3 ms·
Synthesis: Chrome Security Team would like to put :( for all non-secure HTTP connections. With gradual deployment, and increase of all active sites moving to H
by sdrinf 12y ago
Synthesis: Chrome Security Team would like to put :( for all non-secure HTTP connections. With gradual deployment, and increase of all active sites moving to HTTPS, it is assumed that users won't become trained to ignore this as a warning signal.
| Then, in the long term, the vendor might decide to represent non-secure origins in the same way that they represent Bad origins.
The biggest disadvantage of the proposal, as it stands in current CA climate, is that it's psychologically successfull deployment will impose a liability for site operators to touch their sites at least once per CA renewal timeframe. There are many sites where this isn't desired, feasable, or even possible at all, but which despite non-security, still serves giant heaps of high-quality information. So, this will increase SEO, and accessibility gap between sites run by geeks, and sites (attempted to) run by everyone else. Whether this is a desired future of the web is left to an exercise for the dear reader.
- icebraining 12y agoThe Let's Encrypt project will have a daemon that automatically renews the certificate.