Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Protecting users from insecure downloads in Google Chrome

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Protecting users from insecure downloads in Google Chrome


๐Ÿ’ก Newskategorie: Programmierung
๐Ÿ”— Quelle: blog.chromium.org

Today weโ€™re announcing that Chrome will gradually ensure that secure (HTTPS) pages only download secure files. In a series of steps outlined below, weโ€™ll start blocking "mixed content downloads" (non-HTTPS downloads started on secure pages). This move follows a plan we announced last year to start blocking all insecure subresources on secure pages.

Insecurely-downloaded files are a risk to users' security and privacy. For instance, insecurely-downloaded programs can be swapped out for malware by attackers, and eavesdroppers can read users' insecurely-downloaded bank statements. To address these risks, we plan to eventually remove support for insecure downloads in Chrome.

As a first step, we are focusing on insecure downloads started on secure pages. These cases are especially concerning because Chrome currently gives no indication to the user that their privacy and security are at risk.

Starting in Chrome 82 (to be released April 2020), Chrome will gradually start warning on, and later blocking, these mixed content downloads. File types that pose the most risk to users (e.g., executables) will be impacted first, with subsequent releases covering more file types. This gradual rollout is designed to mitigate the worst risks quickly, provide developers an opportunity to update sites, and minimize how many warnings Chrome users have to see.


We plan to roll out restrictions on mixed content downloads on desktop platforms (Windows, macOS, Chrome OS and Linux) first. Our plan for desktop platforms is as follows:


Diagram of when warnings will take affect

  • In Chrome 81ย (released March 2020) and later:
    • Chrome will print a console message warning about all mixed content downloads.
  • In Chrome 82 (released April 2020):
    • Chrome will warn on mixed content downloads of executables (e.g. .exe).
  • In Chrome 83 (released June 2020):
    • Chrome will block mixed content executables.
    • Chrome will warn on mixed content archives (.zip) and disk images (.iso).
  • In Chrome 84 (released August 2020):
    • Chrome will block mixed content executables, archives and disk images.
    • Chrome will warn on all other mixed content downloads except image, audio, video and text formats.
  • In Chrome 85 (released September 2020):
    • Chrome will warn on mixed content downloads of images, audio, video, and text.
    • Chrome will block all other mixed content downloads.
  • In Chrome 86 (released October 2020) and beyond, Chrome will block all mixed content downloads.



Example of a potential warning



Chrome will delay the rollout for Android and iOS users by one release, starting warnings in Chrome 83. Mobile platforms have better native protection against malicious files, and this delay will give developers a head-start towards updating their sites before impacting mobile users.ย 

Developers can prevent users from ever seeing a download warning by ensuring that downloads only use HTTPS. In the current version of Chrome Canary, or in Chrome 81 once released, developers can activate a warning on all mixed content downloads for testing by enabling the "Treat risky downloads over insecure connections as active mixed content" flag at chrome://flags/#treat-unsafe-downloads-as-active-content.ย 

Enterprise and education customers can disable blocking on a per-site basis via the existing InsecureContentAllowedForUrls policy by adding a pattern matching the page requesting the download.ย 

In the future, we expect to further restrict insecure downloads in Chrome. We encourage developers to fully migrate to HTTPS to avoid future restrictions and fully protect their users. Developers with questions are welcome to email us at security-dev@chromium.org.ย 

Posted by Joe DeBlasio, Chrome Security team


...



๐Ÿ“Œ Protecting users from insecure downloads in Google Chrome


๐Ÿ“ˆ 44.28 Punkte

๐Ÿ“Œ Protecting users from insecure downloads in Google Chrome


๐Ÿ“ˆ 44.28 Punkte

๐Ÿ“Œ Protecting Google Chrome users from insecure forms


๐Ÿ“ˆ 34.11 Punkte

๐Ÿ“Œ Securing the Software Supply Chain: Protecting Against Insecure Code Downloads


๐Ÿ“ˆ 32.68 Punkte

๐Ÿ“Œ Google Chrome to Get New Feature Blocking Insecure Downloads


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Expert Advise On Google Chrome To Start Blocking Insecure Downloads From Secure Pages


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Google Chrome Will Soon Start Blocking Insecure Downloads


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Chrome Will Block Insecure Downloads on HTTPS Pages


๐Ÿ“ˆ 24.97 Punkte

๐Ÿ“Œ Protecting Data in Apps and Protecting Apps from Data - ASW #92


๐Ÿ“ˆ 24.1 Punkte

๐Ÿ“Œ Google Chrome will warn users when submitting insecure forms


๐Ÿ“ˆ 22.07 Punkte

๐Ÿ“Œ Google Chrome Begins Warns Users About Insecure Pages


๐Ÿ“ˆ 22.07 Punkte

๐Ÿ“Œ Google Chrome Begins Warns Users About Insecure Pages


๐Ÿ“ˆ 22.07 Punkte

๐Ÿ“Œ google has released a new chrome extension called password checkup, which alerts users when it detects them using insecure passwords.


๐Ÿ“ˆ 22.07 Punkte

๐Ÿ“Œ Protecting users on a thriving web (Chrome Dev Summit 2019)


๐Ÿ“ˆ 21.65 Punkte

๐Ÿ“Œ Protecting Chrome users in Kazakhstan


๐Ÿ“ˆ 21.65 Punkte

๐Ÿ“Œ Protecting Chrome users from abusive notifications


๐Ÿ“ˆ 21.65 Punkte

๐Ÿ“Œ LOYTEC Electronics Insecure Transit / Insecure Permissions / Unauthenticated Access


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ #0daytoday #LOYTEC Electronics Insecure Transit / Insecure Permissions / Unauthenticated Access Vul [#0day #Exploit]


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Programi Bilanc Build 007 Release 014 31.01.2020 Insecure Downloads


๐Ÿ“ˆ 20.63 Punkte

๐Ÿ“Œ #0daytoday #Programi Bilanc Build 007 Release 014 31.01.2020 Insecure Downloads Vulnerability [#0day #Exploit]


๐Ÿ“ˆ 20.63 Punkte

๐Ÿ“Œ Software projects face supply chain security risk due to insecure artifact downloads via GitHub Actions


๐Ÿ“ˆ 20.63 Punkte

๐Ÿ“Œ XOOPS WF-Downloads 2.05 Downloads Module viewcat.php list sql injection


๐Ÿ“ˆ 20.34 Punkte

๐Ÿ“Œ CHIP Downloads 2019: Das sind die beliebtesten Downloads des Jahres


๐Ÿ“ˆ 20.34 Punkte

๐Ÿ“Œ CVE-2015-9514 | Easy Digital Downloads Free Downloads Extension up to 2.3.6 on WordPress add_query_arg cross site scripting


๐Ÿ“ˆ 20.34 Punkte

๐Ÿ“Œ Chrome 86 Will Warn Users About Insecure Forms On HTTPS Pages


๐Ÿ“ˆ 20.07 Punkte

๐Ÿ“Œ Chrome 86 to Alert Users of Insecure Forms


๐Ÿ“ˆ 20.07 Punkte

๐Ÿ“Œ Protecting Users from Deception (Google I/O โ€™19)


๐Ÿ“ˆ 19.31 Punkte

๐Ÿ“Œ Protecting Users from Deception (Google I/O โ€™19)


๐Ÿ“ˆ 19.31 Punkte

๐Ÿ“Œ Protecting Users from Deception (Google I/O โ€™19)


๐Ÿ“ˆ 19.31 Punkte

๐Ÿ“Œ Google: Protecting Android users from 0-Day attacks


๐Ÿ“ˆ 19.31 Punkte

๐Ÿ“Œ Google: Protecting Android users from 0-Day attacks


๐Ÿ“ˆ 19.31 Punkte

๐Ÿ“Œ Google Chrome ohne Google: Ungoogled Chrome bringt vollwertigen Chrome-Browser ohne Google-Dienste


๐Ÿ“ˆ 19.03 Punkte

๐Ÿ“Œ Chrome: Unsichere Downloads sollen spรคtestens ab Chrome 86 keine Chance mehr haben


๐Ÿ“ˆ 18.86 Punkte

๐Ÿ“Œ DEF CON 25 Crypto and Privacy Village - Trey Forgety - Protecting Users' Privacy


๐Ÿ“ˆ 17.31 Punkte











matomo