Google has taken a major step towards improving web security in Chrome by automatically upgrading non-secure HTTP requests to HTTPS requests for 100% of users.
See also: Chrome: Fake update installs malware

This feature is called “HTTPS-Upgrades” and will protect old links that use https://by automatically attempting to connect to the URL via the encrypted https://.
A limited implementation of this feature in Google Chrome began in July, but as of October 16, Google has now made it available to all users on its Stable channel.
“Last week we automatically enabled HTTPS-Upgrades and are currently rolling it out to all stable releases,” reads the update from Google’s Engineering Program Manager, Chris Thompson.
The feature is a Google Chrome feature that automatically upgrades all major browsers to HTTPS, the secure version of the HyperText Transfer Protocol, ensuring a quick fallback to HTTP if necessary.
Historically, browsers have often made insecure HTTP requests to websites that could support HTTPS. Whether this is because users click on old links or because the content on the web pages has not been upgraded to use the new protocol, connections over the HTTP protocol are not encrypted and can be monitored to steal credentials or other sensitive data.
According to Google, this can also happen by loading HTTP resources from:
- A website using HSTS (HTTP Strict Transport Security) for the first time.
- Bypassing a site that defaults to HTTPS but does not use HSTS, or
- Visiting a website that supports both HTTPS and HTTP without automatic redirection to HTTPS.
In any case, user privacy and security are compromised through unnecessary insecure connections. This issue has been reported in various configurations and can affect many requests
See also: IP Protection: Google Chrome feature hides IP addresses
Existing methods for enforcing HTTPS, such as the HSTS default list or manually maintained upgrade lists, have limitations. They either require complex and questionable configuration, or serve a limited range of websites. Additionally, maintaining an up-to-date list of websites that support HTTPS can be challenging and bandwidth-intensive, often resulting in outdated information reaching users.

With this update, Chrome aims to automatically upgrade internal HTTP links to HTTPS, implementing a quick fallback mechanism to HTTP if needed.
While it limits exposure to passive attackers, active attackers can still thwart the upgrade process. Importantly, this change may reduce the incentive for developers to fix HTTP reports.
However, given the current trend of marking HTTP pages as “Not Secure”, this upgrade is a precautionary measure to protect users, especially on sites that are unlikely to be updated to HTTPS.
See also: Google Chrome: 6 ways to use it offline
Potential vulnerabilities in Google Chrome's login security features could include the threat of SSL certificate theft. This occurs when malicious users manage to gain access to valid SSL certificates and use them to impersonate legitimate websites. This can lead to fraud and theft of users' personal information.
Another potential vulnerability is the threat of malicious extensions. Google Chrome extensions can pose risks if not properly controlled. Malicious extensions can track user traffic, steal personal information, or prevent secure connections to websites.
Additionally, Man-in-the-Middle (MITM) attacks are another potential vulnerability. In these attacks , a malicious user intervenes between the user's connection and the website they are visiting. This attacker can monitor, alter, or steal information exchanged between the user and the website, posing serious threats to the security of the connections.
Finally, security vulnerabilities in Chrome's default settings can be a problem. If the settings are not configured correctly or are not implemented correctly, there may be vulnerabilities that would allow malicious users to intercept secure connections or access users' personal information.
Source: bleepingcomputer
