Google Chrome Now Blocks Insecure Scripts on HTTPS
google-chrome-browser.com
google-chrome-browser.com
It's a big problem, but it's more about users compulsively clicking Yes and not so much about Chrome's UI.
I'm not saying that I have a better idea about how to do it, but this is UI designers reaping what they have sown.
(Of course, I'm sure that most users have no idea what clicking 'yes' entails -- I'm just proposing that if they did, they would probably click 'yes' anyway.)
There's a reason browsers don't display a secure logo on HTTPS connections with non-HTTPS resources: it's not secure. It's not "minimally compromised", it's compromised. If my server has one service with one vulnerability, it's not "minimally vulnerable", it's vulnerable.
| I don't see any reason not to give the minority SSL
I was being sarcastic.
| Isn't it perfectly plausible that 80% of a site's users don't give a hoot about security, but 20% do?
It's not even about the users. The site should not ever be mixing HTTP with HTTPS on the same page.
The user is trying to do something (check email, save a note, play angry birds). Something is in their way, and there is an obvious way to get it out of their way. It has nothing to do with UI design or habits.
In this case, "Load anyway" is a poor label. "Load potentially insecure script anyway" is better (if a bit long-winded).
I did not design this interface.
Basically... I'm seeing this message crop up wherever I see embedded media.
Message is: Even if your site doesn't need https:// , if you're going to offer widgets and embedding you better offer a https:// option for those.
At least Chrome's interface for this makes it less obtrusive than a pop-up dialog.
If it can be disabled, the first people who disable it will be developers, who will proceed to continue building websites that pop this up for everybody else, oblivious that it's pissing off every one of their users.
We already went through this cycle once with javascript error popups. Developers turned them off, then pasted in crappy 3rd party dhtml menu code, which in turn threw up warnings for every regular user to come down the pike.
These warnings need to be prominent and painful. And they need to stay that way for everybody, otherwise they'll just be an annoyance for non-savvy users, rather than an incentive to fix the 400 million sites that are currently getting this wrong.
If the current page is served over https, it will load scripts using https. If it's served over http, it will use http.
http://stackoverflow.com/questions/550038/is-it-valid-to-rep...
Before the change, it just put the browser into mixed-content-mode, but now it does that and in addition it disables loaded JS.
I think it should block it without the error message though.