Google says starting with Chrome 82 in April, it will gradually start blocking “mixed content downloads”, which are non-HTTPS downloads started on secure pages
Today we're announcing that Chrome will gradually ensure that secure (HTTPS) pages only download secure files.
Context & Ripple Effects
This announcement closes the loop on a campaign Google has run for years: the security team first floated marking plain HTTP as insecure back in 2014, then followed through when Chrome began labeling all HTTP sites "not secure". By late 2017 the pressure was visibly working, with roughly two-thirds or more of Chrome traffic already encrypted across platforms.
What changes now is the enforcement surface: instead of warning users about insecure pages, Chrome will start refusing insecure files downloaded from secure ones — moving HTTPS from a label users read into a gate they cannot bypass.
First-order effects
- Sites that serve downloadable files over HTTP from HTTPS pages will see those downloads progressively blocked for Chrome 82+ users starting in April, forcing them to move file hosting onto certificates.
Second-order effects
- Certificate authorities, CDNs, and hosting providers gain a fresh wave of migration demand from sites whose pages were already encrypted but whose download endpoints were not — the long tail the earlier page-labeling push never reached.
Third-order effects
- If the warn-then-block cadence holds, browser makers become the de facto enforcement mechanism for transport security across the web, with site operators treating Chrome's release notes as compliance deadlines rather than suggestions.
The trend: Google is extending its HTTPS campaign from labeling insecure pages to actively blocking insecure resources, making encryption a hard requirement rather than a recommendation.