.googleusercontent.com&#x2F;img&#x2F;b&#x2F;R29vZ2xl&#x2F;AVvXsEg...</a>
评论 #35793279 未加载
评论 #35793362 未加载
CharlesWabout 2 years ago
What&#x27;s with the naming and visuals of the &quot;tune&quot; icon, which seems to be a &quot;site settings&quot; icon with weird left- and right-justified radio buttons?
评论 #35797345 未加载
评论 #35791931 未加载
评论 #35792447 未加载
评论 #35793149 未加载
kaycebasquesabout 2 years ago
It&#x27;s been interesting to watch the web landscape change over the last 8 years. Back in 205 when I joined Google&#x27;s Web DevRel team, I worked with Chrome security engineers to create a persuasion article [1] about why all sites should be encrypted with HTTPS. The fact that they felt the need to create that page at all indicates that HTTPS was not that common. In 8 years the ecosystem has got to a place where HTTPS is so common that we don&#x27;t even need UI for it anymore.<p>[1] <a href="https:&#x2F;&#x2F;web.dev&#x2F;why-https-matters&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.dev&#x2F;why-https-matters&#x2F;</a>
评论 #35795774 未加载
matthewaveryusaabout 2 years ago
&quot;You know that green lock in your browser?&quot; used to be how I explained what I did in 5 seconds. Now what am I supposed to do?!<p>I like this update, I think this is an excellent UX change
评论 #35794282 未加载
xPawabout 2 years ago
This is a good move for the secure-by-default move.<p>In The Lounge IRC client, we&#x27;ve also opted to this approach years ago, where secure connections show no icon, and insecure connections show an insecure icon.
rootusrootusabout 2 years ago
While we&#x27;re fixing the UI for SSL, can we do something about unsecure connections to devices on my home network? At best I get a huge security warning that makes me jump through hoops to get past it, sometimes Chrome won&#x27;t even let me get past without knowing the secret code. Surely we can figure out how to tell that a connection is only on the local network, and then give the user a one-time option to not worry about encryption for such local connections?
评论 #35794047 未加载
评论 #35798515 未加载
cyclotron3kabout 2 years ago
I never understood why a website served using a self-signed (and untrusted) certificate would throw up more warnings than a website served without any encryption at all.<p>Even today, a page served over HTTP just gets an unobtrusive bit of text saying &quot;Not secure&quot;, but if a page is served over HTTPS with a cert that expired yesterday you will get a very scary full-page warning that entirely blocks you from accessing the underlying page.<p>It seems totally backwards to me.
评论 #35798356 未加载
015aabout 2 years ago
I think its possible there could be a backlash against this change, as even though many peoples&#x27; understanding of the security implications of the lock icon didn&#x27;t align with reality, their <i>expectation</i> vis a vi &quot;lock icon means secure, no lock means insecure, be careful if there isn&#x27;t a lock&quot; could force a broad unlearning of something that the security community has tried to teach over the past ten to fifteen years.<p>&gt; Despite our best efforts, our research in 2021 showed that only 11% of study participants correctly understood the precise meaning of the lock icon.<p>It doesn&#x27;t seem to me that this is the right thing to be measuring. What matters more is: how many people <i>critically misunderstand</i> what the lock icon means, leading to the potential for trusting sites which shouldn&#x27;t otherwise be trusted. The study itself goes on to better answer this, though its absent from the article: only 23-44% of respondents referred to the padlock at all when asked to evaluate the trustworthiness of a website. Its safe to say that some subset of that group would be shared with the group who critically &amp; negatively misunderstand what the padlock represents, but its also safe to say that the entirety of the 11% &quot;we know what the padlock means&quot; group is also in the center of this venn diagram.<p>In other words: not more, and likely less, than a third of users were being misled by the padlock to the point of compromise. That&#x27;s still a lot of people and its worth improving, but its a far cry from the 89% the blog post advertises.<p>When combined with the notion that the padlock&#x27;s <i>absence</i> could cause harm; a different kind of harm, moving from &quot;yeah this site is trustworthy I&#x27;ll enter my credit card&quot; when it isn&#x27;t, to &quot;no way this site is trustworthy I&#x27;m out of here&quot; when it is trustworthy for some in that 23-44% group; I&#x27;m not sure this is a positive change.<p>I get that the world of HTTPS is evolving, and its very broadly default-on instead of default-off nowadays, but it seems to me that this is something of an expedient and ineffectual solution to something much harder: education. The article says &quot;Despite our best efforts, our research in 2021 showed that only 11% of study participants correctly understood the precise meaning of the lock icon&quot;, but I&#x27;m at a loss for what exactly Google means by &quot;despite our best efforts&quot;. I don&#x27;t intend to be mean or combative with this observation. Education is really difficult; but when viewed through a more critical lens this article and the associated change really smells like &quot;We failed to correctly educate our users about internet security, so we&#x27;re changing an icon to absolve ourselves of the responsibility of the previous icon&#x27;s inferred meaning.&quot;
评论 #35794979 未加载
评论 #35798085 未加载
astreaabout 2 years ago
First they remove the protocol, then the www subdomain, red lock meant http, now this. Are we going to remove the TLD while we&#x27;re at it?
评论 #35798138 未加载
chrismsimpsonabout 2 years ago
Apple will do this in 3 years and call it innovative
awinter-pyabout 2 years ago
chrome lock icon announces proposed offering of common stock + mandatory convertible preferred
tomatbeboabout 2 years ago
They updated it but as soon as you click it the old icon and UX is there?
PaulHouleabout 2 years ago
They just want people to be really confused, don’t they?
mattlabout 2 years ago
Think of all the webpages that tell people to look for a padlock icon in their browser? All the books, all the training materials, videos, etc.<p>This doesn&#x27;t seem like a good idea at all.
评论 #35792416 未加载
评论 #35792529 未加载
评论 #35792472 未加载
评论 #35793969 未加载
评论 #35792440 未加载
jbverschoorabout 2 years ago
Such a cryptic lock is even more confusing. I propose a very simple, easy to understand solution:<p>http should simply be RED https should not be indicated at all<p>A curated list, preferably by the gov. should indicate which SSL certificates are allowed to be green.
评论 #35793175 未加载
评论 #35794027 未加载
评论 #35795056 未加载
jackson1442about 2 years ago
Good change imo. They didn&#x27;t mention in the post but I do hope they continue to show the &quot;Not Secure&quot; warning for HTTP-only websites.
评论 #35791776 未加载
评论 #35791755 未加载