Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Google Chrome will start getting aggressive with non-secure HTTP sites in January

Add as a preferred source on Google

Google’s Emily Schechter of the Chrome Security Team said on Thursday that starting with Chrome 56, slated to arrive in January 2017, the browser will visually inform users when HTTP sites are not securing the transmission of their credit card information and/or passwords. Google will eventually list all HTTP sites as non-secure, so this is a step in that direction.

Right now, Chrome visually indicates a secured website with a green HTTPS label in the address bar. However, when users visit a non-secure HTTP website, the browser throws up a neutral indicator indicating that the user might be at risk from a non-secure connection. According to Schechter, someone on the network could modify the HTTP website before it reaches the user’s browser.

Recommended Videos

When Chrome 56 lands next year, the browser will add a “not secure” label to the left of the website’s address in addition to the neutral indicator when the site doesn’t secure the form fields of credit card numbers and passwords.

Eventually all HTTP pages will don the red non-secure triangle that the company currently uses for broken HTTPS websites. However, getting to that point will be gradual, and based on “increasingly stringent criteria.” One step in that direction will be labeling HTTP pages as non-secure when users are browsing the Internet in incognito mode.

If you’re not sure what HTTPS is all about, it’s short for HyperText Transfer Protocol Secure. That essentially means all data passed between the website and the user’s browser is encrypted so that hackers intercepting the transmission can’t access your credentials. The technology behind this encrypted transmission is called Secure Sockets Layer, or SSL, and essentially each side has a “key” to decrypt the data transmission, locking hackers out.

Unfortunately, HTTP sites don’t do this, allowing anyone to “eavesdrop” on the transmission between a webpage and its visitors. Even worse, hackers can modify these websites, after gaining login credentials, to install malware. And although Chrome warns users that they could be at risk in accessing an HTTP website, not all users perceive this warning as a lack of security. Even more, according to Schechter, users can become “blind” to warnings that occur too many times.

“A substantial portion of web traffic has transitioned to HTTPS so far, and HTTPS usage is consistently increasing,” Schechter said. “We recently hit a milestone with more than half of Chrome desktop page loads now served over HTTPS. In addition, since the time we released our HTTPS report in February, 12 more of the top 100 websites have changed their serving default from HTTP to HTTPS.”

Google’s plan for identifying non-secure websites reveals that HTTP sites accessed by Chrome will still work, and that the company has no plans to block these sites within the browser. However, this plan mainly addresses the concerns of websites that have yet to transition to HTTPS, and lists ways sites can grab free and cheap keys (certificates) for setting up a secure connection. A number of set-up guides can be found here as well.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Google’s new Magic Pointer Play Store listing reveals a Gemini shortcut built for Googlebooks
The unannounced app turns the cursor into a contextual AI tool for search, image creation, and shopping
Plant, Text, Business Card

Google has quietly published a new Play Store listing for Magic Pointer, an unannounced app built for Googlebooks. Updated on July 10, the app turns the cursor into a Gemini shortcut that can act on whatever a user selects on screen.

Magic Pointer can send an image to Lens, generate a related image, or surface a shopping action without forcing users to open a separate chatbot. Regular Android devices currently show as incompatible, so the listing offers an early preview rather than a broad release.

Read more
You can stop using AI, but this new report says you probably can’t escape it
A UK survey found that most people feel AI exposure is unavoidable, raising harder questions about consent, privacy, and whether opting out is still realistic
AI Chatbots

More people are trying to use less AI, but avoiding it altogether may already be impossible.

A survey of 2,055 UK adults found that 42% deliberately limit how much AI they use. Another 70% said avoiding AI exposure would be difficult or impossible, even when they actively wanted less of it.

Read more
The face on an AI interviewer may matter as much as the decision it makes
Researchers found that race and gender matching changed how fairly rejected applicants viewed an automated interview, even though everyone received the same outcome
File, Computer Hardware, Electronics

An AI hiring system can treat every applicant the same and still leave some people feeling targeted. Researchers found that rejected candidates judged an automated interview differently depending on the race and gender of the avatar delivering the result.

Around 220 participants completed a simulated interview for a fictional customer support role with one of four photorealistic AI avatars. Everyone was rejected, yet perceptions of fairness shifted with the interviewer’s appearance. An algorithm audit could miss that reaction because candidates don’t experience the system as raw code. They experience a face asking questions and judging their answers.

Read more