Google to start "shaming" HTTP websites from January 2017

Still on this “HTTPS is important” matter. Ran into this today - Google Chrome Will Start Shaming Unencrypted Websites in January

On Thursday, Google officially announced its anti-HTTP plan. The company isn’t going to shame all unencrypted websites all at once, but start only with HTTP sites that ask users to input passwords or credit cards. These sites will be flagged as “Not secure” in the Chrome address bar.

http://motherboard-images.vice.com/content-images/contentimage/37343/147334093759767.png

Then, in the future—Google is not saying exactly when yet—Chrome will flag all sites that don’t use TLS encryption as “Not secure” and also display a red triangle indicator, which Chrome already uses when users go to a dangerous website.

http://motherboard-images.vice.com/content-images/contentimage/37343/1473340952197298.png

I guess it’s time for boys to sprinkle some LetsEncrypt love on their projects, or put CloudFlare’s universal SSL to use.

3 Likes

I guess its time for countries to fund the creation and improvement of their local search engines :stuck_out_tongue_closed_eyes:

1 Like

If the sole aim is to be able to avoid Google’s push for a more secure web, I wonder how that would fly. Also, it’s the browser - Chrome. Not the search engine. But we all know how these things work. Other browsers will shortly pick it up and follow suit.

1 Like

Let countries decide what type of encryption a website needs same way they decide the security of their countries… When the Heartbleed bug was a problem a lot of websites were affected.

A more secure web depends on the web developer and the website administrators… If admin’s password is breached then the website is at the mercy of the “new admin”…

I am not against a secure web… :laughing:

Considering the recent FBI-Apple debacle, I’m surprised you want governments to be able to dictate what counts as “suitable” encryption.

That “debacle” was for show… :smile:

@xolubi, are you sure @GodMode is not just trolling again?

@Godmode - I see you are still full of it. Indeed, some things never change.

The admin’s password isn’t the only thing that should be protected.

What about user’s data- passwords, credit card data etc.

I bet this is how you feel right now…They have forced your wish on everyone. :smiley:

2 Likes

If the admin’s password is breached then the users data has also been breached… unless the web developer creates verification process before the admin can view users data …

That’s just the admin’s data… if the database itself has been breached the admin is on his/her own :grin:

:rolling_eyes:
HTTP and HTTPS are protocols for communicating with websites. Whatever user category (even admin), all your requests is subject to a man in the middle attack. In fact it’s so easy to do using something like Kali.

Just implement HTTPS.

It all comes down to monitoring websites especially sites that are not located their country…

The government has a secret system that spies on you every hour of everyday…

Very soon websites may require webcam verification before you can use them :grinning:

On the flipside, it could be counter-productive and be simply reduced to just another error message that users will learn to ignore just like UAC dialogs on windows

I was gonna start writing a long reply explaining all kinds of stuff about how the HTTP protocol works, packet sniffing, man in the middle attacks, etc. but I’ve decided against it. This is not new information and not up for debate either. People way smarter than you and I have done the research and concluded that the web is safer by encrypting traffic between clients and servers and that is that. The RFCs, books, blog articles, white papers, etc. are out there for you to find if you’re interested.
There’s no point debating it 'cos its not a subjective, it just is.
I welcome the idea of shaming non HTTPS sites (which somewhat inexplicably includes this site). I enable SSL for all sites I administer unless there’s a specific architectural reason not to (and there likely aren’t any these days). With stuff like Letsencrypt, its become incredibly trivial to do so.

1 Like

Chief Calm Down!

Google sha, wont be surprised they start their SSL Service soon :slight_smile:

This is headache inducing…

1 Like