Security Blog
The latest news and insights from Google on security and safety on the Internet
Simplifying the Page Security Icon in Chrome
13. Oktober 2015
Posted by Lucas Garron and Chris Palmer, Chrome security team
Sometimes, websites try to use HTTPS to be secure and get it mostly right, but they have minor errors. Until recently, Chrome marked this security state with a yellow “caution triangle” badge on the page security icon in the URL bar.
Starting with version 46, Chrome will mark the “HTTPS with Minor Errors” state using the same neutral page icon as HTTP pages.
There are two reasons for this:
This change is a better visual indication of the security state of the page relative to HTTP.
Chrome users will have fewer security states to learn.
(Not) Warning About Mixed Content
This change will mainly affect HTTPS pages that contain certain
mixed content
, such as HTTP images.
Site operators face a dilemma: Switching an HTTP site to HTTPS can initially result in mixed content, which is undesirable in the long term but important for debugging the migration. During this process the site may not be fully secured, but it will usually not be less secure than before.
Removing the yellow “caution triangle” badge means that most users will not perceive a warning on mixed content pages during such a migration. We hope that this will encourage site operators to switch to HTTPS sooner rather than later.
Fewer Security States
This change will reduce the number of page security states in Chrome from four to three.
We have to strike a balance: representing the security state of a webpage as accurately as possible, while making sure users are not overwhelmed with too many possible states and details. We’ve come to understand that our yellow “caution triangle” badge can be confusing when compared to the HTTP page icon, and we believe that it is better not to emphasize the difference in security between these two states to most users. For developers and other interested users, it will still be possible to tell the difference by checking whether the URL begins with “https://”.
In the long term, we hope that most sites on the internet will become secure, and we
plan
to reduce the icon to just two states: secure and not secure. The change announced in this post is a small step in that direction.
Keine Kommentare :
Kommentar posten
Labels
android
android security
android tr
app security
big data
biometrics
blackhat
chrome
chrome security
federated learning
Gboard
google play
google play protect
pha family highlights
privacy
Security
spyware
targeted spyware
vulnerabilities
Archive
2021
Feb
Jan
2020
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2019
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2018
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2017
Dez
Nov
Okt
Sep
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2016
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2015
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
Jan
2014
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Apr
Mär
Feb
Jan
2013
Dez
Nov
Okt
Aug
Jun
Mai
Apr
Mär
Feb
Jan
2012
Dez
Sep
Aug
Jun
Mai
Apr
Mär
Feb
Jan
2011
Dez
Nov
Okt
Sep
Aug
Jul
Jun
Mai
Apr
Mär
Feb
2010
Nov
Okt
Sep
Aug
Jul
Mai
Apr
Mär
2009
Nov
Okt
Aug
Jul
Jun
Mär
2008
Dez
Nov
Okt
Aug
Jul
Mai
Feb
2007
Nov
Okt
Sep
Jul
Jun
Mai
Feed
Follow @google
Follow
Give us feedback in our
Product Forums
.
Keine Kommentare :
Kommentar posten