News: 1616573948

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Chrome 90 goes HTTPS by default while Firefox injects substitute scripts to foil tracking tech

(2021/03/24)


When version 90 of Google's Chrome browser arrives in mid-April, initial website visits will default to a secure HTTPS connection in the event the user has failed to specify a preferred [1]URI scheme .

Lack of security is currently the norm in Chrome. As Google Chrome software engineers Shweta Panditrao and Mustafa Emre Acer explain in a [2]blog post , when a user types "www.example.com" into Chrome's omnibox, without either an "http://" or "https:// prefix," Chrome chooses "http://." The same is true in other browsers like Brave, Edge, Mozilla, and Safari.

[3]

This made sense in the past when most websites had not implemented support for HTTPS. It was only [4]in 2018 that the majority of websites redirected traffic to HTTPS. But these days, most of the web pages loaded rely on secure transport (ranging from about [5]98 per cent on Chrome to about 77 per cent on Linux). And among the top 100 websites, 97 of them currently default to HTTPS.

Google fails to neutralize lawsuit that complains Chrome's incognito mode isn't very private at all [6]READ MORE

[7]

Previously, only websites that declared they should be loaded securely with an entry on an HTTP Strict Transport Security ( [8]HSTS ) preload list – supported in multiple browsers – got HTTPS automatically.

Chrome 90 will make HTTPS the default for first time website visits where no transport has been declared. Beyond the security and privacy benefits, say Panditrao and Acer, this will improve performance since the delay incurred by redirection from an http:// endpoint to an https:// endpoint will no longer happen.

A few exceptions will persist, however. IP addresses, single label domains (eg [9]contoso without TLD like .com), and reserved hostnames like localhost/ will still default to http://.

Private like a fox

In other browser-related news, Mozilla Firefox 87 debuted on Tuesday with a privacy feature [10]called SmartBlock .

Borrowing from techniques used by privacy-focused extensions NoScript and uBlock Origin (eg " [11]stub scripts "), SmartBlock provides a way to block tracking scripts while attempting to minimize performance-affecting delays or errors that can arise from meddling with webpage code.

"SmartBlock does this by providing local stand-ins for blocked third-party tracking scripts," explains Thomas Wisniewski, web compatibility engineer at Mozilla, in a [12]blog post .

"These stand-in scripts behave just enough like the original ones to make sure that the website works properly. They allow broken sites relying on the original scripts to load with their functionality intact."

Firefox SmartBlock can replace trackers found on the extensive Disconnect Tracking Protection List, which [13]just for the US numbers well over a thousand.

Firefox 87 also incorporates another privacy enhancement: It will limit the information contained in the referrer (misspelled but implemented as " [14]Referer ") header string by setting its default [15]Referrer-Policy to "strict-origin-when-cross-origin."

[16]

What this means is that when a Firefox user follows a link like "https://www.example.com/path?query" – where "path" and "query" represent more meaningful or sensitive information – the HTTP Referer Header that gets sent to the visited website will indicate that the visitor has arrived from "https://www.example.com" and the extra path and query data will be dropped. ®

Get our [17]Tech Resources



[1] https://en.wikipedia.org/w/index.php?title=List_of_URI_schemes&oldid=1007886193

[2] https://blog.chromium.org/2021/03/a-safer-default-for-navigation-https.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFsb0Ddqmc-Tiy2Wv1RS6wAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://scotthelme.co.uk/alexa-top-1-million-analysis-august-2018/

[5] https://transparencyreport.google.com/https/overview?hl=en

[6] https://www.theregister.com/2021/03/17/google_incognito_lawsuit/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFsb0Ddqmc-Tiy2Wv1RS6wAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://hstspreload.org/

[9] https://docs.microsoft.com/en-US/troubleshoot/windows-server/networking/single-label-domains-support-policy

[10] https://blog.mozilla.org/security/2021/03/23/introducing-smartblock/

[11] https://bugzilla.mozilla.org/show_bug.cgi?id=1434357

[12] https://blog.mozilla.org/security/2021/03/23/introducing-smartblock/

[13] https://github.com/disconnectme/disconnect-tracking-protection/blob/master/entities.json

[14] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referer

[15] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFsb0Ddqmc-Tiy2Wv1RS6wAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://whitepapers.theregister.com/

No, this is wrong

Mage

In fact Chrome doesn't work as described and not all sites need https.

In testing https and http versions of the same site it was impossible to access the http version, even if the https was subsequently broken. Also hiding the URL prefix in the stupid omnibox is also wrong.

Chrome development is driven by ideology, not actual usability, security or privacy. Privacy? It's practically Google spyware. An elephant in the room is how it does DNS and manages trackers and communication with Google.

Also it should be up to the rewrite rules on the site and the user input what to do, not some half baked algorithm put in by a programmer at Google's request.

Re: No, this is wrong

b0llchit

Chrome development is driven by ideology, not actual usability, security or privacy.

It is driven by pure commercial interests. It slowly subverts standards, good ideas and user-oriented usability into a vehicle to better support the corporate cash cow. Changes are done slow enough so that the general public does not see any problems. Those who see the problems are a (technical) minority who can be silenced easily or will simply be ignored as alarmists.

Re: No, this is wrong

Ben Tasker

> not all sites need https.

It's _literally_ free to set up HTTPS nowadays, and performance is no longer a concern (outside of some extreme edge cases).

It's not just about the site you're accessing, it's about the network you're accessing the site via. HTTPS helps provide some in-flight security so that someone in the middle can't inject nasties (US ISPs have been caught injecting advertising).

If you're not serving via HTTPS, its your users/visitors you're putting at risk, not yourself.

Honestly, the battle for "not everything needs HTTPS" has been long-since lost.

> In testing https and http versions of the same site it was impossible to access the http version, even if the https was subsequently broken.

Sounds like a bug, report it

> Chrome development is driven by ideology, not actual usability, security or privacy.

It's driven by commercial interests, but I largely agree as a rule.

Not sure this one falls under that though - in fact, I'd posit that nowadays "not everything needs HTTPS" is an ideology rather than something supported by real-world evidence.

> Privacy? It's practically Google spyware.

It's perfectly possible for something to offer near-absolute privacy against *most* threats whilst leaving you still entirely exposed to one party. If you're married, then your bedroom curtains probably do much the same thing.

If you're using Chrome, then that involves accepting that Google are going to be Google. It doesn't mean they should just say "fuck keeping things private from others" for users that are willing to make that trade-off

> Also it should be up to the rewrite rules on the site and the user input what to do, not some half baked algorithm put in by a programmer at Google's request.

It is - if you don't want HTTPS on your site, Chrome will fall back to HTTP. If you're the user, then enter the url with a scheme (http://foo.bar) rather than just the FQDN (foo.bar).

All that's changed is the default scheme

Re: No, this is wrong

jezza99

Agreed! I would go further and suggest that all unencrypted protocols should be removed from RFCs. It is just too risky, even for intranets.

Implementing HTTPS is trivial.

Re: No, this is wrong

Hubert Cumberdale

I've been saying this for years, but kept getting downvoted. There is no excuse for a site to not use HTTPS any more. Yes, it's bad that Google have so much power (and I refuse to use Chrome except for testing purposes), but in this case, they happen to be using it to do something good. Defaulting to HTTPS is the right thing to do.

Really useful blocking

iGNgnorr

One of the most useful things any of the browsers could do is permanetly and completely block autoplay of *anything*.

Brave

NonSSL-Login

Brave does upgrade connections to HTTPS automatically by default and has done so for at least 6 months, despite being based on Chromium.

It also has an icon in the url bar to turn of strict HTTPS for the current site you are on.

What annoyed me with Chrome a few years back is when they decided to hide the HTTP/HTTPS from the URL bar so if you wanted to copy and paste a domain from the url bar to say ping it, you also got the invisible HTTP/HTTPS meaning you had to edit the paste every time.

Looking forward to more advances in the browser anti-tracking and also keeping an eye on Googles 'new privacy features' which will do nothing to increase my privacy.

Bondage maybe, discipline never!
-- T.K.