Google Chrome gets ready to mark all HTTP sites as 'bad'

kev216

Level 21
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 6, 2014
1,044
Google's push for all websites to be HTTPS has so far been all carrot. But the company is now using its big stick: a large red cross through every website that doesn't offer an encrypted connection.


A year after Google's Chromium Security team proposed marking all HTTP sites which are non-secure, the company is preparing to implement the policy in Chrome.

As the company highlighted in its proposal in 2014, HTTP sites provide no data security to users, so why don't browsers warn users of this fact, say, by displaying a red cross over a padlock next to the URL instead of the status quo, which is no warning at all?

Google called on Apple, Microsoft, and Mozilla to reverse the situation gradually, so that one day the only unmarked sites are those that have enabled the more secure protocol, HTTPS.

With HTTPS, the connection to users is encrypted and the site's digital certificate has been verified by a third-party certificate authority.


The new marking in Chrome is designed to be the stick to the carrots Google has dangled to encourage wider adoption of HTTPS.

Google argues that properly secured connections can frustrate surveillance attacks on the web. In 2014, it began using HTTPS as a positive ranking signal and in December adjusted its indexing system to crawl for HTTPS equivalents of HTTP pages and prioritize them where they're available.

However, until this week it hadn't announced any progress on its proposal. At the Usenix Enigma 2016 security conference, Google offered a snapshot of the future, showing what The New York Times website would like when Google implements the feature in Chrome.

Chrome users can look at how the markings would work by typing chrome://flags/ in the URL bar and enabling the experimental feature 'Mark non-secure origins as non-secure'.


It is not clear when Google will introduce the new marking system by default in Chrome, though some observers, such as Eric Mill from the US General Services Administration's tech savvy unit 18F, have taken it as a sure sign the plan will proceed.

Google's Chromium issue tracker also indicates it is pressing ahead with the feature: "Our goal is to mark non-secure pages like HTTP, using the same bad indicator as broken HTTPS, since this 1) is more accurate than marking such pages as neutral, and 2) simplifies the set of security indicators."

And as the company prepares to begin marking HTTP as bad, it has also released new tools to help developers deploy HTTPS.

On Tuesday, Google announced Security Panel, a new developer tool in Chrome that will help them identify common issues preventing sites from attaining the green padlock that represents a properly secured connection.

The tool will check the validity of a digital certificate and whether the site is using a secure protocol, cipher suite, and key exchange.

It will also help pinpoint the source of mixed content issues, such as a non-secure image on an otherwise secured page, which today in Chrome will trigger a grey padlock with a yellow triangle.
 

cutting_edgetech

Level 3
Verified
Feb 14, 2013
113
This could lead to a large rise in Firefox users. I surf many HTTP websites. I already use Firefox, but if I didn't I would have to switch to Firefox. They may switch to a browser other than Firefox, but FF will be the most likely option for most users due to it's vast library of add-ons support.
 
  • Like
Reactions: kev216 and jamescv7

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
The only drawback is the implement of HTTPS due to financial issues, so users who use Google Chrome may shock and use other alternative browsers instead because they don't want any notifications that be annoyed.

Even though the purpose is meant for good however expect the massive adjustment.
 
  • Like
Reactions: kev216

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top