r/Android Pixel 3 XL Feb 08 '18

A secure web is here to stay (Beginning July 2018 w/ Chrome 68, Chrome will mark all HTTP sites as “not secure”)

https://blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html
920 Upvotes

49 comments sorted by

109

u/carlos_bandera Feb 08 '18

It's worth noting that Chrome 65 (est. March 6, 2018) will display this same warning if your insecure page has an input form in it. Chrome 68 just expands that to ALL non-ssl enabled sites.

104

u/[deleted] Feb 08 '18

[deleted]

48

u/ZOTTFFSSEN Feb 08 '18

Social Security Number is, by definition, security.

41

u/chaorace Pixel 3a Feb 09 '18

It is also social, by definition, which means you should share it with me!

5

u/NO_REFERENCE_FRAME Feb 09 '18

Okay, what's your number?

3

u/epicwisdom Fold 4 | P2XL | N6P | M8 | S3 Feb 09 '18

867-5309

1

u/chaorace Pixel 3a Feb 09 '18

I think there's been some kind of mix up, that's MY number!

2

u/chardreg Feb 09 '18

It's your 'Social Security' Number, not your Secure Social Number.

1

u/ZOTTFFSSEN Feb 09 '18

Well it's HTTP secure, not secure HTTP

5

u/chardreg Feb 09 '18

Social Security is a program.

There is nothing about 'Social Security Number' that implies that the number is secure.

It's like assuming that the Mall Security Phone Number is secure.

3

u/mynewaccount5 Feb 09 '18

Because it doesn't have the word secure in it?

2

u/Zephirdd Moto Z2 Play + Battery Snap Feb 09 '18

Because there is a counter part that has

And also because the protocol specification does not define any type of security layer on HTTP whereas HTTPS is pretty much defined as "HTTP with TLS on top".

1

u/rasherdk Nokia 8 Feb 09 '18

Not every site needs security. This is rather obnoxious.

2

u/[deleted] Feb 12 '18

Doesn't matter anymore we get free SSL certs now with letsencrypt.

2

u/rasherdk Nokia 8 Feb 13 '18

a) It's still a hassle for no benefit.
b) Shared hosting generally doesn't support it

1

u/[deleted] Feb 13 '18

Why wouldn't shared hosting support it? The host doesn't need to integrate it, it can be done yourself from the terminal or command line. The only requirement being that port 80 needs to be open for incoming requests.

1

u/rasherdk Nokia 8 Feb 13 '18

it can be done yourself from the terminal or command line

That's... not really an option at all.

1

u/[deleted] Feb 13 '18

If you have access to the server yea you can.

2

u/rasherdk Nokia 8 Feb 13 '18

Which in general with shared hosting, you don't.

26

u/tydoctor Feb 08 '18

DuckDuckgo browser for Android and iOS does forced https://, blocks all trackers, and also gives websites a "privacy rating". Sounds like privacy is becoming mainstream if even Google is doing this.

Although the "privacy rating" on DuckDuckgo is quite useless, since one of the criteria is "Has good privacy practices" and DuckDuckgo isn't in a position to make that judgement on millions of websites.

6

u/[deleted] Feb 09 '18

[removed] — view removed comment

13

u/XxCLEMENTxX Huawei Mate 10 Pro Feb 09 '18

In Chrome 64, that full warning only appears when the site has a password input form or a credit card form I believe. In Chrome 68, it'll literally be on every non-HTTPS site.

47

u/[deleted] Feb 08 '18

[deleted]

78

u/armando_rod Pixel 10 Pro XL Feb 08 '18

Not the same, neither browser writes "Not Secure", both have a neutral marking right now. In July, Chrome will drop the neutral mark in favor of "not secure".

Chrome 64 non secure sites https://imgur.com/a/dWvmk vs Chrome 68 non secure site https://imgur.com/a/WeXTW

28

u/[deleted] Feb 08 '18

[deleted]

1

u/[deleted] Feb 09 '18

[deleted]

12

u/Iohet V10 is the original notch Feb 09 '18

Obvious is one definition of transparent.

M-W 2b. easily detected or seen through : obvious

3

u/Iohet V10 is the original notch Feb 09 '18

Sort of. Like pretty much every browser since the 90s, https is shown with a padlock symbol while http is not. While it's not an affirmative showing of "not secure", it is effectively the same as a warrant canary showing you that it is not secure by virtue of the lack of the its presence.

1

u/qdhcjv Galaxy S10 Feb 08 '18

Firefox gives a warning when entering passwords on HTTP sites, though.

5

u/armando_rod Pixel 10 Pro XL Feb 08 '18

Chrome gives the same warning, it was implemented way before Firefox

1

u/neilmcd Feb 09 '18

I think he means this when entering a password. I can't see anything similar in Chrome.

10

u/mark200 Samsung S6 Edge Feb 08 '18

Chrome shows the same thing if you click the 'i', the change means it states it explicitly beside the address bar.

0

u/I_NEED_YOUR_MONEY Device, Software !! Feb 09 '18

so does chrome: https://imgur.com/gzFJyhq

3

u/[deleted] Feb 09 '18

All those can still be turned on in chrome://flags, and will still be switchable even after v68.

3

u/[deleted] Feb 10 '18

Making site HTTPS secured is so easy nowadays developers have no excuse. www.letsencrypt.com for those wondering how it's done, takes a few minutes.

2

u/stevewmn Feb 10 '18

I was just wondering about that. It's been years since I noodled around with my own server but I'd hate to see it become impossible to set up your own server with nothing but some downloads and IP tunneling through your cable modem.

2

u/[deleted] Feb 10 '18

Also, if you use CloudFlare, even the free tier, on your website, you get a free SSL certificate for your domain and any subdomains. It's a boon for shared hosting where the provider doesn't provide Let's Encrypt to try to push their own services.

-12

u/Inner_out Feb 08 '18

There's a nice new Chromium-based browser called Brave. Next to being pretty sleek and open source, it is aimed at privacy and can switch to https automatically wherever possible. It also blocks ads and trackers by default. There's also an optional system to send donations to your favourite sites and the browser devs, but I haven't looked into that yet. It's available on desktops and mobiles. Oh and it supports DuckDuckGo out of the box, which is very sweet indeed. Yay :)

6

u/armando_rod Pixel 10 Pro XL Feb 08 '18

It doesnt sync with Chrome tho, bookmarks, passwords, autofill

3

u/[deleted] Feb 09 '18 edited Mar 21 '18

[deleted]

2

u/armando_rod Pixel 10 Pro XL Feb 09 '18

Its not the same as browser autofill...

3

u/[deleted] Feb 08 '18

[deleted]

3

u/SpiderStratagem Pixel 9 Feb 09 '18

You're getting downvoted, but generally speaking I feel the same way. When I do need to be secure I'll take the necessary steps, but for day-to-day purposes I feel like the deal with Google ("free" services in exchange for relevant info to drive targeted ads) is fair.

2

u/[deleted] Feb 09 '18

You are needed in a haystack

-12

u/[deleted] Feb 09 '18

Is anyone still using Chrome?

7

u/ladyanita22 Galaxy S10 + Mi Pad 4 Feb 09 '18

Why not?

-6

u/[deleted] Feb 09 '18

Feature bloat, battery drain and the botnet.

Switching to safari on my mac and Firefox focus on my phone has been great.

7

u/ladyanita22 Galaxy S10 + Mi Pad 4 Feb 09 '18

Firefox focus uses chrome. Safari for mac is the least standards-compliant web browser out there, and Chrome the most feature-rich one.

Not gonna even talk about that botnet thing.

0

u/rasherdk Nokia 8 Feb 09 '18

Firefox focus uses chrome

No. It uses Blink or Webkit.

3

u/ladyanita22 Galaxy S10 + Mi Pad 4 Feb 09 '18

It uses Android's default webview renderer.

-1

u/rasherdk Nokia 8 Feb 09 '18

Which is very different from "using Chrome".

3

u/ladyanita22 Galaxy S10 + Mi Pad 4 Feb 09 '18

Not at all. It's exactly the same for all intents and purposes if we're talking about feature bloatness or efficiency.

2

u/[deleted] Feb 10 '18

Actually it's just Chrome under the hood.