Following Google's announcement of Chrome, the Mozilla Foundation is preparing two new options that will mark HTTP websites as "not secure" in the browser's address bar starting with Firefox 60 and all later versions of the browser.
It's clear that the HTTPS protocol is being promoted across the web, and that the major browser manufacturers support the idea.
As we mentioned earlier, Google announced this week that it plans to mark all HTTP sites as not secure starting with Chrome 68. The browser is scheduled to be released in mid-2018.
It's currently unclear when Firefox will start marking HTTP websites as not secure, but we do know that starting with version 60 of Firefox it will bring two options that will help with this functionality.
It should be noted that Firefox 60 will also be the next ESR (Extended Support Release) version.
Below you will see how you can configure these options (requires Firefox 60 or later):
Open the internal page:
about:config?=security.insecure_connection_text.enabled
Double-click on the option to enable it.
Open the internal page:
about:config?=security.insecure_connection_text.pbmode.enabled
Double-click on the option to enable it.
These settings will add the “not secure” flag to websites that use the HTTP protocol.
The pbmode.enabled setting will add the same flag to display “not secure” on pages using HTTP protocol in private browsing mode.
HTTPS adoption is expected to improve significantly in 2018, and one reason for this is that browser manufacturers will finally start marking HTTP pages as “not secure.”
So all website owners who want to have a decent and secure site should adopt HTTPS.
