Skip to main content

Google Chrome will start getting aggressive with non-secure HTTP sites in January

Google’s Emily Schechter of the Chrome Security Team said on Thursday that starting with Chrome 56, slated to arrive in January 2017, the browser will visually inform users when HTTP sites are not securing the transmission of their credit card information and/or passwords. Google will eventually list all HTTP sites as non-secure, so this is a step in that direction.

Right now, Chrome visually indicates a secured website with a green HTTPS label in the address bar. However, when users visit a non-secure HTTP website, the browser throws up a neutral indicator indicating that the user might be at risk from a non-secure connection. According to Schechter, someone on the network could modify the HTTP website before it reaches the user’s browser.

Recommended Videos

When Chrome 56 lands next year, the browser will add a “not secure” label to the left of the website’s address in addition to the neutral indicator when the site doesn’t secure the form fields of credit card numbers and passwords.

Please enable Javascript to view this content

Eventually all HTTP pages will don the red non-secure triangle that the company currently uses for broken HTTPS websites. However, getting to that point will be gradual, and based on “increasingly stringent criteria.” One step in that direction will be labeling HTTP pages as non-secure when users are browsing the Internet in incognito mode.

If you’re not sure what HTTPS is all about, it’s short for HyperText Transfer Protocol Secure. That essentially means all data passed between the website and the user’s browser is encrypted so that hackers intercepting the transmission can’t access your credentials. The technology behind this encrypted transmission is called Secure Sockets Layer, or SSL, and essentially each side has a “key” to decrypt the data transmission, locking hackers out.

Unfortunately, HTTP sites don’t do this, allowing anyone to “eavesdrop” on the transmission between a webpage and its visitors. Even worse, hackers can modify these websites, after gaining login credentials, to install malware. And although Chrome warns users that they could be at risk in accessing an HTTP website, not all users perceive this warning as a lack of security. Even more, according to Schechter, users can become “blind” to warnings that occur too many times.

“A substantial portion of web traffic has transitioned to HTTPS so far, and HTTPS usage is consistently increasing,” Schechter said. “We recently hit a milestone with more than half of Chrome desktop page loads now served over HTTPS. In addition, since the time we released our HTTPS report in February, 12 more of the top 100 websites have changed their serving default from HTTP to HTTPS.”

Google’s plan for identifying non-secure websites reveals that HTTP sites accessed by Chrome will still work, and that the company has no plans to block these sites within the browser. However, this plan mainly addresses the concerns of websites that have yet to transition to HTTPS, and lists ways sites can grab free and cheap keys (certificates) for setting up a secure connection. A number of set-up guides can be found here as well.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
5 web browsers you should use instead of Google Chrome or Edge
Google Drive in Chrome on a MacBook.

Google Chrome and Microsoft Edge dominate the world of web browsers, but they’re not for everyone. Whether you want a browser that better respects your privacy or need an app that does things a little bit differently, you don’t have to stick to the usual suspects.

There’s a world of alternative web browsers out there if you want to give something new a try. Here, we’ve put together five excellent options, with each one bringing fresh new ideas to the table. So, if you’re looking for alternative browsers to Chrome and Edge, take one of these browsers for a spin.
Arc
Easels let you pin live websites snippets, which can update themselves and be interacted with. Alex Blake / Digital Trends

Read more
Google may build Gemini AI directly into Chrome
The Google Gemini AI logo.

Google is now fleshing out its newly unified Gemini AI system in its browser with its first attempt at implementing Chat with Gemini into the Chrome Omnibox.

This latest effort will update Google Chrome with a Chat with Gemini shortcut in the Chrome Omnibox, allowing users to access the AI chatbot feature without having to go to the Gemini website, according to WindowsReport. The Omnibox serves as an address bar and search bar, and it adds multiple other tasks to a browser. Now with a simple @ prompt, you can also access Google's AI chatbot to answer questions, create images, and generate summaries, among other tasks.

Read more
Google just settled a $5B privacy suit involving Chrome browser
The Google Chrome logo on a smartphone.

Google has agreed to settle a $5 billion lawsuit brought by claimants who accused the web giant of privacy invasion by tracking their online activities despite being in “incognito mode” when using the company’s Chrome browser.

After lawyers announced on Thursday that they’d reached a preliminary agreement, U.S. District Judge Yvonne Gonzalez Rogers put a scheduled trial for the case in California on hold, Reuters reported.

Read more