Chrome Security Team Proposes Marking HTTP Sites As 'Non-Secure'

Latest Videos FromTom's Hardware
TOPICS
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • ralanahm
    this page is non-
    http://www.tomshardware.com/news/chrome-security-http-non-secure,28223.html
    Reply
  • spdragoo
    The problem is that you only need an "https" site if you're going to be logging into it: online banking, online billpay, email, social networks, etc.

    If all you're doing is visiting a site to read articles or reference information, then you don't need a "secure" website, because you're not logging into an account that needs to be secured.
    Reply
  • dennisfyfe
    The problem is that you only need an "https" site if you're going to be logging into it: online banking, online billpay, email, social networks, etc.

    If all you're doing is visiting a site to read articles or reference information, then you don't need a "secure" website, because you're not logging into an account that needs to be secured.

    Might help to read the ENTIRE article.

    "After the Snowden revelations, we know that HTTP is indeed non-secure, and spy agencies from all over the world can not only intercept and spy on that HTTP traffic, but they can also send malware through it."
    Reply
  • dthx
    The problem is that you only need an "https" site if you're going to be logging into it: online banking, online billpay, email, social networks, etc.

    If all you're doing is visiting a site to read articles or reference information, then you don't need a "secure" website, because you're not logging into an account that needs to be secured.

    Might help to read the ENTIRE article.

    "After the Snowden revelations, we know that HTTP is indeed non-secure, and spy agencies from all over the world can not only intercept and spy on that HTTP traffic, but they can also send malware through it."
    It is equally easy to send malware through an https website than through an http website. In fact, in many cases, it even further increases your chances of getting the malware delivered to the right computer as the encryption makes it impossible for some firewalls to analyze the traffic (SSL interception is possible on decent firewalls but often not configured in many companies).
    I understand that SSL makes spoofing more difficult, but don't tell me that government agencies have no possibility to obtain the certificates they need for their mission ;-)
    Reply
  • Vilepickle
    Google better start offering SSL certs for free then.
    Reply
  • Wait what? Is there any reason why a read-only portfolio site for example, needs HTTPS?
    As someone said above, best get handing out those certificate's Google, that stuff's expensive.
    Reply
  • gmuser
    Speaking of HTTPS, does Tomshardware work on https?

    https://www.tomshardware.com seems not to work for me.
    Reply
  • mradamdavies
    This is retarded. I really don't like the direction in which Chrome is moving. The following statement makes no sense at all... "we know that HTTP is indeed non-secure" Kind of a non sequitur. HTTPS doesn't ensure security but is one aspect thereof. They should focus on marking compromised sites and not targeting those that can't afford to, or prohibited by technical limitations.

    Should my comment have been Tom's Hardware isn't HTTPS?!?!?!?!?1one... OMG, I got haxored!"
    Reply