Chrome 83 will Block Insecure Downloads on HTTPS Pages

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,148
Google plans to block all insecure downloads in coming versions of the company's Google Chrome browser. Insecure downloads, according to Google, are downloads that originate from HTTPS websites that are not served via HTTPS. The decision won't affect sites that are still accessed via HTTP.

The change is the next step in Google's plan to block "all insecure subresources on secure pages" which it announced last year. Back then, Google declared that mixed content, another term for insecure content on secure websites, "threatens the privacy and security of users" as attackers could modify the insecure content, e.g. by tampering with a mixed image of a stock chart to mislead investors" or injecting "a tracking cookie into a mixed resource load".
Insecurely-downloaded files are a risk to users' security and privacy. For instance, insecurely-downloaded programs can be swapped out for malware by attackers, and eavesdroppers can read users' insecurely-downloaded bank statements. To address these risks, we plan to eventually remove support for insecure downloads in Chrome.
chrome insecure downloads blocking
Read more below:
 

Antus67

Level 9
Verified
Well-known
Nov 3, 2019
413
In an attempt to improve the security of its users, the Chrome browser will soon start blocking insecure downloads on HTTPS pages, Google announced.


The plan, which the Internet giant laid out this week, is expected to be completed sometime in the fall, when Chrome 86 arrives.
The announcement comes just days after the release of Chrome 80, which by default blocks mixed audio and video resources if they cannot be automatically upgraded to HTTPS. The same will happen with image files in Chrome 81, which is expected to be released to the stable channel in March 2020.
In the long term, Google’s plan is to block all insecure sub resources on secure pages, as they represent a risk for users. Files that are downloaded insecurely could be replaced by attackers with malware, or exposed to eavesdroppers.


“To address these risks, we plan to eventually remove support for insecure downloads in Chrome,” the Internet giant says.
In the initial phase, the focus is on insecure downloads started on secure pages, and the first step is to display warnings. The restrictions for mixed content downloads, Google says, will be pushed to all desktop platforms first.

Executable files will be impacted first, with Chrome 82 displaying a warning on them and Chrome 83 blocking them.
 

Sampei Nihira

Level 6
Verified
Well-known
Dec 26, 2019
287
There is something wrong with the information in the article.
This is much more detailed:

And in fact it seems to me that mixed audio video content is not blocked in Chrome 80.
As verified by the test below:


Microsoft Edge/Chromium also behaves the same way.
My New Moon performs much better on this test.(y)(y)(y)(y)
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top