Re: Proposal: Marking HTTP As Non-Secure
Jens Engelke <[email protected]> Tue, 16 Aug 2016 08:56:42 +0000
| Newsgroups | gmane.comp.web.blink.devel,gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAAGsGv1eKXxUEV8B-S3Gt8jBEcDsY6jmT9tKw1N42zn99k+0XA@mail.gmail.com> |
I can image that there are concerns from content providers that there visitors might be scared by a visual indication of "non-secure". Even if these content providers offer their content via http:// and https:// a careless user is taken to http:// if he just enters the hostname in the URL bar as many consumers do. If browsers could default to https for "scheme-less" entries in the URL bar (and fall back to http:// if there is no response), then visiting a non-secure page is an explicit choice of the end user. These users would more likely expect (and be used to) visual indicators for non-secure. <[email protected]> schrieb am Di., 16. Aug. 2016 um 10:30 Uhr: > As both a user and sysadmin I really encourage this initiative. > > One way to implement this that I think would make non-secure site more > obvious and would enhance security would be to add a red border to any site > or frame that isn't secure. Hovering the mouse over the border could > identify what makes the site/frame non-secure. > > An option to disable the borders per site could be added in the site > permissions so that known sites wouldn't show the border and could be used > for sites where the border affects functionality. > > This should be a fairly simple function to code and I think it would be a > lot more noticeable than just the address bar notifications. I think user > education would be fairly easy too. -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].