Chrome Security Team Considers Marking All HTTP Pages As ‘Non-Secure’
Back in August, we noted that Google had started adjusting its search algorithm to give a slight boost to sites that are encrypted. That is, all else equal, sites that use HTTPS will get a slight ranking boost.
Context & Ripple Effects
This proposal lands six months after Google began adjusting its search ranking to slightly favor encrypted sites — the first time HTTPS carried a direct SEO incentive rather than a purely security one. Now the Chrome Security Team is weighing the stick to match that carrot: labeling every unencrypted page 'non-secure' directly in the browser.
The corpus shows the idea had legs. Chrome moved from consideration to visible warnings within about a year (flagging unencrypted sites with a red X over the padlock), then committed to marking all HTTP sites 'not secure' starting with Chrome 68 in July 2018 ([[a:926551]]), and by 2020 was tightening further with blocking of mixed content downloads on secure pages. By late 2017 Google could report roughly two-thirds or more of Chrome traffic on each major platform already protected.
First-order effects
- Site operators still serving plain HTTP face an immediate trust problem: a persistent browser warning on every page, independent of how their site actually ranks.
- Certificate authorities and hosting providers see demand shift, since switching to HTTPS becomes a UI-driven necessity rather than an optional hardening step.
Second-order effects
- Rival browser makers come under pressure to match Chrome's labeling, turning 'non-secure' badges into a cross-browser convention rather than one vendor's experiment.
- Advertising and analytics vendors whose tags run on unencrypted pages inherit the stigma, pushing publishers to migrate entire stacks — not just landing pages — to HTTPS.
Third-order effects
- Browsers consolidate their role as de facto web-security regulators: instead of standards bodies mandating encryption, the platform owner uses UI warnings and search signals to make HTTPS the default, with laggards progressively cut off as Chrome extends enforcement to mixed content.
- If the pattern holds, the distinction between 'secure' and ordinary web traffic disappears entirely — unencrypted delivery becomes the anomaly that requires justification.
The trend: Browser vendors are shifting from passive renderers to active security enforcers, using UI labels, search-ranking incentives, and staged blocking to push the web toward universal HTTPS.