03.03.2020

Google Chrome will soon start blocking insecure HTTP downloads

Google Chrome will soon start blocking insecure HTTP downloads

Google Chrome developers wrote on their blog that they would block the "download of mixed content" on HTTPS-protected pages with resources on HTTP. Yes, friends, what is so far showing as warning or an error in the developer console will be blocked soon:

Mixed Content: The page at 'https://domain.com/' was loaded over HTTPS, but requested an insecure image 'http://domain.com/wp-content/uploads/2019/01/logo.png'. This content should also be served over HTTPS.
Mixed Content: The page at 'https://domain.com/' was loaded over HTTPS, but requested an insecure favicon 'http://domain.com/favicon.png'. This request has been blocked; the content must be served over HTTPS.

Mixed Content Errors

This way, developers will block all insecure resources on secure HTTPS pages. But don’t worry - we still have time to fix all the errors of mixed content. At first (from the version of Chrome 82, which will be released in April 2020), the Chrome browser will notify, but only in future versions it will already block executable files, for example .exe, .apk, etc.

Further, other types of files, such as .zip, .iso, will fall under the lock, and everything will end in the version of Chrome 86, which will be released in October 2020, where all downloads of mixed content, that is, all file types, will be blocked. For convenience, the developers have posted a roadmap for innovations with blocking mixed content:

Mixed Content Errors for Mobile Devices

It’s worth noting that Chrome will delay the application of notifications and blocking mixed content for Android and iOS users by one release, which will lead to warnings in the Chrome 83 release. Google Chrome developers believe that mobile platforms have better built-in protection against malicious files, and this the delay will give webmasters the opportunity to start updating their sites before the innovation affects mobile users.

How to activate mixed content blocking

By the way, in the current version of Google Chrome, you can already activate the blocking of mixed content to test your sites - for this, in the address bar of the Chrome browser you must enter the following address (flag):

chrome://flags/#treat-unsafe-downloads-as-active-content

Latest news

Discount on all Ukrainian domains until 10/21/2022!
14.10.2022
Discount on all Ukrainian domains until 10/21/2022!
Dear users! For a whole week -15% discount for registration of all Ukrainian domains using the promo code defendersday22!
Increase in price of a number of Ukrainian domains UA ccTLD!
28.09.2022
Increase in price of a number of Ukrainian domains UA ccTLD!
Dear users! From October 1, 2022, we are waiting for a rise in price in a number of Ukrainian domains - in.ua, od.ua, mk.ua!
Important changes in some Ukrainian domains!
09.03.2022
Important changes in some Ukrainian domains!
Dear users! In some Ukrainian domain zones, the Redemption period for domains has been increased from 30 to 60 days.
Rise in price of dedicated IPv4 in Germany!
09.08.2021
Rise in price of dedicated IPv4 in Germany!
Dear users! In Germany, additional dedicated IP addresses (IPv4) and IP networks have risen significantly.

Latest Blog Posts

New virus Coronavirus (COVID-19) and cyber fraud on the Internet
02.03.2020
New virus Coronavirus (COVID-19) and cyber fraud on the Internet
The panic surrounding the coronavirus COVID-19 is used by cyber fraudsters on the Internet - phishing, selling masks, vaccines and tests.
Mail is not sent - check if the internet provider is blocking port 25
11.01.2020
Mail is not sent - check if the internet provider is blocking port 25
How to check if provider is blocking port 25 using the command line in Windows. How to send mail if port 25 is blocked.
How to install Clam AntiVirus (ClamAV) on a VPS or server with CentOS
11.11.2019
How to install Clam AntiVirus (ClamAV) on a VPS or server with CentOS
Install Clam AntiVirus (ClamAV) on VPS / VDS or a dedicated server with CentOS OS and configure daily server scan.
ISPmanager no longer supports backup to Yandex.Disk
20.10.2019
ISPmanager no longer supports backup to Yandex.Disk
Within a week, Yandex.Disk will disappear from the list of backup storage in the ISPmanager panel and other ISPsystem products.