{"id":6819,"date":"2018-07-24T01:00:33","date_gmt":"2018-07-24T05:00:33","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6819"},"modified":"2020-11-24T10:24:49","modified_gmt":"2020-11-24T15:24:49","slug":"google-chrome-68-https-mandatory","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/google-chrome-68-https-mandatory\/","title":{"rendered":"Chrome 68 is out, all HTTP sites will now be marked \u201cNot Secure\u201d"},"content":{"rendered":"<h2>Google Chrome 68 makes HTTPS mandatory \u2013 have you installed an SSL certificate yet?<\/h2>\n<p>Today is the start of the roll out for <a href=\"https:\/\/www.thesslstore.com\/blog\/deadline-install-ssl-certificate-google-marks-not-secure\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google Chrome 68<\/a> \u2014 the version that makes HTTPS mandatory. This event has <a href=\"https:\/\/www.thesslstore.com\/blog\/not-secure-2017-time-get-ssl-https\/\" target=\"_blank\" rel=\"noopener noreferrer\">been on the horizon for two years<\/a>. I know this because I have been writing this same article for two years.<\/p>\n<p>But what\u2019s one more time? Starting today, Google will begin rolling out the stable version of Chrome 68. It\u2019s important to note that not every user will be on 68 right away. Owing to its massive user-base, Google tends to roll these updates out over the course of a week or two to ensure that everything releases smoothly. It also makes it easier to roll something back if it\u2019s implemented incrementally.<\/p>\n<p>So not everyone will be on Chrome 68 right out the gate, but make no mistake about it, starting today Chrome users are going to see some big changes.<span id=\"newline\"><\/span><\/p>\n<h2>What\u2019s changing in Chrome 68?<\/h2>\n<p>Starting today, any website still being served via HTTP will receive a negative visual indicator that says, \u201cnot secure\u201d beside the URL in Chrome\u2019s address bar.<\/p>\n<p>Here\u2019s an example of how the treatment for HTTP will change, using Chrome 64 (which has the current user interface) against Chrome 68.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6823\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Treatment-of-HTTP-Pages@1x.png\" alt=\"Google Chrome 68, HTTP\" width=\"640\" height=\"231\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Treatment-of-HTTP-Pages@1x.png 640w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Treatment-of-HTTP-Pages@1x-300x108.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Google plans to up the ante in future versions of Chrome, too. Soon, when someone attempts to input text into an HTTP page the warning will switch from black font to a more urgent shade of red.<\/p>\n<p>That\u2019s not all, either. Currently websites that are being served via HTTPS receive a positive indicator\u2014it says \u201cSecure\u201d with a little padlock icon in the space to the left of the URL in the address bar.<\/p>\n<p>But not for long. In a future release Google plans to eliminate the indicator for Domain Validated and Organization Validated SSL certificates entirely.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6820\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Security-Indicator-Google.png\" alt=\"Google Chrome 68, HTTPS\" width=\"640\" height=\"310\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Security-Indicator-Google.png 640w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Security-Indicator-Google-300x145.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h2>Why is Google making HTTPS mandatory?<\/h2>\n<p>It all comes down to the overall security of the web. HTTP has served its purpose but its fatal flaw is in its lack of security. Specifically, its lack of connection security. When an internet user\u2019s web browser arrives at an HTTP website, all of their communication with that site is sent in plaintext that can easily be intercepted and stolen. This is hardly ideal in a number of contexts, from online banking to healthcare to social media, so Google and the rest of the browsers a pushing to make better connection security a default for the entire internet.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<p>When you install an SSL\/TLS certificate and migrate your website to HTTPS, it facilitates encrypted connections, which keep the data being transmitted from being eavesdropped on or even manipulated.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-6824\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Https-Protocol-Secure-Networ-241573042-300x300.jpg\" alt=\"HTTPS\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Https-Protocol-Secure-Networ-241573042-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Https-Protocol-Secure-Networ-241573042-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Https-Protocol-Secure-Networ-241573042-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Https-Protocol-Secure-Networ-241573042.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>You may not have noticed, but most reputable businesses and organizations on the internet already use SSL\/TLS certificates and HTTPS. You can tell by the little green padlock beside the address bar. Some browsers also still show the protocol <a href=\"https:\/\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/<\/a> at the start of the URL, too.<\/p>\n<p>By requiring all websites to have encryption, it effectively eliminates an action that users would otherwise have to make in order to ascertain whether they have a secure connection with the website they\u2019re visiting. What? You don\u2019t already do that? Join the club. That actually bolsters Google and the other browser\u2019s position.<\/p>\n<p>Many users don\u2019t know what to look for to check connection security. Many users don\u2019t even know what connection security is at all. So asking them to check for a padlock or a protocol at the start of a URL is what Google calls \u201cactively hostile to the user.\u201d<\/p>\n<p>Personally, I think there\u2019s an air of hyperbole in that word choice, but Google aims to simplify connection security to the point where encryption and HTTPS is just standard and users don\u2019t have to worry about checking for it.<\/p>\n<p>You should probably still try to make sure you know who is running the site. Bad guys can get SSL and serve their <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-find-and-fix-mixed-content-warnings-on-https-sites\/\">sites over HTTPS<\/a>, too. But the days of checking visual indicators is over. That\u2019s why Google is retiring its \u201cSecure\u201d indicator. For one, I wouldn\u2019t say it was actively hostile, but it did confuse a lot of users into getting phished. But more importantly, when HTTPS is the default, there\u2019s no need to incentivize or reward websites for having it.<\/p>\n<p>The only time the user needs an indicator is when encryption is not present.<\/p>\n<h2>What do I need to do to avoid the wrath of Google?<\/h2>\n<p>Short of making some sort of symbolic offering following a pilgrimage to its palace in the Valley of Silicon, your best bet is to procure and install an SSL certificate immediately.<\/p>\n<p>The point of this article is to inform, so I\u2019ll be CA-agnostic and just say that there are a range of options for every site owner, depending on your size and scope. Everything from free Domain Validated certificates to Extended Validation certificates that showcase an organization\u2019s name in the address bar is available.<\/p>\n<p>Before you make a decision, it\u2019s probably a good idea to figure out what you need to encrypt, how many domains, sub-domains, etc. There are different certificate types for each budget and use-case. Just remember, every public-facing page and asset now needs to be served via HTTPS. You can use 301 redirects to point browsers to the correct HTTPS page.<\/p>\n<p>Just remember, choosing not to encrypt is choosing to have your website labeled \u201cNot Secure\u201d by Google, which owns the lion\u2019s share of the browser market. Also remember that internet users tend to trust Google when it tells them something isn\u2019t secure.<\/p>\n<p>So don\u2019t let that happen to you, encrypt today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Chrome 68 makes HTTPS mandatory \u2013 have you installed an SSL certificate yet? Today is the start of the roll out for Google Chrome 68 \u2014 the version that&#8230;<\/p>\n","protected":false},"author":6,"featured_media":6822,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[131,155,170],"class_list":["post-6819","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-google","tag-google-chrome","tag-https","post-with-tags"],"views":30359,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-Sankt-petersburg-Russia-Marc-2312479991.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6819"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6819\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6822"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}