EPISODE · Jul 30, 2018 · 24 MIN
Sean Wright -- Google Chrome and the Case of the Disappearing HTTP
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance? Application security practitioner Sean Wright explains the browser changes in their 2018 context and makes the case for protecting every website with TLS. He separates encrypted transport from trust in a website, examines how unencrypted traffic can be read or modified, and discusses the objections that complicated wider HTTPS adoption. The conversation covers accessible certificate options such as Let’s Encrypt, the role of Cloudflare, and the usability benefits of safer browser defaults. Sean also explains how HTTP Strict Transport Security and preload lists address downgrade opportunities. It is a useful historical discussion of the shift from optional encryption toward an HTTPS-first web.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Sean Wright:→ Sean Wright’s blog→ Sean Wright’s portfolioMentioned in this episode:→ Let’s Encrypt→ HSTS Preload List→ HTTPS Everywhere — retired browser extensionFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Chrome, HTTP, and Sean Wright01:49 Sean’s route from development into security03:23 What TLS protects04:11 Why every website needs encrypted transport05:34 The controversy around HTTP warnings07:45 How unencrypted traffic can be modified08:46 Misinformation and objections to HTTPS10:34 Let’s Encrypt and accessible certificates16:20 Safer defaults and usable security20:22 HSTS headers and preload protection22:38 Resources for understanding the change
Embed this episode
What this episode covers
What changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance? Application security practitioner Sean Wright explains the browser changes in their 2018 context and makes the case for protecting every website with TLS. He separates encrypted transport from trust in a website, examines how unencrypted traffic can be read or modified, and discusses the objections that complicated wider HTTPS adoption. The conversation covers accessible ce...
Ready to play
Sean Wright -- Google Chrome and the Case of the Disappearing HTTP
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.