Jump to content

Google is Proposing to Warn People their Data is at Risk Every Time Users Visit Websites That Do Not Use "HTTPS" System.

https everywhere

https-image.jpg

 

Google is proposing to warn people their data is at risk every time they visit websites that do not use the "HTTPS" system.The proposal was made by the Google developers working on the search firm's Chrome browser.

 

 

It will be a good thing for the whole web in the long run
                                                                                                                                                                  Paul Mutton Netcraft

Currently only about 33% of websites use HTTPS, according to statistics gathered by the Trustworthy Internet Movement which monitors the way sites use more secure browsing technologies.

 

there are three basic transport layer security states for web origins:

  1. Secure (valid HTTPS, other origins like (*, localhost, *));
  2. Dubious (valid HTTPS but with mixed passive resources, valid HTTPS with minor TLS errors);
  3. Non-secure (broken HTTPS, HTTP).

 

HTTPS uses well-established cryptographic systems to scramble data as it travels from a user's computer to a website and back again.

 

 

The team said warnings were needed because it was known that cyber thieves and government agencies were abusing insecure connections to steal data or spy on people.

 

Letting people know when their connection to a website is insecure could drive sites to adopt more secure protocols,In the short term, the biggest headache is likely to be faced by website operators who will feel forced to migrate unencrypted HTTP websites to encrypted HTTPS

 

 

2011-10-19-09-09-25-5809bb.jpg

 

Firefox's Browser based warning system

 

We all need data communication on the web to be secure (private, authenticated, untampered). When there is no data security, the UA should explicitly display that, so users can make informed decisions about how to interact with an origin.

 

 

 

this will be a very useful function if gets implemented , what are your thoughts on this? post your comments & rants down below..

 

Link: http://www.bbc.com/news/technology-30505970

        https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure

Details separate people.

Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.

×