Chrome Just Started Shaming My Old Links

Chrome Just Started Shaming My Old Links

Tech News browsers chrome https web-security

So I finally got the "not secure" shame treatment last week and it kicked me into gear. If you haven't noticed yet, Chrome 68 rolled out around July 24th and now every single site still running on plain old http:// gets a little "Not Secure" label right in the address bar. Not a scary red warning yet, just a flat gray "i" with the words sitting there next to your URL like a parking ticket. But still. Google's been telegraphing this for like two years and now its actually here.

I went and checked techpad first, because of course I did, and thankfully I moved this thing to HTTPS back in 2016 when Let's Encrypt made it free and mostly painless. But then I started clicking through my own old posts from 2012 and 2013 looking for outbound links, and holy cow, so many of them point to sites that still haven't bothered. A few local business sites I link to in old restaurant reviews (yes I used to write restaurant reviews here, dont judge past me). A couple of old dev blogs I used to read. All sitting there now with that little warning for anyone who clicks through.

Chrome has about 60-something percent of the browser market at this point, maybe more depending on whose numbers you trust, so this isnt some fringe thing you can ignore if you run literally anything on the web. Firefox has been doing something similar in its own quieter way too. The writing has been on the wall since at least early 2017 when Chrome started flagging password and credit card fields on http pages specifically. This is just the next, much bigger step: now its every page, not just the ones asking for sensitive info.

What gets me is how many small business sites are just never going to fix this. Not because the owners don't care, but because half of them paid some guy $400 in 2011 to build a WordPress site and havent touched it since, and the idea of touching server config again is basically a nightmare to them. I get it honestly, cert renewal used to be a genuine pain before Let's Encrypt showed up with free 90-day certs and auto-renewal scripts. I remember paying something like $70 a year to Comodo for a basic cert on an old freelance project back in like 2014 and it felt like such a racket even then.

Anyway this is basically why I've started telling people to just pick a host that handles HTTPS automatically instead of fiddling with it themselves — domain, hosting, and a cert that just works without you thinking about it, which honestly is most of the battle for anyone who isnt going to sit around reading Apache config docs on a Tuesday night like some of us apparently do for fun.

Separate but related thought: it's a weird week for tech generally. Facebook's stock cratered by something like $119 billion in a single day after their earnings call last Wednesday, which I think is still the largest one-day loss for any US company ever, and that was mostly about user growth slowing down and them warning investors about GDPR-related costs eating into revenue going forward. And the EU hit Google with that massive $5 billion antitrust fine over Android bundling a couple weeks back. Both stories that everyone and their mother has already written ten thousand words about, so I wont bother rehashing the details here. But it does feel like this specific stretch of summer 2018 is when a bunch of the "we're too big to really be touched" energy around these companies started cracking a little, even if just cosmetically.

Back to the boring HTTPS thing though because I think it actually matters more day to day for most of us than the stock market drama does. If you run any kind of small site, even a dumb little hobby blog nobody reads, go check if you're still on http. It takes like fifteen minutes now. There's genuinely no excuse left, and browsers are only going to get more aggressive about calling it out from here.

Also, side note, I need to go fix that restaurant review section. Half those places have probably closed anyway.