Lots of websites — from Wikipedia to Reddit to the Washington Post — are moving towards encrypting all of their web traffic to protect their readers' privacy. We'll talk about what this all means (benefits, downsides) and problems we've encountered moving to HTTPS (and how we solved them).
31. Marking HTTP As Non-Secure
We, the Chrome Security Team, propose that user
agents (UAs) gradually change their UX to
display non-secure origins as affirmatively
non-secure. We intend to devise and begin
deploying a transition plan for Chrome in 2015.
The goal of this proposal is to more clearly display
to users that HTTP provides no data security.
32. Marking HTTP As Non-Secure
We, the Chrome Security Team, propose that user
agents (UAs) gradually change their UX to
display non-secure origins as affirmatively
non-secure. We intend to devise and begin
deploying a transition plan for Chrome in 2015.
The goal of this proposal is to more clearly display
to users that HTTP provides no data security.
33.
34. Deprecating Non-Secure HTTP
Today we are announcing our intent to phase out
non-secure HTTP.
There are two broad elements of this plan:
1. Setting a date after which all new features will be
available only to secure websites
2. Gradually phasing out access to browser
features for non-secure websites, especially
features that pose risks to users’ security and
privacy.
35. Deprecating Non-Secure HTTP
Today we are announcing our intent to phase out
non-secure HTTP.
There are two broad elements of this plan:
1. Setting a date after which all new features will be
available only to secure websites
2. Gradually phasing out access to browser
features for non-secure websites, especially
features that pose risks to users’ security and
privacy.
36. Deprecating Non-Secure HTTP
Today we are announcing our intent to phase out
non-secure HTTP.
There are two broad elements of this plan:
1. Setting a date after which all new features will be
available only to secure websites
2. Gradually phasing out access to browser
features for non-secure websites, especially
features that pose risks to users’ security and
privacy.
40. A Call to Action
If you run a news site, or any site at all, we’d like
to issue a friendly challenge to you. Make a
commitment to have your site fully on HTTPS by
the end of 2015 and pledge your support with
the hashtag #https2015.
—Eitan Konigsburg, Rajiv Pant and Elena Kvochko
“Embracing HTTPS”
November 13, 2014
109. Many graphics from The Noun Project
Mountains by Chris Cole; Statue of Liberty by John Melven; Tombstone by Jakob
Wells; Congress by Martha Ormiston; Shield by Wayne Thayer; Books by Ashley
van Dyck; Snail by aLf; carrot by Creative Stall; Geolocation by Alexander Smith;
Notification by vijay sekhar; Microphone by Edward Boatman; Video camera by
Pham Thi Dieu Linh; Full screen by Garrett Knoll; Rotation by Lemon Liu;
speedmeter by Michal Beno; layers by Muhamad Ulum; arrow by Maurizio
Pedrazzoli; stick by Blaise Sewell; Server by Yazmin Alanis; SEO by Azis; Money
by Nick Levesque; Shopping cart by Patrizia Daidone; Lock with keyhole by
Brennan Novak; Scribble by Michael Chanover; Network by Stephen Boak; Hat
based on work by Blake Kimmel. ; Warning by Icomatic; Error by Anas Ramadan.