Re: TLS everywhere has a major flaw and needs refining to the page level.

Peter Bowen <[email protected]> Fri, 16 Feb 2018 08:15:10 -0800
Newsgroups gmane.comp.mozilla.security
Message-ID <CAK6vND9VzAfkTpPfVzbrCJ1coANspGBWsm2nKzYOWfUmKbpqeQ@mail.gmail.com>
On Fri, Feb 16, 2018 at 3:34 AM, Kevin Chadwick via
dev-security-policy <[email protected]> wrote:
>
> On that subject I think the chromium reported plan to label sites as
> insecure should perhaps be revised to page insecured or something more
> accurate?

Given this group focused on Mozilla, it is likely out of scope to
discuss Chromium design.  I do suggest you look at
https://security.googleblog.com/2018/02/a-secure-web-is-here-to-stay.html
 It seems reasonably clear the marking is per top level page load.
This is very similar to the UI for Firefox which shows the lock (and
EV info) per top level page load.