Google says Chrome will mark all HTTP sites as “not secure” starting in July 2018 with release of Chrome 68
leaving just a handful of outliers. http://www.zdnet.com/... @pinboard : “A secure web is here to stay,” boasts Google, “unless of course you're using an Android phone” http://security.googleblog.com/ ...
Context & Ripple Effects
This announcement closes a loop Google opened years earlier, when the Chrome Security Team first floated marking all HTTP pages as non-secure back in 2014. By late 2017 the groundwork was visible in adoption numbers — 64% of Chrome traffic on Android and 75% on Mac already ran over HTTPS, with 71 of the top 100 sites defaulting to it — giving Google the confidence to set a hard date rather than keep nudging.
First-order effects
- Every operator still serving pages over plain HTTP faces an immediate trust penalty in the world's dominant browser starting with the Chrome 68 release in July, with the warning escalating to red later that year.
- Certificate authorities, hosting providers, and CDN vendors see a surge in demand as millions of small sites scramble to obtain TLS certificates before the deadline.
Second-order effects
- Rival browser makers face pressure to match Chrome's labeling or risk looking lax on security, turning HTTPS-by-default from differentiator into table stakes across the industry.
- Sites that migrate gain access to secure-only web platform features, widening the capability gap between HTTPS and HTTP sites and accelerating deprecation of plain HTTP beyond just warnings.
Third-order effects
- The pattern Google established here — using browser UI as enforcement rather than waiting for standards bodies — became the template for later moves like blocking mixed-content downloads outright in Chrome 82, shifting the browser from passive renderer to active security gatekeeper.
- If the trajectory holds, unencrypted HTTP survives only as a legacy edge case, and browser vendors become de facto regulators of baseline web security for publishers worldwide.
The trend: Browser vendors are replacing gradual HTTPS encouragement with hard UI penalties and outright blocking, making encrypted connections the enforced default for the open web.