<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google's decision to kill its 'Secure' URL label in Chrome in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10678#M970</link>
    <description>&lt;P&gt;It's all over Al Gore's amazing interwebs:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.techspot.com/news/74698-chrome-remove-ecure-label-https-sites-september.html" target="_blank"&gt;https://www.techspot.com/news/74698-chrome-remove-ecure-label-https-sites-september.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2018 11:31:10 GMT</pubDate>
    <dc:creator>Flyslinger2</dc:creator>
    <dc:date>2018-05-24T11:31:10Z</dc:date>
    <item>
      <title>Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10471#M939</link>
      <description>&lt;P&gt;According to multiple sources, Google has decided to simplify our lives again by removing "Secure" identifier in its Chrome browser for HTTPS sites protected, by what it deems, valid certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This development is very unwelcome, as I recall them trying this in one of the earlier iterations of their browser to dismay of many security professionals, when we could not readily lookup certificate data from the address bar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance, in my demo lab environment, I am using HTTPS inspection by the firewall/IPS/AV/Antibot/URL filtering and Application control device. Its certificate is installed in the domain's Trusted Root Certification Authorities. Therefore browser will see it as "Valid" and is presently indicating that the site is secure. But, importantly, it allows me to easily verify if the traffic is being inspected, or if it is allowed by the exceptions in the sites categorization:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="HTTPS Inspected and Bypassed Certificate Indicators" style="width: 847px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2396i0576892CFBC2047C/image-size/large?v=v2&amp;amp;px=999" role="button" title="HTTPS_Inspected_or_bypassed.png" alt="HTTPS Inspected and Bypassed Certificate Indicators" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HTTPS Inspected and Bypassed Certificate Indicators&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add to this Google's implementation of &lt;A href="https://en.wikipedia.org/wiki/QUIC" target="_self"&gt;QUIC protocol&lt;/A&gt;, which presently could not be inspected and it's payload analyzed, the unilateral initiative with certificate issuance log validation, and it feels like Google deliberately making the life of security specialists difficult.&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 18:02:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10471#M939</guid>
      <dc:creator>vt100</dc:creator>
      <dc:date>2018-05-20T18:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10504#M944</link>
      <description>&lt;P&gt;More of the same that I mentioned in another post regarding Google (Gorilla) flexing it's muscles and arbitrarily making a decision without peer review, involvement with organizations like the Internet Standards society or any other group that can logically and reasonably approve or disprove an action.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Google is way to big for its britches.&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 12:48:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10504#M944</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-05-21T12:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10651#M964</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/416071361"&gt;@vt100&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;According to multiple sources, Google has decided to simplify our lives again by removing "Secure" identifier in its Chrome browser for HTTPS sites protected, by what it deems, valid certificates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Are you able to cite any of those sources?&amp;nbsp; It's kind of hard to judge the veracity of a claim through anonymous sources.&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 19:54:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10651#M964</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-23T19:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10678#M970</link>
      <description>&lt;P&gt;It's all over Al Gore's amazing interwebs:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.techspot.com/news/74698-chrome-remove-ecure-label-https-sites-september.html" target="_blank"&gt;https://www.techspot.com/news/74698-chrome-remove-ecure-label-https-sites-september.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 11:31:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10678#M970</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-05-24T11:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10822#M1000</link>
      <description>&lt;P&gt;In concept, I do agree with Google's &lt;A href="https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html" target="_self"&gt;stance&lt;/A&gt;&amp;nbsp;"Users should expect that the web is safe by default, and they’ll be warned when there’s an issue&lt;SPAN&gt;."&amp;nbsp; However, I do hope they permanently learned that it is also necessary to give the users the ability to easily validate security settings.&amp;nbsp; Google forgot this in&amp;nbsp;Chrome&amp;nbsp;&lt;A href="https://www.thesslstore.com/blog/how-to-view-ssl-certificate-details-in-chrome-56/" target="_self"&gt;56&lt;/A&gt;&amp;nbsp;and relearned it in&amp;nbsp;&lt;A href="https://www.thesslstore.com/blog/enable-certificate-details-chrome-60/" target="_self"&gt;60&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;When this development effort was &lt;A href="https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure" target="_self"&gt;first announced&lt;/A&gt;, they did offer a selection of ways to provide feedback.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the QUIC protocol, it is easy to block.&amp;nbsp; I have yet to find anything that does not fall back to HTTP/HTTPS.&amp;nbsp; As QUIC gets more popular (currently, &lt;A href="https://w3techs.com/technologies/overview/site_element/all" target="_self"&gt;0.8%&lt;/A&gt;), I am confident that QUIC inspection abilities will equal that of HTTPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[edit: fixed incorrect reference]&lt;/P&gt;</description>
      <pubDate>Sun, 27 May 2018 22:12:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10822#M1000</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-05-27T22:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10825#M1001</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;I humbly disagree. We should never assume that the internet is safe and Google taking that position is only showing their&amp;nbsp;&lt;SPAN&gt;naiveté&lt;/SPAN&gt;&amp;nbsp;in understanding threats. Something we all were supposed to learn in CISSP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 May 2018 20:37:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10825#M1001</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-05-26T20:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10842#M1005</link>
      <description>&lt;P&gt;I don't think that anyone believes the Internet (as a whole) to be a safe place.&amp;nbsp; This is more about effectively communicating the relative security posture and risk of the &lt;STRONG&gt;site&lt;/STRONG&gt; being visited.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Studies (&lt;A href="https://www.usenix.org/system/files/conference/soups2016/soups2016-paper-porter-felt.pdf" target="_self"&gt;Usenix&lt;/A&gt;,&amp;nbsp; &lt;A href="http://commerce.net/wp-content/uploads/2012/04/The%20Emperors_New_Security_Indicators.pdf" target="_self"&gt;Harvard/MIT&lt;/A&gt;, &lt;A href="https://cups.cs.cmu.edu/soups/2013/proceedings/a6_Bravo-Lillo.pdf" target="_self"&gt;CMU&lt;/A&gt;) have backed up the theory that passive security indicators are not effective.&amp;nbsp; Fixing this requires being more "in your face"&amp;nbsp;about exceptional&amp;nbsp;concerns and avoiding &lt;A href="http://read.gov/aesop/043.html" target="_self"&gt;crying wolf&lt;/A&gt; about the routine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;A href="https://www.techspot.com/news/74698-chrome-remove-ecure-label-https-sites-september.html" target="_self"&gt;original&lt;/A&gt;&amp;nbsp;reference was lopsided in that it only mentioned&amp;nbsp;what the Chrome overlords were&amp;nbsp;taking away and ignored what was being added. Plenty of other sites (&lt;A href="https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html" target="_self"&gt;1&lt;/A&gt;, &lt;A href="https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure" target="_self"&gt;2&lt;/A&gt;, &lt;A href="https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html" target="_self"&gt;3&lt;/A&gt;, &lt;A href="https://www.wired.com/2016/11/googles-chrome-hackers-flip-webs-security-model/#slide-3" target="_self"&gt;4&lt;/A&gt;) have presented a more comprehensive picture of the happenings. Notably, In addition to removing&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secure.png" style="width: 60px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2418i6ACD4A88A025AA08/image-size/large?v=v2&amp;amp;px=999" role="button" title="secure.png" alt="secure.png" /&gt;&lt;/span&gt;&amp;nbsp;from HTTPS web sites, they will be adding&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="not secure.png" style="width: 60px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2416i3A88D4F8F9D7F812/image-size/large?v=v2&amp;amp;px=999" role="button" title="not secure.png" alt="not secure.png" /&gt;&lt;/span&gt;&amp;nbsp;to HTTP web sites and&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="! not secure.png" style="width: 60px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2417iF04EC66DD9E6A68D/image-size/large?v=v2&amp;amp;px=999" role="button" title="! not secure.png" alt="! not secure.png" /&gt;&lt;/span&gt;&amp;nbsp;to sites that have suspicious indicators (e.g. bad certificate or entering a password over HTML).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Effectively, they are changing the &lt;STRONG&gt;default&lt;/STRONG&gt; to warn about bad instead of praising what should be the norm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 May 2018 22:11:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10842#M1005</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-05-27T22:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10871#M1006</link>
      <description>&lt;P&gt;Sadly, I'm slammed at work with a big project and my personal life is ridiculous right now with anniversaries (35 for my wife and I), b-days out the wazzo and recent engagement by one of my offspring-busy.&amp;nbsp; I don't have the time to even scan these articles let alone really put some thought and effort into them since you did the same. Thank you for doing that.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 12:06:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10871#M1006</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-05-29T12:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10970#M1026</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case, thanks for raising the question (well, comment).&amp;nbsp; It inspired me to take a moment to write down what I had figured out so that others can (hopefully) benefit from it.&amp;nbsp; Like you,&amp;nbsp;my initial response was WTF.&amp;nbsp; It wasn't until I dug into it that things started to make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure that the tables will be turned in a few months and I will be the one slammed.&amp;nbsp; Hopefully, I too will be able to lean on the community when that happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 21:32:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10970#M1026</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-05-30T21:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10975#M1029</link>
      <description>&lt;P&gt;The WS at my customer location updated with the latest version of Chrome.&amp;nbsp; I'm a Firefox fan myself so I only use Chrome to follow their shenanigans.&amp;nbsp; I'd say 50% of the sites I visited using Chrome I got the "Not Secure" message, including some famous tech blogs!&amp;nbsp; &amp;nbsp;I also use Chrome because it handles 2FA better then FF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use Chrome Incognito and they are HTTP sites that I go to.&amp;nbsp; Ding #1.&lt;/P&gt;&lt;P&gt;The site could have a form somewhere* that Chrome/Incognito throws up about. Ding #2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Really? What if the site doesn't go to HTTPS until you authenticate in?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I contacted the webmasters for these sites.&amp;nbsp; I showed them the write-up you get if you press F12 and click on the caution icon.&amp;nbsp; You get sent to a Google blog detailing why this is a security issue.&amp;nbsp;&amp;nbsp;&lt;A href="https://security.googleblog.com/2017/04/next-steps-toward-more-connection.html" target="_blank"&gt;https://security.googleblog.com/2017/04/next-steps-toward-more-connection.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Their responses? LOL - what do you think it is?&amp;nbsp; I don't think Google's security posture is too widely known and it will upset more people then it will help in securing anything.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already gotten several emails and calls from my network of people that still depend on me for their IT consultant even though I haven't done that in a while.&amp;nbsp; They notice what Google is doing and are panicked that the website they have used for years is now not secure all of a sudden?&amp;nbsp; Yeah.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:14:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/10975#M1029</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-05-31T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Google's decision to kill its 'Secure' URL label in Chrome</title>
      <link>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/11035#M1034</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...panicked that the website they have used for years is now not secure all of a sudden...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;Many organizations, including Firefox (&lt;A href="https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/comment-page-1/#comments" target="_self"&gt;1&lt;/A&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blog.mozilla.org/security/2018/01/15/secure-contexts-everywhere/" target="_self"&gt;2&lt;/A&gt;, &lt;A href="https://blog.mozilla.org/security/2017/01/20/communicating-the-dangers-of-non-secure-http/" target="_self"&gt;3&lt;/A&gt;),&lt;SPAN&gt; &lt;A href="https://www.eff.org/encrypt-the-web-report" target="_self"&gt;EFF&lt;/A&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.w3.org/2001/tag/doc/web-https" target="_self"&gt;W3C&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are in on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;HTTP conspiracy.&amp;nbsp; Current versions of&amp;nbsp;Chrome, Firefox, Edge, Opera all&amp;nbsp;have similar cautions.&amp;nbsp; MSIE, not so much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firefox 60&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FF - 2018-05-31 14_53_12-BBC - Homepage.png" style="width: 375px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2436i4C44A99F51DCA76B/image-dimensions/375x188?v=v2" width="375" height="188" role="button" title="FF - 2018-05-31 14_53_12-BBC - Homepage.png" alt="FF - 2018-05-31 14_53_12-BBC - Homepage.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chrome 66&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chrome - 2018-05-31 14_56_30-BBC - Homepage.png" style="width: 378px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2435iF2E4141E0FC1D139/image-dimensions/378x157?v=v2" width="378" height="157" role="button" title="Chrome - 2018-05-31 14_56_30-BBC - Homepage.png" alt="Chrome - 2018-05-31 14_56_30-BBC - Homepage.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;HR /&gt;I don't think Google's security posture is too widely known &amp;nbsp;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The HTTPS push does seem to be&amp;nbsp;working --&amp;nbsp;&amp;nbsp;&lt;A href="https://transparencyreport.google.com/https/overview?hl=en" target="_self"&gt;75%-88%&lt;/A&gt;&amp;nbsp;of web traffic today is https, up from&amp;nbsp;&lt;A href="https://nakedsecurity.sophos.com/2016/10/18/halfway-there-firefox-users-now-visit-over-50-of-pages-via-https/" target="_self"&gt;50%&lt;/A&gt;&amp;nbsp;19 months ago and &lt;A href="https://blog.mozilla.org/security/2017/01/20/communicating-the-dangers-of-non-secure-http/" target="_self"&gt;38%&lt;/A&gt; 33 months ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 20:23:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Google-s-decision-to-kill-its-Secure-URL-label-in-Chrome/m-p/11035#M1034</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-05-31T20:23:38Z</dc:date>
    </item>
  </channel>
</rss>

