Stories
Slash Boxes
Comments

SoylentNews is people

posted by hubie on Saturday May 06, @05:00AM   Printer-friendly

Google will remove secure website indicators in Chrome 117:

Google announced today that the lock icon, long thought to be a sign of website security and trustworthiness, will soon be changed with a new icon that doesn't imply that a site is secure or should be trusted.

While first introduced to show that a website was using HTTPS encryption to encrypt connections, the lock symbol is no longer needed given that more than 99% of all web pages are now loaded in Google Chrome over HTTPS.

These also include websites used as landing pages in phishing attacks or other malicious purposes, designed to take advantage of the lock icon to trick the targets into thinking they're safe from attacks.

"This misunderstanding is not harmless — nearly all phishing sites use HTTPS, and therefore also display the lock icon," Google said.

[...] The lock icon will be changed in Chrome 117 with a "variant of the tune icon," a user interface element commonly linked to app settings and designed to show that it's a clickable item.

[...] This move was first announced almost two years ago, in August 2021, when the company revealed that secure website indicators are no longer needed and would be removed from Google Chrome's address bar since over 90% of connections are made over HTTPS.

​"When HTTPS was rare, the lock icon drew attention to the additional protections provided by HTTPS. Today, this is no longer true, and HTTPS is the norm, not the exception, and we've been evolving Chrome accordingly," Google said.

[...] It's worth noting that Google Chrome will continue to alert users of insecure plaintext HTTP connections on all platforms.


Original Submission

 
This discussion was created by hubie (1068) for logged-in users only. Log in and try again!
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by GloomMower on Sunday May 07, @12:49PM

    by GloomMower (17961) on Sunday May 07, @12:49PM (#1305121)

    > And my point is, if you can't tell easily whether the traffic is truly encrypted or not on port 443, you can bet your ass they'll start using it again.

    So, right now if you go to a http website a big warning icon shows. I doubt that is going away, only the lock when it is https.

    So the strategy is, be minimal when https which is 90% of websites, and show warning when http.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2