Chrome 56 arrives with 28% faster page reloading, “Not secure” warning for HTTP password and credit card forms
Google has launched Chrome 56 for Windows, Mac, Linux, and Android. Among the additions is a new warning for websites that collect passwords or credit card numbers …
Context & Ripple Effects
With Chrome 56, Google turns its Credential Management API-era security roadmap into visible user-facing pressure: any page collecting passwords or credit card numbers over plain HTTP now carries a "Not secure" label, alongside a 28% faster reload path. This is the opening move of a staged campaign rather than a one-off flag.
The follow-through is already mapped in the coverage: Chrome 68 later extends the warning to every HTTP page, with a red variant announced for October, and by late 2017 Google reports 64% of Chrome traffic on Android and 75% on Mac now riding HTTPS. Chrome 79 then layers breach notifications and phishing tools on top of the same trust surface.
First-order effects
- Operators of login and checkout pages still served over HTTP see a "Not secure" label appear directly beside their forms in Chrome on Windows, Mac, Linux, and Android starting today.
- Users gain an immediate visual cue distinguishing encrypted from unencrypted credential entry, making insecure forms harder to fill without noticing.
Second-order effects
- Site operators facing conversion risk from the label are pushed toward TLS migration, shifting demand toward certificate authorities and hosting providers that make HTTPS cheap or free.
- Rival browser makers face pressure to match Chrome's warning behavior or cede ground on being seen as the security-conscious default.
Third-order effects
- If the escalation pattern holds — broader warnings, harsher colors, then breach alerts — browser UI becomes the de facto enforcement mechanism for web encryption standards, with Google's release cadence setting compliance timelines for the entire web rather than any regulator.
The trend: Browser vendors are replacing passive protocol standards with escalating interface-level pressure, using Chrome's warning labels to force the web onto HTTPS.