Showing posts sorted by relevance for query https google. Sort by date Show all posts
Showing posts sorted by relevance for query https google. Sort by date Show all posts

05 August 2021

Coming soon: Google Chrome to no longer show secure website indicators

 

Google Chrome will no longer show whether a site you are visiting is secure and only show when you visit an insecure website.

For years, Google has been making a concerted effort to push websites into using HTTPS to provide a more secure browsing experience.

To further push web developers into only using HTTPS on their sites, Google introduced the protocol as a ranking factor. Those not hosting a secure site got a potentially minor hit in their Google search results rankings.

It has appeared to have worked as according to the 'HTTPS encryption on the web' of Google's Transparency Report, over 90% of all browser connections in Google Chrome currently use an HTTPS connection.

Currently, when you visit a secure site, Google Chrome will display a little locked icon indicating that your communication with the site is encrypted, as shown below:


As most website communication is now secure, Google is testing a new feature that removes the lock icon for secure sites. This feature is available to test in Chrome 93 Beta, and Chrome 94 Canary builds by enabling the 'Omnibox Updated connection security indicators' flag. With this feature enabled, Google Chrome will only display security indicators when the site is not secure.

www.bleepingcomputer.com


02 July 2018

Google shaming HTTP websites in Chrome - a lousy idea...


From Slashdot: Long-time software guru Dave Winer is criticizing Google's plans to deprecate HTTP (by, for example, penalizing sites that use HTTP instead of HTTPS in search results and flagging them as "insecure" in Chrome). 

Winer writes: A lot of the web consists of archives. Files put in places that no one maintains. They just work. There's no one there to do the work that Google wants all sites to do. And some people have large numbers of domains and sub-domains hosted on all kinds of software Google never thought about. Places where the work required to convert wouldn't be justified by the possible benefit. The reason there's so much diversity is that the web is an open thing, it was never owned....

If Google succeeds, it will make a lot of the web's history inaccessible. People put stuff on the web precisely so it would be preserved over time. That's why it's important that no one has the power to change what the web is. It's like a massive book burning, at a much bigger scale than ever done before.

"Many of these sites don't collect user data or provide user interaction," adds Slashdot reader saccade.com, "so the 'risks' of not using HTTPS are irrelevant." And Winer summarizes his position in three points:
The web is an open platform, not a corporate platform.
It is defined by its stability. 25-plus years and it's still going strong.
Google is a guest on the web, as we all are. Guests don't make the rules.

"The web is a social agreement not to break things," Winer writes. "It's served us for 25 years. I don't want to give it up because a bunch of nerds at Google think they know best."

HTTPS is great - it secures your connection to a web server: perfect for ecommerce, banking, data transfers, etc. HOWEVER: if a website is just supplying simple information, and there is no requirement for the visitor to input personal data or payment information - then what is the point of HTTPS?


09 February 2018

From July, Google Chrome will name and shame "insecure" HTTP websites. Oh dear: read in conjunction with yesterday's post...


Three years ago, Google's search engine began favoring in its results websites that use encrypted HTTPS connections.

Sites that secure their content get a boost over websites that used plain-old boring insecure HTTP. In a "carrot and stick" model, that's the carrot: rewarding security with greater search visibility.

Later this year comes the stick. This summer, Google will mark non-HTTPS websites as insecure in its Chrome browser, fulfilling a plan rolled out in September 2016.

Starting with Chrome 68, due to hit the stable distribution channel on July 2018, visiting a website using an HTTP connection will prompt the message "Not secure" in the browser's omnibox – the display and input field that accepts both URLs and search queries.

Well that's just great: Google will stop trusting Symantec-issued SSL/TLS certs from this year. One option would be to drop the certificate - going from HTTPS back to good old HTTP. Unfortunately this will now flag that website as insecure! Good job Google - you can go off people, you know...


07 July 2017

Padlock in the address bar is a good thing right? Not necessarily so...


Article 1 from The Register

Let's Encrypt plans to begin offering free wildcard certificates in January 2018, a move likely to make web security easier and a bit less costly for many organizations.

Announced in 2014 as an effort to enhance and accelerate online security, the public benefit certificate authority (CA) has been issuing free X.509 (TLS/SSL) certificates through an automated process that allows websites, given the technical requirements, to be accessed over encrypted HTTPS rather than the unprotected HTTP.

So: every site (including potentially scammers & crooks) can have a digital certificate: a padlock in the right hand side of the address bar.

Article 2 from the Google Chrome Help Forum:

QUESTION: When browsing to a secure site, I used to be able to click to the left of the URL where it shows the padlock and Secure icon and click 'details' which would bring a popout from the right side of my browser to view the certificate details.

Today it no longer provides this option and only says I'm on a secure connection and the only option is to select 'Learn More' which brings me to a page explaining the differences between Secure, Not Secure, etc.

ANSWER: To review the website's security certificate details, use: top-right Chrome Menu/three vertical dots ( ⋮ ) > More tools > Developer tools - Security panel  ( keyboard shortcut  Ctrl+Shift+I  or  F12 )

Now this has been bugging me for ages! I'm a big Google Evangelist, and don't moan about them often, but I have to criticise Google for this. Hiding this functionality away from users really doesn't help.

If you are using Google Chrome, on an HTTPS site, & would like to check who the CA (certificate authority) is: press the F12 button on your keyboard & a panel will appear in the right hand side of your browser window "Security Overview". 
Press the "View Certificate" button, to see who the CA is & then you can make a more informed decision as to  whether or not you TRUST the website.


UPDATE: Apparently this will be fixed (restored!) in Chrome v60. We are currently in v59, so coming soon folks! Stay safe out there!

08 February 2018

Is your website secured with a Symantec SSL Cert? Trouble looms ahead...


Tens of thousands of websites are going to find themselves labeled as unsafe unless they switch out their HTTPS certificate in the next two months.

Thanks to a decision in September by Google to stop trusting Symantec-issued SSL/TLS certs, from mid-April Chrome browser users visiting websites using a certificate from the security biz issued before June 1, 2016 or after December 1, 2017 will be warned that their connection is not private and someone may be trying to steal their information. They will have to click past the warning to get to the website.

This will also affect certs that use Symantec as their root of trust even if they were issued by an intermediate organization. For example, certificates handed out by Thawte, GeoTrust, and RapidSSL that rely on Symantec will be hit by Google's crackdown. If in doubt, check your cert's root certificate authority to see if it's Symantec or not.

Oh dear: Donline's SSL cert is a Symantec issued one. Thanks 1&1... 
Time to explore the options!


11 April 2017

Trust issues: Know the limits of SSL certificates


Certificate authorities (CAs) have given themselves a black eye lately, making it hard for users to trust them. Google stopped trusting Symantec after discovering the CA had mis-issued thousands of certificates over several years, and researchers found that phishing sites were using PayPal-labeled certificates issued by Linux Foundation’s Let’s Encrypt CA. Even with these missteps, the CAs play a critical role in establishing trust on the internet.

TLS/SSL certificates have a usability problem because web browsers mark all HTTPS websites as secure—and users have been trained to look for the padlock or the word “Secure” to determine the site’s legitimacy. Yet all that padlock or the word “Secure” indicate is that the communications is encrypted. It doesn’t say the owner has been validated. A site can be encrypted and still be unsafe because the owner has been spoofed by a phisher or other malevolent force.

In other words: just because the site that you are visiting has a padlock, don't automatically assume that it's kosher! 


21 November 2018

Using a free VPN? Why not skip the middleman and just send your data to President Xi Jinping?


Many popular free VPN apps are sketchy Chinese operations with dubious privacy policies, according to research.

Metric Labs' Top10VPN conducted a rare investigation into the ownership structure and responsiveness of top VPN providers who distributed their services on iOS and through Google's Play Store. 86 per cent are deemed to have substandard security policies that failed to disclose how the data was used. And 59 per cent are either Chinese-backed, or actually based in the People's Republic of China.

"It was often very challenging to verify who was actually behind these VPN apps, due to the great lengths companies went to in order to hide their ultimate ownership, and far beyond the means of the typical consumer to discover," concluded head of research Simon Migliano, who collated the data.

VPNs act kinda like a bridge: netizens' network traffic is routed through the VPN provider so that for all intents and purposes, each user appears on the internet at the location of the VPN's gateway. So, someone in the USA can use a VPN in the UK to appear as though they are using the web from Blighty. This obscures the true public IP address of the user. Also, connections to and from the user and the VPN are typically encrypted so if you're worried about your hotel or airport Wi-Fi being spied on, the VPN tunnel will mask it.

However, this means you place an enormous amount of trust in your VPN provider, which becomes effectively a second ISP. By carrying your network traffic, the VPN biz can potentially snoop on and tamper with your web browsing and internet activities. Websites and other online services that use HTTPS, or similar encryption, with mitigations to prevent man-in-the-middle eavesdropping can evade snooping VPNs.