New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 799156 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Feature
Team-Security-UX



Sign in to add a comment

"Your connection is not private" possibly should be "Your connection is not secure" instead

Reported by 93m4qau...@gmail.com, Jan 4 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. Open a site with invalid HTTPS.
2. See Chrome's "Your connection is not private" warning screen.
3. Think to yourself "I don't need it to be private".
4. Just click through it.
5. Later, forget that it was insecure and enter your credit card and make a transaction.

What is the expected behavior?
I think that "Your connection is not secure" might possibly be more influential than "Your connection is not private", because sometimes people think "I don't need it to be private".

What went wrong?
The "Your connection is not private" message sometimes causes people to just click through it and think "I don't need it to be private" even though it is a security issue and not just a privacy issue.

Did this work before? N/A 

Chrome version: 63.0.3239.132  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

I have actually witnessed someone do this, and I know they will not be the only one to do this.
 
Cc: sc00335...@techmahindra.com
Labels: -Type-Bug Needs-Triage-M63 Triaged-ET OS-Linux OS-Mac Type-Feature
Status: Untriaged (was: Unconfirmed)
93m4qau783@ Thanks for the issue.

From the original comment, looks like this is a feature request.

Hence marking this as Untriaged for further updates from Dev.

Thanks..
Components: Security
Components: -UI -Security UI>Browser>Interstitials
Status: WontFix (was: Untriaged)
Thanks for the suggestion. The strings on HTTPS error pages were chosen carefully and experimentally, so I don't think we'll be making changes to them without significant study and experimentation. Please see https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/43265.pdf for some more background.

Sign in to add a comment