{"id":6507,"date":"2018-05-30T14:15:12","date_gmt":"2018-05-30T18:15:12","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6507"},"modified":"2023-04-10T11:41:22","modified_gmt":"2023-04-10T15:41:22","slug":"google-negative-security-indicators","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/google-negative-security-indicators\/","title":{"rendered":"Negative Security Indicators: Sign(s) of the Things to Come"},"content":{"rendered":"<h2>Brace yourself. Negative SSL indicators are coming!<\/h2>\n<p>We\u2019re now less than 60 days away from witnessing something remarkable. You know what we\u2019re talking about, don\u2019t you? On July 24, <a href=\"https:\/\/www.thesslstore.com\/blog\/deadline-install-ssl-certificate-google-marks-not-secure\/\" target=\"_blank\" rel=\"noopener\">Google Chrome, the most popular browser on the planet, will flag every website that doesn\u2019t have SSL\/TLS encryption<\/a>. Some view this move as Google\u2019s last throw of the dice in its crusade against HTTP. However, contrary to this belief, a whole new game is about to kick off. This game will eradicate all the positive security indicators (such as the \u201csecure\u201d text &amp; padlock icon) and will introduce penalizing negative security indicators instead.<span id=\"newline\"><\/span><\/p>\n<h3>So, Why Is Google Doing This?<\/h3>\n<p>To understand this, we&#8217;d have to time-travel a bit. If you remember, at 2014 Google I\/O, Google announced its campaign to encrypt the entire web\u2014HTTPS Everywhere. Since then, Google has repeatedly cracked down on the use of HTTP. As a result of such efforts (and other factors), <a href=\"https:\/\/transparencyreport.google.com\/https\/overview?hl=en\" target=\"_blank\" rel=\"nofollow noopener\">the usage of HTTPS has reached unprecedented heights<\/a>. So much so that Google believes that web users should expect HTTPS by default and the sites that are not HTTPS-secured should be reprimanded.<\/p>\n<p>This is what Emily Schechter posted on Chrome\u2019s official blog:<\/p>\n<blockquote><p><em>&#8220;Users should expect that the web is safe by default, and they&#8217;ll be warned when there&#8217;s an issue. Since we&#8217;ll soon start marking all HTTP pages as &#8220;not secure,&#8221; we&#8217;ll step towards removing Chrome&#8217;s positive security indicators so that the default unmarked state is secure.&#8221;<\/em><\/p><\/blockquote>\n<p>To put this all in simple words, websites needed some incentivization from browsers so that the usage of HTTPS could proliferate. But now that HTTPS is close to becoming a standard, Google feels no need for such incentives in the form of positive indicators and will now be turning to negative security indicators instead.<\/p>\n<p>To be fair, Google is doing the right thing with this move. More often than not, the positive indicators are misleading to ordinary users. On seeing the \u201cSecure\u201d text and padlock, most internet users would believe the site to be secure, but it\u2019s only encrypted in reality. This is especially true in case of DV SSL certificate and its visual indicators<a href=\"https:\/\/www.thesslstore.com\/blog\/symantec-spoof-dv-ssl-visual-indicator\/\" target=\"_blank\" rel=\"noopener\">. DV SSL indicators are too strong<\/a> and often the main ingredient in a successful phishing scam.<\/p>\n<p>Now that SSL certificates have become free and installing them is pretty straightforward, more and <a href=\"https:\/\/www.thesslstore.com\/blog\/browsers-helping-https-phishing\/\" target=\"_blank\" rel=\"noopener\">more sites have started using HTTPS-enabled sites to dupe users into phishing scams<\/a>. Due to the lack of awareness, many fall for it.<\/p>\n<p>Now there are two ways in which this could be curbed: by spreading awareness or by eliminating misleading positive indicators and replacing them with even more obvious negative security indicators. As good as the first option is, it&#8217;s mightily difficult to teach everyone about URLs, SSL, encryption, and phishing. Google was always going to go with the second option.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h3>So, No More Padlock?<\/h3>\n<p>No (eventually).<\/p>\n<p>Ultimately, Google aims to establish HTTPS as a norm, and the way it&#8217;s going to do is not attaching any positive signs pertaining to HTTPS or encryption and penalizing the exceptions (HTTP sites). So, the \u201cSecure\u201d text and the padlock sign will soon be a thing of the past. With the launch of Chrome 69 in September 2018, the \u201cSecure\u201d text will be gone. The next step would be removing the padlock sign that will mark a milestone in establishing HTTPS as a norm.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6508 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Chrome-Warnings.png\" alt=\"Negative Security Indicators: Sign(s) of the Things to Come\" width=\"640\" height=\"310\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Chrome-Warnings.png 640w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Chrome-Warnings-300x145.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h3>Negative Security Indicators to Get Even More Negative<\/h3>\n<p>Chrome 62, released in October 2017, introduced a new negative security indicator that warned users when they typed anything in a non-HTTPS website. Here\u2019s how it looks:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6509 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/http-search.gif\" alt=\"Negative Security Indicators: Sign(s) of the Things to Come\" width=\"1016\" height=\"744\" \/><\/p>\n<p>This warning was intended to discourage users from typing anything or giving away their details when the connection isn\u2019t secure. Chrome 70, to be released in October 2018, is set to make this warning even more negative\u2014more noticeable in other terms. After the introduction of Chrome 68, when every HTTP site will be marked as &#8220;Not Secure,&#8221; Google will need some other negative security indicator when one types in something on an HTTP page as the \u201cNot Secure\u201d sign is there as a default. This will be done with the cunning use of the color red. Here&#8217;s how it looks:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6510 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/Treatment-of-HTTP-Pages-with-User-Input.gif\" alt=\"Negative Security Indicators: Sign(s) of the Things to Come\" width=\"544\" height=\"338\" \/><\/p>\n<p>As you can see, the red warning is much angrier than the current one\u2014behold, the power of red.<\/p>\n<h3>What Happens to EV Certificates and Green Address Bar?<\/h3>\n<p>Let&#8217;s just say that the omens don&#8217;t look good right now for the EV fans\u2014including me.<\/p>\n<p>First, Google doesn\u2019t see EV SSL certificate as a viable solution to phishing attacks. Emily Schechter, Product Manager, Chrome Security even said at the Loco Moco Sec conference that \u201cEV isn\u2019t a good defense against phishing attacks.\u201d This may seem to be just another statement, but it&#8217;s not. Many experts view EV SSL certificates as a good counter-measure against phishing and social engineering attacks. To be fair, the authentication is the only thing that separates an EV cert from the rest. However, Google seems to have other ideas. This perspective of Google\u2014whether right or not\u2014will inevitably get reflected in the upcoming versions of Chrome and you know what? <a href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=803501\" target=\"_blank\" rel=\"nofollow noopener\">It\u2019s already started<\/a>.<\/p>\n<p>Google Chrome now incorporates a flag (chrome:\/\/flags\/#simplify-https-indicator) that allows users to disable the EV indicator\u2014the green address bar. This tells us that the Chrome team is working (or at least thinking) on removing the EV indicator.<\/p>\n<p>I realize that&#8217;s a really depressing note to end this section on, so he&#8217;s a picture of a hamster in a sweater.<\/p>\n<figure id=\"attachment_6511\" aria-describedby=\"caption-attachment-6511\" style=\"width: 750px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6511 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/hamster-in-a-sweater.jpg\" alt=\"Negative Security Indicators: Sign(s) of the Things to Come\" width=\"750\" height=\"421\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/hamster-in-a-sweater.jpg 750w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/hamster-in-a-sweater-300x168.jpg 300w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><figcaption id=\"caption-attachment-6511\" class=\"wp-caption-text\">All hail the SEO hamster!<\/figcaption><\/figure>\n<h3>Final Thoughts<\/h3>\n<p>Flagging all HTTP sites, removing the secure sign, tinkering with the EV UI\u2026all of this tells us that Google thinks the usage of HTTPS is close to becoming a norm. In other words, Google, in its eyes, has succeeded in its &#8220;Encryption Everywhere&#8221; campaign. That&#8217;s why it no longer feels the need to incentivize sites to propagate HTTPS. Instead, it wants to treat HTTP sites as exceptions and reprimand them with negative security indicators.<\/p>\n<p>Another thing that Google wants to focus upon is the user experience. As most internet users feel safe seeing the \u201cSecure\u201d sign in Chrome, many fall prey to scams and frauds as many phishers now hide behind the curtain of free and DV SSL\/TLS certs.<\/p>\n<p>To counter such attempts, many see high assurance certs (OV and EV) as a solution because of the validation process that they require. However, Google\u2014as it seems right now\u2014doesn\u2019t seem to be agreeing with it. Even the EV certs, the ones that require a rigorous validation process, are not good enough for Google against phishing scams. So, if EV certs are not good enough, no SSL cert is. Therefore, I\u2019m assuming that Google sees SSL certs only as means to provide encrypted connections, nothing else. On the grounds of this, in the future, Google *could* treat all encrypted sites equally\u2014whether secured through DV, OV or EV.<\/p>\n<p>Needless to say, such radical changes will have some serious impact in the SSL industry. However, we can only sit on the sidelines and play the guessing game. The real game is in the hands of the mighty Google, and it can change its rules anytime it wants!<\/p>\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n","protected":false},"excerpt":{"rendered":"<p>Brace yourself. Negative SSL indicators are coming! We\u2019re now less than 60 days away from witnessing something remarkable. You know what we\u2019re talking about, don\u2019t you? On July 24, Google&#8230;<\/p>\n","protected":false},"author":10,"featured_media":6512,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[131,170],"class_list":["post-6507","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-google","tag-https","post-with-tags"],"views":14690,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Hand-Holds-A-Cube-With-The-Let-236198398.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6507"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6507\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6512"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}