HomeSecurityConcern about the rate of HTTPS usage in light of the new policy...

Concerns about HTTPS usage rate in light of Chrome's new policy

It's been almost 2 years since Google announced it would "mark" HTTP pages as "not secure" in version 56 of its Chrome browser. In February 2018, Emily Schechter, Chrome's security product manager, said in a blog post that it had helped users understand that HTTP websites were not secure by marking a large portion of HTTP pages as not secure, and with the release of version 68 of Chrome, the policy will be applied to all sites that have not yet migrated to HTTPS.

https chrome policy

This week marks the release of version 68. Two researchers collaborated, who, in order to emphasize how important it is for pages to have their own SSL certificates, conducted many tests on well-known sites, and posted the results on a new page.

https chrome policy

Troy Hunt, who has previously worked extensively on SSL and HTTPS protocols, and Scott Helme worked together on the research. Taking the most popular sites from the Alexa rankings service, they noticed that more than 38% of websites still use HTTP.

A similar study had been conducted in the past. The websites that were checked were again from the Alexa service. The 100 most popular sites (according to Alexa) from each country were checked, gathering a total of 12,363 results. The researchers again checked the same domains, believing that after so long the number of safe pages would have increased significantly.

In contrast, only 56 of the 12,363 addresses have changed the protocol they use. So the two researchers created whynohttps.com, where they posted the results broken down by country.

But what are the risks of our unencrypted internet traffic?

Helme explains that all traffic transmitted using HTTPcan be turned against the user. “Even though the page itself might be a static news page or something similar, a hacker could inject a malicious payload during transmission, and attack the user, unknowingly.”

Attacks that can be carried out through unencrypted traffic on a network range from unwanted advertisements, to cryptominers, keyloggers and even malware or phishing attacks.

Hunt also said he was surprised by the results of the study, and that he hopes that all of these sites' policies will change soon. While great progress has already been made in keeping Internet users safe, this study shows that we still have a long way to go.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS