Chrome will soon mark some HTTP pages as 'non-secure'

7 google chrome geralt zdnet eileen brown

Google plans to start the new year with a security message.

google-not-secure-pages.png

(Image: Google)

ADVERTISEMENT

Beginning next month, the company will tag web pages that include login or credit card fields with the message “Not Secure” if the page is not served using HTTPS, the secure version of the internet protocol.

The company on Tuesday began sending messages through its Google Search Console, a tool for webmasters, warning them of the changes that take place starting in January 2017.

The changes are supported in version 56 or later of the Chrome browser.

The move is a first step in a long-term plan to clearly mark as non-secure all HTTP sites regardless of their content. In upcoming releases of Chrome, for example, Google will label HTTP pages as “not secure” in Incognito mode.

There is no timeline for when webmasters are required to switch all their pages to HTTPS.

Googles plans go along with on-going efforts to motivate consumers and G Suite users to adopt more secure login methods.

HTTPS is designed to protect the integrity and the confidentiality of data as it moves between an end-user computer and a website. The protocol protects personal and other sensitive information such as login credentials.

The transmission is secured by the Transport Layer Security (TLS) protocol, which provides encryption, data integrity and authentication. The authentication piece, among other reasons, is designed to combat man-in-the-middle attacks and promote end-user trust in a website.

In a blog updated a few weeks ago, Google noted that it “recently hit a milestone with more than half of Chrome desktop page loads now served over HTTPS. In addition, since the time we released our HTTPS report in February, 12 more of the top 100 websites have changed their serving default from HTTP to HTTPS.”

Converting pages from HTTP to HTTPS comes with a few common pitfalls, such as not keeping certificates or TLS libraries up to date. Converts also may see temporary fluctuations in their site rankings.

Google wrote on its Google + page: “Enabling HTTPS on your whole site is important, but if your site collects passwords, payment info, or any other personal information, it’s critical to use HTTPS. Without HTTPS, bad actors can steal this confidential data. #NoHacked.”

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Supreme Court dismisses pleas for 100% VVPAT verification // MENA Debt Surge Raises Concerns for Global Economic Stability // World Intellectual Property Day: OPPO Maintains Top 10 Global IP Ranking for Fifth Consecutive Year // Saudi Arabia on Verge of Sending First Delegate to Miss Universe // Downpours in Oman and UAE Likely Amplified by Warming Planet // “Hello China, Sunshine Hainan” International Media Tour witnessed the evolution of Hainan’s tourism and culture // e& UAE Unveils Strategic Roadmap // Abu Dhabi Unveils Online Portal to Strengthen Healthcare Workforce // CapBridge Shares Insights on the Recent Launch of Digital Asset ETFs in Hong Kong // Ministry of Agriculture Supports Taiwanese Tea’s Entry into Singapore Market to Boost Global Presence // Oman Seeks Growth Through Strategic Economic Alliances // TPBank and Backbase Clinch ‘Best Omni-Channel Digital CX Solution’ at the Digital CX Awards 2024 // UN Commends Vietnam’s Progress on Climate Goals // Election Commission Of India Degrades Itself To Modi’s Own Commission // Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // World Football Federation Secures Sponsorship From Saudi Oil Giant // Forward Fashion’s Artelli Presents: Nobuyoshi Araki’s “Paradise” Starting from April 27th, at K11 MUSEA // AVPN Charts Path Forward at 2024 Global Conference // GE Jun, Chairman and CEO of TOJOY, Delivers an Inspiring Speech: “Leaping Ahead Again” // DIFC Courts Cement Role as Top English Dispute Resolution Choice //