It's happened. Today Chrome's stable channel was updated with a new HTTPS UI. The changes in these versions of Chrome (Chrome 53 for Windows, Mac users got them in Chrome 52) complete 'transition 1' in Google's HTTPS plans, first announced in December 2014:
T1: Non-secure origins marked as Dubious
In other words:
If a Chrome user visits a site that isn't private - for example, there's no HTTPS, broken HTTPS, or HTTPS only on 'checkout' pages - Chrome now displays a mid-grey colored info box:
Clearer identity for EV
The new stable vesins of Chrome also have a clearer identity display for certificates that have been through extended validation: the verified legal entity (in most cases, a company name) is simply displayed in front of the address, without background.
The new Chrome EV UI is higher contrast, much easier to read that the previous version and looks similar to what Microsoft Edge does:
At CertSimple we've already updated the certificate previews we use for Chrome users to reflect the changes.
The next steps of Google's plans is simple:
T2: Non-secure origins marked as Non-secure
Ie, the grey exclamation mark will get redder as more sites begin to update and HTTPS market share increases
After that, https becomes a regular part of the web, i.e., we don't bother displaying https:// or the green lock anymore, because all websites should have them:
T3: Secure origins unmarked
The timelines for this are fluid but T2 is coming and if you're not on HTTPS - properly, not just for your checkout pages - you need to get on it. Also: site-wide HTTPS gets an SEO boost.
Still not on HTTPS?
If you have an active registered company and want to prove your identity with EV HTTPS, give CertSimple a try - we're an EV-only HTTPS provider that specialises in helping you pass through the required background checks as painlessly as possible!
Try Expedited WAF.
Get a Free Tee.
Option 1: Install Expedited WAF (the Web Application Firewall service that shields your Heroku applications from attacks) from the Heroku Elements Marketplace..
Seven days later we'll ask for some feedback and your (US or Canada only) shipping details.
Option 2: Select a Date & Time below to talk to us about your existing web application security framework and see how Expedited WAF can help better secure your Heroku applications.