In April of last year, Google had contacted other browser manufacturers in an attempt to convince them to enhance the security of their users by blocking mixed content downloads.
Google's proposal was for browsers to block file downloads that occur over HTTP. Specifically, the blocking would apply when the file download starts from an site .
Now, Google has announced that it will implement this plan in the Chrome browser in the coming months.
Google says it blocks these types of downloads because they pose a risk to users' security and privacy. They could allow for a "man-in-the-middle" (MiTM) attack.
"Files sent via mixed content can carry malware from attackers who can gain access to users' banking transactions," Google said.
What exactly will Google block?
According to a timeline published by Google, the changes will begin rolling out in Chrome 83, which will be released in June. From then on, any new version of Chrome will block “dangerous downloads.”
However, Google will not block all HTTP downloads.
For example, the company won't block HTTP downloads coming from HTTP sites. The reason is that Chrome already warns users in this case. It lets them know that the site they're visiting is not secure by displaying "Not Secure" in the URL bar.
The goal is to block insecure downloads from sites that appear to be secure (HTTPS) but the downloads are not (loaded via HTTP).
According to Google, the presence of HTTPS in the site's URL deceives users into thinking that the download is also done via HTTPS. But in some cases, this is not the case.
Google wants to stop these cases.
The change won't happen overnight with the new version of Chrome. Google has published a six-step process during which HTTP downloads from HTTPS sites will be gradually blocked:
- Chrome 81 (March 2020): Chrome will display a warning about all mixed content downloads.
- Chrome 82 (April 2020): Chrome will warn about downloads of mixed executable files (e.g. .exe).
- Chrome 83 (June 2020): Chrome will block mixed executables and warn about mixed archives (.zip) and disk images (.iso).
- Chrome 84 (August 2020): Chrome will block mixed executables ,archives and disk images and will warn about all other mixed content downloads (except image, audio, video and text).
- Chrome 85 (September 2020): Chrome will warn about downloads of mixed image, audio, video, and text content and block all other downloads.
- Chrome 86 (October 2020): Chrome will block all mixed content downloads.
This is illustrated in the following image:
However, Google said it understands that in some controlled environments, such as intranets, mixed content downloads are not as risky. For these cases, there is a Google Chrome policy (InsecureContentAllowedForUrls) that will allow HTTP downloads in controlled environments.
Site administrators will be able to check whether their sites comply with this new policy via Google Chrome Canary . To do so, they will need to enable the following Chrome flag:
chrome://flags/#treat-unsafe-downloads-as-active-content


