"Our heuristics for detecting misleading URLs involve comparing characters that look similar to each other and domains that vary from each other just by a small number of characters," Stark says. "Our goal is to develop a set of heuristics that pushes attackers away from extremely misleading URLs, and a key challenge is to avoid flagging legitimate domains as suspicious. This is why we're launching this warning slowly, as an experiment."

Google says it hasn't started rolling out the warnings to the general user population while the Chrome team refines those detection capabilities. And while URLs may not be going anywhere anytime soon, Stark emphasizes that there is more in the works on how to get users to focus on important parts of URLs and to refine how Chrome presents them. The big challenge is showing people the parts of URLs that are relevant to their security and online decision-making, while somehow filtering out all the extra components that make URLs hard to read. Browsers also sometimes need to help users with the opposite problem, by expanding shortened or truncated URLs.

"The whole space is really challenging because URLs work really well for certain people and use cases right now, and lots of people love them," Stark says. "We’re excited about the progress we’ve made with our new open source URL-display TrickURI tool and our exploratory new warnings on confusable URLs."

The Chrome security team has taken on internet-wide security issues before, developing fixes for them in Chrome and then throwing Google's weight around to motivate everyone to adopt the practice. The strategy has been particularly successful over the past five years in stimulating a movement toward universal adoption of HTTPS web encryption. But critics of the approach fear the drawbacks of Chrome's power and ubiquity. The same influence that has been used for positive change could be misdirected or abused. And with something as foundational as URLs, critics fear that the Chrome team could land on website identity display tactics that are good for Chrome but don't actually benefit the rest of the web. Even seemingly minor changes to Chrome's privacy and security posture can have major impacts on the web community.

Additionally, a trade-off of that ubiquity is being beholden to risk-averse corporate customers. "URLs as they work now are often unable to convey a risk level users can quickly identify," says Katie Moussouris, founder of the responsible vulnerability disclosure firm Luta Security. "But as Chrome grows in enterprise adoption, rather than the consumer space, their ability to radically change visible interfaces and underlying security architecture will be reduced by the pressure of their customers. Great popularity comes not only with great responsibility to keep people safe, but to minimize churn in features, usability, and backwards compatibility."

If it all sounds like a lot of confusing and frustrating work, that's exactly the point. The next question will be how the Chrome team's new ideas perform in practice, and whether they really wind up making you safer on the web.

*Correction January 29, 10:30pm: This story originally stated that TrickURI uses machine learning to parse URL samples and test warnings for suspicious URLs. It has been updated to reflect that the tool instead assesses whether software displays URLs accurately and consistently.

More Great WIRED Stories