Mozilla wants to deprecate non-secure HTTP, will make proposals to W3C ‘soon’
Mozilla today announced its intent to phase out non-secure HTTP, and that it will be making some proposals to the W3C WebAppSec Working Group soon. Specifically, the company says it is committed to …
Context & Ripple Effects
Mozilla's announcement formalizes what had been brewing since late 2014, when the Chrome Security Team first floated marking every HTTP page as non-secure. By taking its case to the W3C WebAppSec Working Group rather than acting unilaterally in Firefox, Mozilla is trying to turn a single-browser UI change into an agreed web standard.
The move fits an escalating sequence of coordinated crypto removals across browsers: Google, Microsoft, and Mozilla already committed to dropping RC4 from Chrome, Edge, IE, and Firefox, and by 2018 all four vendors would announce a unified early-2020 plan to deprecate TLS 1.0 and 1.1. Plain HTTP is the logical endpoint of that trajectory.
First-order effects
- Operators of sites served over plain HTTP face direct pressure to obtain certificates and migrate to HTTPS or risk their pages being labeled non-secure in Firefox.
- The W3C WebAppSec Working Group becomes the decision arena where browser vendors negotiate how and when HTTP deprecation proceeds.
Second-order effects
- Certificate authorities and hosting providers gain a wave of mandated migration demand as sites rush to avoid insecure labels.
- Other browser vendors are pushed toward matching positions — the RC4 removal and later the four-vendor TLS 1.0/1.1 deprecation show these decisions converge quickly once one vendor moves first.
Third-order effects
- If the pattern holds, browsers become the enforcement layer for web encryption, with standards bodies ratifying deprecations the vendors have already aligned on — shifting 'secure' from an option site owners choose to a baseline the platform imposes.
- The eventual result is a two-tier web in which unencrypted delivery is treated as a defect, making transport security a prerequisite for features and ranking rather than a compliance checkbox.
The trend: Browser vendors are moving web security from opt-in to enforced-by-default, using coordinated deprecation timelines and standards bodies to phase out legacy plaintext and weak cryptography together.