Live data from Hacker News

Chrome will mark all HTTP sites as ‘not secure’ starting in July

theverge.com

121–130 of 143 posts

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#121
post #5

So, what is the Chromes team solution for local network devices like routers? Proxy it over the manufacturers server for a complete loss of any privacy and security, but hey, there is a green check mark then?

This change will only add the grey 'not secure' text to the address bar and not hinder functionality. So it is just less green and not more red as with invalid or self-signed certificates where you have to perform additional steps to continue.

For now..

Look at the trend. First it was just a small SEO bump.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#122
And yet they recently changed it so that if you name a text field username or password it will get filled in with the current user's info, even when it is an admin page where you create new users. There is no way to instruct Chrome to NOT autofill your credentials onto another user. They removed support for the HTML attributes ages ago and even removed the workaround (hidden fields with display: none that don't get used) developers used to prevent this behavior.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#124

Earlier quoted context omitted.

A few problems: 1. SSH's whining about first connection fingerprint trusting is needlessly petty and nobody actually checks the fingerprints, and in many cases they have no need to do so anyways. 2. Almost all cert errors a user will encounter in the real world are the fault of misconfiguration (wrong domain) or pathological/greed-driven behavior (expiration) rather than something that actually impacts the confidenti…

> A few problems: > 1. SSH's whining about first connection fingerprint trusting is needlessly petty and nobody actually checks the fingerprints, and in many cases they have no need to do so anyways. I disagree, but this is really a question of configured defaults and security UX. The first connection you make to a server is not secure, and impacts the security of all subsequent requests to that server. > 2. Almost a…

Interesting. I thought Safari in iOS would block it, but I guess that is just chrome still.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#125

Technical people should not be pushing centralization and vested interests, that's not a technical solution. In the a world of state surveillance and invasive data practices by SV based companies it's a difficult to understand this obsession with http scaremongering by some to perpetuate more centralization.

>it's a difficult to understand this obsession with http scaremongering Your surely meant it's not difficult, right? The first part of your sentence is exactly the answer.

Why would that be? Hn is full of people who do not like even essential bureaucracy, let alone an unneeded one. Yet when it comes to superfluous certificate authorities suddenly its ok? That does not make sense.

Everyone is concerned about centralization in other contexts but do not see the downsides of certificate centralization and control? How is it that there is no technical solution that does not involve 'authorities'?

This is how control works, first its innocuous and harmless - just get a cert, its even free from letsencrypt. Then after that is accepted its x,y,z. Then its x,y,z and your first newborn. And now you have a way to effectively prevent people from publishing and can silence dissent and anything you don't like under the cover of 'process'.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#126

And yet they recently changed it so that if you name a text field username or password it will get filled in with the current user's info, even when it is an admin page where you create new users. There is no way to instruct Chrome to NOT autofill your credentials onto another user. They removed support for the HTML attributes ages ago and even removed the workaround (hidden fields with display: none that don't get u…

Yup. I had to disable autofill entirely to stop obliterating users' data in an app I work with.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#127

Earlier quoted context omitted.

>it's a difficult to understand this obsession with http scaremongering Your surely meant it's not difficult, right? The first part of your sentence is exactly the answer.

Why would that be? Hn is full of people who do not like even essential bureaucracy, let alone an unneeded one. Yet when it comes to superfluous certificate authorities suddenly its ok? That does not make sense. Everyone is concerned about centralization in other contexts but do not see the downsides of certificate centralization and control? How is it that there is no technical solution that does not involve 'authori…

Wait, you don't see the obvious benefits of a local coffee shop page displaying its address and hours being served over an encrypted and secured connection?

Sarcasm aside, I think that the big organizations pushing for HTTPS everywhere also tend to employ a lot of people who visit HN; company culture does have an effect.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#128
post #92

Earlier quoted context omitted.

You're kidding right? Its 2018, there is no reason to not use https these days. With lets encrypt its not like its costing you anything.

Time is money. It takes time to set it up.

So does showering, and you do that before interacting with people outside right?

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#129
post #57

Earlier quoted context omitted.

Let’s push for self-signed certicates everywhere ! Let’s do Trust On First Use like SSH and now we’re done with all this certificates authorities bloated bureaucraties

But how am I supposed to know if I can trust it if it is the first time I am using it?

Check the pubkey fingerprint out of band, like you would do with ssh.

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#130

Earlier quoted context omitted.

What does it mean to fix a site that does not accept/process POST requests?

Start serving over https? Since when has encryption only mattered for POST?

Can you explain the benefit in other situations?

Preventing MitM attacks is the only thing I can think of.

Post reply on HN