Re: Proposal: Marking HTTP As Non-Secure

Jens Engelke <[email protected]> Tue, 16 Aug 2016 08:56:42 +0000
Newsgroups gmane.comp.web.blink.devel,gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <CAAGsGv1eKXxUEV8B-S3Gt8jBEcDsY6jmT9tKw1N42zn99k+0XA@mail.gmail.com>
I can image that there are concerns from content providers that there
visitors might be scared by a visual indication of "non-secure". Even if
these content providers offer their content via http:// and https:// a
careless user is taken to http:// if he just enters the hostname in the URL
bar as many consumers do.
If browsers could default to https for "scheme-less" entries in the URL bar
(and fall back to http:// if there is no response), then visiting a
non-secure page is an explicit choice of the end user. These users would
more likely expect (and be used to) visual indicators for non-secure.

<[email protected]> schrieb am Di., 16. Aug. 2016 um 10:30 Uhr:

> As both a user and sysadmin I really encourage this initiative.
>
> One way to implement this that I think would make non-secure site more
> obvious and would enhance security would be to add a red border to any site
> or frame that isn't secure. Hovering the mouse over the border could
> identify what makes the site/frame non-secure.
>
> An option to disable the borders per site could be added in the site
> permissions so that known sites wouldn't show the border and could be used
> for sites where the border affects functionality.
>
> This should be a fairly simple function to code and I think it would be a
> lot more noticeable than just the address bar notifications. I think user
> education would be fairly easy too.

-- 
You received this message because you are subscribed to the Google Groups "blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].