Issue metadata
Sign in to add a comment
|
HTTPS redirects to HTTP are followed
Reported by
ralph.t...@gmail.com,
Mar 20 2017
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36 Steps to reproduce the problem: 1. Visit a page like https://cbs.com or https://fox.com or https://msnbc.com or https://cnbc.com 2. Watch the browser follow a redirect to an insecure page. 3. Die a little bit inside. What is the expected behavior? At a minimum I expect if I ask for a secure page to be warned if I am being sent to an insecure page. What went wrong? There was no warning or interruption to indicate my request for a secure connection was redirected to an insecure connection. Did this work before? No Chrome version: 56.0.2924.87 Channel: stable OS Version: OS X 10.10.5 Flash Version: Shockwave Flash 25.0 r0 I suggest either refusing to follow redirects from secure to insecure resources or presenting an interstitial display element to notify the user of the transition from a secure to insecure context.
,
Mar 20 2017
I was actively using every major browser in that time frame and yes, I remember the annoying popups "You are about to leave a secure connection!" The problem here is that Chromium is eroding the security posture for everyone if an HTTPS link is typed in or pasted and the user ends up in a non-secure environment. I'm certain the design needs to be revisited given the changes in HTTPS adoption and implementation since IE2. I wrote a longer essay on the subject here: https://medium.com/@ralphtice/the-impossibility-of-refuting-fake-news-in-mainstream-media-c2485cb72292#.ndhcp9ww8 I understand there are serious user experience ramifications for making any changes to the current flow. We also have quite serious issues of trust and authenticity. I originally became aware of this problem because of the AMP project, which more directly exposes whether pages fetched by the Google search engine are secure or not. The presence of HTTP in the request chain for mainstream media journalism means I have less confidence in both the cached content that Google is serving me as well as the confidence in the content served from the media organizations I described, which a large percentage of the Chromium user base relies on for facts. By opening this up for change (and please, escalate this as a UX concern rather than a direct security concern if you prefer to have) there is an opportunity to improve the trust in the Google brand and the brands of publishers who rely on Google for ad revenue and the brands of advertisers who purchase ad space on media properties. Thanks for your time & consideration.
,
Mar 23 2017
I can imagine such warnings being introduced in more specific circumstances than in early IE, and therefore being less intrusive. Say I manually type an https: address and it redirects to an http: address. In this situation I'm being explicit about my intent to use a secure connection, and would really like Chrome to tell me if that's not possible. A broader use might be to warn when navigating from secure to insecure within the same domain. Some websites (I think Amazon is an example) load over HTTPS if explicitly requested but then subsequent internal links go back to HTTP. I'm always upset when this happens. When navigating between domains, however, e.g. from a secure Google search to an insecure website, I would not expect a warning (this would indeed be annoying). And there was never a suggestion to warn when *entering* a secure area (which I believe early IE did). Can this be moved from security bug to UI feature request? |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Mar 20 2017Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)