New issue
Advanced search Search tips

Issue 832869 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security
Team-Security-UX



Sign in to add a comment

Not Secure Message is Misleading

Reported by bustyasi...@gmail.com, Apr 13 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.0 Safari/537.36

Steps to reproduce the problem:
Hi I was reading a blog from a Googler and there was a discussion about HTTPS/SSL Websites.

Basically everyone was saying that HTTPs is not secure - it is encrypted. Making a website HTTPs doesn't mean that it is secure.

Everyone was also saying that in Google Chrome the "Not Secure" message in grey is misleading and it should say "Not Encrypted" instead.

I just wondered if it was better to see in Google Chrome:

HTTPs = Green saying "Encrypted"

Non-HTTPs = Grey saying "Not Encrypted"

Dangerous = Red saying "Same message" 

What is the expected behavior?
Possible misleading label

What went wrong?
I just wondered if it was better to see in Google Chrome:

HTTPs = Green saying "Encrypted"

Non-HTTPs = Grey saying "Not Encrypted"

Dangerous = Red saying "Same message" 

Did this work before? N/A 

Chrome version: 67.0.3396.0  Channel: canary
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 
Status: WontFix (was: Unconfirmed)
Thanks for the report. You are correct in the fact that the "Secure" and "Not Secure" refers to the connection, and not to the content of the website. (As opposed to the "Dangerous" case, which is websites that were flagged as containing malware or phishing sites).

We are currently in the process of making changes to the security indicator, you can read a bit more about the changes planned here: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html, and a bit more abot the research behind the changes here: https://www.usenix.org/system/files/conference/soups2016/soups2016-paper-porter-felt.pdf
Components: UI>Browser>Omnibox>SecurityIndicators>VerboseChip
Labels: -Restrict-View-SecurityTeam allpublic
Thank you very much for the links and extra infomation.

Sign in to add a comment