Jump to content

Recommended Posts

Posted (edited)

I see it on some sites and not others currently but come July all HTTP sites will be marked as 'not secure'

 

Chrome has been taking measures to inform users when they're on an unencrypted HTTP website, adding notifications to more and more sitesover the last couple of years. Today, Google announced it will be taking that one step further, labeling all HTTP sites as "not secure" starting with the release of Chrome 68. You can see what that will look like in the image below.Treatment_of_HTTP_Pages%402x.png

Google says there has been a lot of progress when it comes to getting developers to switch their sites to the more secure HTTPS. Now, over 68 percent of Chrome traffic on Android and Windows is protected while over 78 percent is protected on Chrome OS and Mac. Additionally, 81 of the top 100 sites now use HTTPS. To keep things going in that direction, Google's open-source Lighthouse tool now has an audit feature that lets developers see which resources are being loaded with HTTP and which of those can be simply upgraded to HTTPS.

"Chrome's new interface will help users understand that all HTTP sites are not secure, and continue to move the web towards a secure HTTPS web by default," Google said in a statement. Chrome 68 is scheduled to be released in July.

Image: Google

 

 

 

Edited by fiza
Posted
Could be interesting with internal sites still on http. They should be https really. Just because it's behind the firewall. Doesn't mean it's safe.
Posted
.......who will then “need” Firefox!

Mozilla will eventually do the same for Firefox.

 

https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/

 

Today we are announcing our intent to phase out non-secure HTTP.

 

There’s pretty broad agreement that HTTPS is the way forward for the web. In recent months, there have been statements from IETF, IAB (even the other IAB), W3C, and the US Government calling for universal use of encryption by Internet applications, which in the case of the web means HTTPS.

 

New browser features will also be restricted to HTTPS.

 

https://blog.mozilla.org/security/2018/01/15/secure-contexts-everywhere/

 

Effective immediately, all new features that are web-exposed are to be restricted to secure contexts. Web-exposed means that the feature is observable from a web page or server, whether through JavaScript, CSS, HTTP, media formats, etc. A feature can be anything from an extension of an existing IDL-defined object, a new CSS property, a new HTTP response header, to bigger features such as WebVR.
Posted (edited)
That a problem as https site redirect does not seem to work for our guest wifi sign in unless you go the BBC first HTTP. Edited by nicholab
  • 5 months later...
Posted (edited)

Chrome 68 Released: HTTP Sites Marked as "Not Secure"

 

The Chrome team is delighted to announce the promotion of Chrome 68 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

 

HTTP Sites Marked as "Not Secure"

In Chrome 68, Chrome will show the “Not secure” warning on all HTTP pages. We announced this in a blog post published on February 8th on Google’s Chromium and Online Security blogs.

 

To ensure that the Not Secure warning is not displayed for your pages in Chrome 68, we recommend migrating your site to HTTPS. The following migration guide provides migration recommendations and addresses common migration concerns such as SEO, ad revenue and performance impact.

 

eFO7Ex.png

Edited by Arthur

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...