{"id":6454,"date":"2018-05-17T17:19:47","date_gmt":"2018-05-17T21:19:47","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6454"},"modified":"2023-04-10T16:51:03","modified_gmt":"2023-04-10T20:51:03","slug":"google-will-remove-the-secure-indicator-in-september","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/google-will-remove-the-secure-indicator-in-september\/","title":{"rendered":"Google will remove the &#8220;Secure&#8221; indicator in September"},"content":{"rendered":"<h2>Eventually Google plans to remove the padlock icon from its UI, too.<\/h2>\n<p>In a <a href=\"https:\/\/blog.chromium.org\/2018\/05\/evolving-chromes-security-indicators.html\" target=\"_blank\" rel=\"nofollow noopener\">blog post<\/a> made on Thursday, Google announced that it will be removing the &#8220;Secure&#8221; indicator from its address bar in September with the release of Chrome 69. This is a move that was desperately needed.<\/p>\n<blockquote>\n<p>HTTPS usage on the web has <a href=\"https:\/\/transparencyreport.google.com\/https\/overview\" target=\"_blank\" rel=\"nofollow noopener\">taken off<\/a> as we\u2019ve evolved Chrome security indicators. Later this year, we\u2019ll be taking several more steps along this path. Users should expect that the web is safe by default, and they\u2019ll be warned when there\u2019s an issue. Since we\u2019ll soon <a href=\"https:\/\/security.googleblog.com\/2018\/02\/a-secure-web-is-here-to-stay.html\" target=\"_blank\" rel=\"nofollow noopener\">start marking<\/a> all HTTP pages as \u201cnot secure\u201d, we\u2019ll step towards removing Chrome\u2019s positive security indicators so that the default unmarked state is secure. Chrome will roll this out over time, starting by removing the \u201cSecure\u201d wording and HTTPS scheme in September 2018 (Chrome 69).<\/p>\n<\/blockquote>\n<p>As we have stated before, <a href=\"https:\/\/www.thesslstore.com\/blog\/eliminating-secure-dv-ssl-indicator\/\" target=\"_blank\" rel=\"noopener\">the &#8220;Secure&#8221; indicator in Google&#8217;s UI was never a good idea<\/a>. Though it was well-intentioned, proposed as a way to incentivize switching to HTTPS, <a href=\"https:\/\/www.thesslstore.com\/blog\/browsers-helping-https-phishing\/\" target=\"_blank\" rel=\"noopener\">it has instead made phishing websites more effective<\/a> by adding a &#8220;secure&#8221; label in the address bar despite the site&#8217;s nefarious nature. <a href=\"https:\/\/www.thesslstore.com\/blog\/1-4-million-new-phishing-websites-created-every-month\/\" target=\"_blank\" rel=\"noopener\">Phishing has never been more rampant<\/a>. Now it seems that Google has gotten enough buy-in to remove the indicator, which should help deal a blow to phishers the world over. <span id=\"newline\"><\/span><\/p>\n<p>The new UI will look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6455\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Google-UI.png\" alt=\"Google removing Secure indicator from UI\" width=\"640\" height=\"310\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Google-UI.png 640w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Google-UI-300x145.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>If you&#8217;ll notice Google has also eliminated the protocol at the beginning of the URL. It used to start with &#8220;https:\/\/&#8230;,&#8221; that will now be omitted.<\/p>\n<p>Emily Schecter, a Google Product Manager handling Chrome Security (<a href=\"https:\/\/blog.chromium.org\/2018\/05\/evolving-chromes-security-indicators.html\" target=\"_blank\" rel=\"nofollow noopener\">and one of the authors of today&#8217;s Chromium blog post<\/a>), recently gave a keynote that discussed some of the reasons Google has decided to drop the protocol and simplify what it displays in Chrome&#8217;s address bar. You can watch it below.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/UD-ukjVoeLc?rel=0\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>Additionally, starting in Chrome 70, which will release in October, Google will begin adding a more intense &#8220;Not Secure&#8221; indicator whenever you start entering text into an HTTP page.<\/p>\n<p>It&#8217;s likely that Mozilla and the other browser vendors will follow suit in the coming months.<\/p>\n<p>This new neutral UI means that Extended Validation will be only the kind of SSL certificate that receives any kind of indicator. And who knows how long that will stick around for. Many non-CA members of the CAB Forum have been discussing removal of the EV indicator for years.<\/p>\n<p>As always, we&#8217;ll keep you posted as more develops.<\/p>\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>Eventually Google plans to remove the padlock icon from its UI, too. In a blog post made on Thursday, Google announced that it will be removing the &#8220;Secure&#8221; indicator from&#8230;<\/p>\n","protected":false},"author":6,"featured_media":6456,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[131,166,7339],"class_list":["post-6454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-google","tag-phishing","tag-secure-ui","post-with-tags"],"views":27919,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Internet-Security-6049171.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6454"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6454\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6456"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}