Chrome 68, rolling out today, shows a “not secure” warning for any HTTP website; in October the warning's color will change to red
Three and a half years ago, Google predicted the day would come when Chrome would warn us all of the security risks of using the web's seminal HTTP technology …
Context & Ripple Effects
This is the endpoint of a staged campaign Google has been telegraphing for years: the 2016 plan to flag unencrypted sites first materialized in Chrome 56's warnings on HTTP password and credit card forms, then Google committed to a July 2018 deadline in February's Chromium Blog post. Today's Chrome 68 release makes good on it, extending the 'not secure' label from sensitive forms to every HTTP page.
The sequencing matters because Google deliberately inverted the incentive: per May's announcement, HTTPS sites lose their green 'Secure' badge in September while HTTP sites get a red 'Not secure' label in October — security becomes the assumed default rather than a differentiator.
First-order effects
- Every site still serving plain HTTP now displays a 'not secure' warning to all Chrome users, and operators of those sites face an immediate trust penalty they must fix by migrating to HTTPS.
Second-order effects
- Certificate authorities and hosting providers see demand shift from optional certificates to table-stakes migrations, while sites that delay face a harsher red warning when October's color change lands.
Third-order effects
- If browser vendors keep treating encryption as the default, HTTP becomes a legacy protocol phased out by UI pressure rather than standards mandates — with Chrome's market position letting Google set web security policy de facto.
The trend: Browser vendors are converting encryption from an opt-in feature into a baseline expectation, using warning UI rather than regulation to force the web onto HTTPS.