SlideShare une entreprise Scribd logo
1  sur  13
REASONS HTTP WILL BECOME
A THING OF THE PAST
6
Reason #1: Browsers Will Warn
Users of Non-HTTPS Connections
Chrome plans to warn users when
pages are insecure (non-https),
and will warn if an insecure page
asks for a password or credit card
with words “Not Secure”
Firefox plans a similar warning
for sites requiring passwords
and credit cards
Both will transition to a more
noticeable red triangle
Firefox Warnings
When passwords are requested over http:
https://blog.Mozilla.org/tanvi/2016/01/28/no -more-passwords-over-http-please/
http-password.badssl.com
DevEdition 46+
http-password.badssl.com
DevEdition 45
Chrome to Present Similar Warnings
https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
Treatment of HTTP pages with
password or credit card form fields:
Current (Chrome 53) login.example.com
Jan. 2017 (Chrome 56) login.example.comNot secure
Reason #2: Powerful Features
Only on HTTPS
Encrypted Media
Extension (DRM)
See: https://www.chromium.org/Home/chromium-
security/deprecating-powerful-features-on-insecure-origins
Geolocation
(Chrome 50)
Device
Motion/Orientation
Fullscreen
getUserMedia
(Camera/Mic)
Reason #3: HTTP2 Over HTTPS Only
Chrome, Firefox, IE, Edge,
Safari, Opera test comparison
0 20 40 60
HTTP/2
HTTP/1.1
Latency (in milliseconds)
0 5 10 15 20
HTTP/2
HTTP/1.1
LoadTime (in seconds)
See: https://http2.akamai.com/demo
Reason #4: Improved Referrer Data
Use HTTPS for your own site
and improve your referrer
data!
HTTP Website
Operator:
Source (HTTPS):
Reason #5: GMAIL Showing
Encryption Indicators
SMTP TLS Connection GUI in gmail
Use publicly trusted
certs for mail servers
NO ENCRYPTION WITH
ENCRYPTION
CERTIFICATE
of mail servers don’t
have a publicly trusted
SSL cert yet, according
to Netcraft
82%
Reason #6: HTTPS is Coming
to a Domain Near You
56%Use https
46%Participate in the
digital analytics
program
ALL .gov
OUT OF 1166
DOMAINS!
As of 10/17/16
What Do These Mean?
SymbolsThat Are Consistent,
Universal, Global, No Learning Curve!
Consistency Matters
Copyright © 2014 Symantec Corporation
CASC Predictions
Certificate usage will continue to
grow6.5 to 7.5M in 12 months
Fueled by https initiatives (search ranks, powerful
features, negative browser UI)
SNI servers will show
increased growth
SHA-1 usage will
decline dramatically
(and so will XP!)
Phishing using DV certs
will continue to increase
Chrome will be on the
bleeding edge of changes
and enforcements
IPv6 will finally be
adopted for CRL and
OCSP lookups
Q&A

Contenu connexe

En vedette

HH HR company presentation
HH HR company presentationHH HR company presentation
HH HR company presentation
Reema Gupte
 
Hart Bryan IWS Diploma
Hart Bryan IWS DiplomaHart Bryan IWS Diploma
Hart Bryan IWS Diploma
Bryan Hart
 

En vedette (12)

HH HR company presentation
HH HR company presentationHH HR company presentation
HH HR company presentation
 
Wiara Nadzieja Miłość Marketing
Wiara Nadzieja Miłość MarketingWiara Nadzieja Miłość Marketing
Wiara Nadzieja Miłość Marketing
 
Determinacion de la ROE
Determinacion de la ROEDeterminacion de la ROE
Determinacion de la ROE
 
Diploma de inginer
Diploma de inginerDiploma de inginer
Diploma de inginer
 
The past, present and future of singing synthesis
The past, present and future of singing synthesisThe past, present and future of singing synthesis
The past, present and future of singing synthesis
 
Felicitare de Craciun - ComoriNemuritoare.Ro
Felicitare de Craciun - ComoriNemuritoare.RoFelicitare de Craciun - ComoriNemuritoare.Ro
Felicitare de Craciun - ComoriNemuritoare.Ro
 
Cara Menghasilkan Uang Dari Blog & Media Sosial
Cara Menghasilkan Uang Dari Blog & Media SosialCara Menghasilkan Uang Dari Blog & Media Sosial
Cara Menghasilkan Uang Dari Blog & Media Sosial
 
Hart Bryan IWS Diploma
Hart Bryan IWS DiplomaHart Bryan IWS Diploma
Hart Bryan IWS Diploma
 
T6 movimiento fq 4º eso
T6 movimiento fq 4º esoT6 movimiento fq 4º eso
T6 movimiento fq 4º eso
 
Tabla de cationes y aniones 8º v3
Tabla de cationes y aniones 8º v3Tabla de cationes y aniones 8º v3
Tabla de cationes y aniones 8º v3
 
Tema 2. la materia y sus propiedades (16 17)
Tema 2. la materia y sus propiedades (16 17)Tema 2. la materia y sus propiedades (16 17)
Tema 2. la materia y sus propiedades (16 17)
 
Sveto tunneli 03_11_2016 (1)
Sveto tunneli 03_11_2016 (1)Sveto tunneli 03_11_2016 (1)
Sveto tunneli 03_11_2016 (1)
 

Similaire à Six Reasons http Will Become a Thing of the Past

Modern Resources - Browsing
Modern Resources - BrowsingModern Resources - Browsing
Modern Resources - Browsing
cquirinCS
 
Rich Web App Security - Keeping your application safe
Rich Web App Security - Keeping your application safeRich Web App Security - Keeping your application safe
Rich Web App Security - Keeping your application safe
Jeremiah Grossman
 
W3 conf hill-html5-security-realities
W3 conf hill-html5-security-realitiesW3 conf hill-html5-security-realities
W3 conf hill-html5-security-realities
Brad Hill
 

Similaire à Six Reasons http Will Become a Thing of the Past (20)

How to be trusted in 2017
How to be trusted in 2017How to be trusted in 2017
How to be trusted in 2017
 
Browser Security
Browser SecurityBrowser Security
Browser Security
 
Chrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainmentChrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainment
 
What you need to know about Google Chrome 56?
What you need to know about Google Chrome 56?What you need to know about Google Chrome 56?
What you need to know about Google Chrome 56?
 
Google Chrome 56 What You Need to Know?
Google Chrome 56   What You Need to Know?Google Chrome 56   What You Need to Know?
Google Chrome 56 What You Need to Know?
 
5 critical-optimizations.v2
5 critical-optimizations.v25 critical-optimizations.v2
5 critical-optimizations.v2
 
CMS & Chrome Extension Development
CMS & Chrome Extension DevelopmentCMS & Chrome Extension Development
CMS & Chrome Extension Development
 
Better Safe Than Sorry with HTTPS - SMX East 2016 - Patrick Stox
Better Safe Than Sorry with HTTPS - SMX East 2016 - Patrick StoxBetter Safe Than Sorry with HTTPS - SMX East 2016 - Patrick Stox
Better Safe Than Sorry with HTTPS - SMX East 2016 - Patrick Stox
 
Introduction to Linked Data and Web Payments
Introduction to Linked Data and Web Payments Introduction to Linked Data and Web Payments
Introduction to Linked Data and Web Payments
 
526_topic08.ppt
526_topic08.ppt526_topic08.ppt
526_topic08.ppt
 
Modern Resources - Browsing
Modern Resources - BrowsingModern Resources - Browsing
Modern Resources - Browsing
 
Building Encrypted APIs with HTTPS and Paillier
Building Encrypted APIs with HTTPS and PaillierBuilding Encrypted APIs with HTTPS and Paillier
Building Encrypted APIs with HTTPS and Paillier
 
Frontend development of the (current) future
Frontend development of the (current) futureFrontend development of the (current) future
Frontend development of the (current) future
 
HTTP Strict Transport Security (HSTS), English version
HTTP Strict Transport Security (HSTS), English versionHTTP Strict Transport Security (HSTS), English version
HTTP Strict Transport Security (HSTS), English version
 
New or obscure web browsers 4x3 (rcsi draft 6)
New or obscure web browsers 4x3 (rcsi draft 6)New or obscure web browsers 4x3 (rcsi draft 6)
New or obscure web browsers 4x3 (rcsi draft 6)
 
Rich Web App Security - Keeping your application safe
Rich Web App Security - Keeping your application safeRich Web App Security - Keeping your application safe
Rich Web App Security - Keeping your application safe
 
E-commerce Lab work
E-commerce Lab workE-commerce Lab work
E-commerce Lab work
 
Word press bg 16x9 draft 16
Word press bg 16x9 draft 16Word press bg 16x9 draft 16
Word press bg 16x9 draft 16
 
W3 conf hill-html5-security-realities
W3 conf hill-html5-security-realitiesW3 conf hill-html5-security-realities
W3 conf hill-html5-security-realities
 
WordCamp US: Delivering the news over HTTPS
WordCamp US: Delivering the news over HTTPSWordCamp US: Delivering the news over HTTPS
WordCamp US: Delivering the news over HTTPS
 

Plus de CASCouncil

Plus de CASCouncil (20)

100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
 
What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?
 
Payments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to knowPayments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to know
 
TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly
 
2016 IRS Free e-File Audit & Honor Roll
2016 IRS Free e-File Audit & Honor Roll2016 IRS Free e-File Audit & Honor Roll
2016 IRS Free e-File Audit & Honor Roll
 
Symantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the WebSymantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the Web
 
CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security  CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security
 
Update on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser ForumUpdate on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser Forum
 
Extended Validation Builds Trust
Extended Validation Builds TrustExtended Validation Builds Trust
Extended Validation Builds Trust
 
CA Day 2014
CA Day 2014 CA Day 2014
CA Day 2014
 
Heartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and SolutionHeartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and Solution
 
New Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer InternetNew Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer Internet
 
Alternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure WebAlternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure Web
 
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
 
State of the Web
State of the WebState of the Web
State of the Web
 
Trust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory ProcessesTrust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory Processes
 
Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!
 
CAs And The New Paradigm Shift
CAs And The New Paradigm ShiftCAs And The New Paradigm Shift
CAs And The New Paradigm Shift
 
CA Self Regulation
CA Self RegulationCA Self Regulation
CA Self Regulation
 
New Window of Opportunity
New Window of OpportunityNew Window of Opportunity
New Window of Opportunity
 

Dernier

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 

Dernier (20)

🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 

Six Reasons http Will Become a Thing of the Past

  • 1. REASONS HTTP WILL BECOME A THING OF THE PAST 6
  • 2. Reason #1: Browsers Will Warn Users of Non-HTTPS Connections Chrome plans to warn users when pages are insecure (non-https), and will warn if an insecure page asks for a password or credit card with words “Not Secure” Firefox plans a similar warning for sites requiring passwords and credit cards Both will transition to a more noticeable red triangle
  • 3. Firefox Warnings When passwords are requested over http: https://blog.Mozilla.org/tanvi/2016/01/28/no -more-passwords-over-http-please/ http-password.badssl.com DevEdition 46+ http-password.badssl.com DevEdition 45
  • 4. Chrome to Present Similar Warnings https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html Treatment of HTTP pages with password or credit card form fields: Current (Chrome 53) login.example.com Jan. 2017 (Chrome 56) login.example.comNot secure
  • 5. Reason #2: Powerful Features Only on HTTPS Encrypted Media Extension (DRM) See: https://www.chromium.org/Home/chromium- security/deprecating-powerful-features-on-insecure-origins Geolocation (Chrome 50) Device Motion/Orientation Fullscreen getUserMedia (Camera/Mic)
  • 6. Reason #3: HTTP2 Over HTTPS Only Chrome, Firefox, IE, Edge, Safari, Opera test comparison 0 20 40 60 HTTP/2 HTTP/1.1 Latency (in milliseconds) 0 5 10 15 20 HTTP/2 HTTP/1.1 LoadTime (in seconds) See: https://http2.akamai.com/demo
  • 7. Reason #4: Improved Referrer Data Use HTTPS for your own site and improve your referrer data! HTTP Website Operator: Source (HTTPS):
  • 8. Reason #5: GMAIL Showing Encryption Indicators SMTP TLS Connection GUI in gmail Use publicly trusted certs for mail servers NO ENCRYPTION WITH ENCRYPTION CERTIFICATE of mail servers don’t have a publicly trusted SSL cert yet, according to Netcraft 82%
  • 9. Reason #6: HTTPS is Coming to a Domain Near You 56%Use https 46%Participate in the digital analytics program ALL .gov OUT OF 1166 DOMAINS! As of 10/17/16
  • 10. What Do These Mean? SymbolsThat Are Consistent, Universal, Global, No Learning Curve!
  • 11. Consistency Matters Copyright © 2014 Symantec Corporation
  • 12. CASC Predictions Certificate usage will continue to grow6.5 to 7.5M in 12 months Fueled by https initiatives (search ranks, powerful features, negative browser UI) SNI servers will show increased growth SHA-1 usage will decline dramatically (and so will XP!) Phishing using DV certs will continue to increase Chrome will be on the bleeding edge of changes and enforcements IPv6 will finally be adopted for CRL and OCSP lookups
  • 13. Q&A

Notes de l'éditeur

  1. The SSL protocol is stronger now than ever, because of the number of researchers assessing it and the improvements that have been made.   What’s important is that we’re evolving, and we have a better unity than ever before in focusing on efforts that will earn the trust we seek from our customers and all users and improve internet security.
  2. Increased threats towards CAs from sophisticated hacker networks, global cybercriminal organizations and state-sponsored espionage. Pressure for global and increasingly tough standards - CA/B Forum, Network Security Guidelines. Great need for research and education to help people better understand how to use SSL to its maximum benefit. There needs to be a leader and it can’t be just one CA, it must be a unified group.
  3. The CASC’s mission is to advance internet security by promoting deployments and enhancements to publicly trusted certificates and through public education, collaboration, and advocacy. Promotion of best practices that advance trusted SSL deployment and CA operations as well as the security of the internet in general. The CASC strives for the adoption of digital certificate best practices and the proper issuance and use of digital certificates by CAs, browsers, and other interested parties. While not a standards-setting organization, the CASC works collaboratively to improve understanding of critical policies and their potential impact on the internet infrastructure.
  4. What’s important is for people to realize that we as CAs can do more to improve SSL security, but not alone. Browsers, software vendors, web server administrators, even end users can contribute by getting educated about the key factors and working together to value security. The CASC works actively with browsers, relying parties and other stakeholders to enhance internet security through practical, thoughtful measures and collaborative research. In addition, the CASC supports the efforts of the CA/Browser Forum and other standards-setting bodies in their important work, and will continue to help develop reasonable and practical enhancements that improve trusted Secure Sockets Layer (SSL) and Certificate Authority (CA) operations.
  5. Coinciding with its launch, the CASC is announcing the first of a planned series of educational and advocacy efforts related to best practices in SSL deployment with a focus on the importance of online certificate status checking and revocation.   Specifically, the CASC will highlight the benefits of OCSP stapling for web server administrators, software vendors, browser makers, and end-users through blog posts, conference presentations and other resources.