Sean Wright  -- Google Chrome and the Case of the Disappearing HTTP episode artwork

EPISODE · Jul 30, 2018 · 24 MIN

Sean Wright -- Google Chrome and the Case of the Disappearing HTTP

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance? Application security practitioner Sean Wright explains the browser changes in their 2018 context and makes the case for protecting every website with TLS. He separates encrypted transport from trust in a website, examines how unencrypted traffic can be read or modified, and discusses the objections that complicated wider HTTPS adoption. The conversation covers accessible certificate options such as Let’s Encrypt, the role of Cloudflare, and the usability benefits of safer browser defaults. Sean also explains how HTTP Strict Transport Security and preload lists address downgrade opportunities. It is a useful historical discussion of the shift from optional encryption toward an HTTPS-first web.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Sean Wright:→ Sean Wright’s blog→ Sean Wright’s portfolioMentioned in this episode:→ Let’s Encrypt→ HSTS Preload List→ HTTPS Everywhere — retired browser extensionFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Chrome, HTTP, and Sean Wright01:49 Sean’s route from development into security03:23 What TLS protects04:11 Why every website needs encrypted transport05:34 The controversy around HTTP warnings07:45 How unencrypted traffic can be modified08:46 Misinformation and objections to HTTPS10:34 Let’s Encrypt and accessible certificates16:20 Safer defaults and usable security20:22 HSTS headers and preload protection22:38 Resources for understanding the change

Episode metadata supplied by the publisher feed · Published Jul 30, 2018

Embed this episode

What changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance? Application security practitioner Sean Wright explains the browser changes in their 2018 context and makes the case for protecting every website with TLS. He separates encrypted transport from trust in a website, examines how unencrypted traffic can be read or modified, and discusses the objections that complicated wider HTTPS adoption. The conversation covers accessible ce...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Sean Wright -- Google Chrome and the Case of the Disappearing HTTP

0:00 24:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 24 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 30, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!