{"id":42013,"date":"2018-07-24T04:00:00","date_gmt":"2018-07-24T08:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/another-nail-coffin-http-2\/"},"modified":"2023-03-10T10:56:58","modified_gmt":"2023-03-10T15:56:58","slug":"another-nail-coffin-http-2","status":"publish","type":"cira_news","link":"https:\/\/stg-saas.cira.ca\/fr\/ressources\/nouvelles\/cybersecurity-fr\/another-nail-coffin-http-2\/","title":{"rendered":"Another nail in the coffin for HTTP"},"content":{"rendered":"<p>Well, the time is now here. Starting this week, Google\u00a0Chrome will start sending \u201cnot secure\u201d warnings to every user visiting a non-https\u00a0site. We took a look at our own threat blocking data to see how often HTTP sites are classified as malicious.\u00a0<\/p>\n<p><!--more--><\/p>\n<p>Back in June, we wrote <a href=\"\/blog\/cybersecurity\/why-you-need-ssl-certificate-your-website-and-how-get-one\">a post that gave a heads up on the upcoming changes to Google Chrome<\/a>. It was practically a warning to website owners that if they don&#8217;t have an SSL certificate for their blog or website that it&#8217;s time to get your butt in gear\u2014with free options out there, there&#8217;s no excuse to not&nbsp;encrypt your website data.<\/p>\n<p>Well, the time is now here. Starting this week, Google&nbsp;Chrome will start sending \u201cnot secure\u201d warnings to every user visiting a non-HTTPS&nbsp;site\u2014not just those with form elements. This is another&nbsp;step by Google in helping to improve security and privacy on the internet (since 2015,&nbsp;https&nbsp;has been a positive ranking factor in their search algorithm).&nbsp;This week&#8217;s change should be even more effective because it directly impacts the end user in a commonly used browser.<\/p>\n<p>In light of this, we took a look at the recursive http traffic going to the <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">D-Zone DNS Firewall<\/a>&nbsp;service, specifically at four customers in the education sector. Each has&nbsp;a large number of users including&nbsp;students, faculty and administration.<\/p>\n<p>When we looked at the amount of HTTP&nbsp;traffic that was blocked due to phishing or malware distribution,&nbsp;we found that in the best-case situation a full 27% of HTTP&nbsp;traffic got blocked as malicious. In the worst, a whopping 52% of HTTP&nbsp;traffic was&nbsp;classified thusly.<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" style=\"width:449px\" width=\"0\">\n<tbody>\n<tr>\n<td nowrap=\"nowrap\" style=\"width:288px;height:19px\">\n<p><strong>Status<\/strong><\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p><strong>Customer 1<\/strong><\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p><strong>Customer 2<\/strong><\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p><strong>Customer 3<\/strong><\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p><strong>Customer 4<\/strong><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" style=\"width:288px;height:19px\">\n<p>Permitted<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>56<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>73<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>48<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>67<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" style=\"width:288px;height:19px\">\n<p>Infected or phishing page<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>44<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>27<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>52<\/p>\n<\/td>\n<td nowrap=\"nowrap\" style=\"width:162px;height:19px\">\n<p>33<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>Why HTTPS?<\/h2>\n<p>Well, when you encrypt the communications you protect users from things like data snooping and man-in-the-middle attacks.<\/p>\n<p>Is it a surprise that bad guys don&#8217;t use HTTPS?&nbsp;Probably not. To be HTTPS you need&nbsp;an SSL certificate, and this generally requires providing&nbsp;personal information &#8211; even for the free ones.&nbsp;In other words, this move to HTTPS&nbsp;will not only help safe browsing but also hopefully make it a little more difficult for people to set-up nefarious web properties.<\/p>\n<p>For more information on SSL you can read our<a href=\"\/blog\/cybersecurity\/website-security-and-ssl-certificates-qa-matt-larose\"> interview with our in-house expert<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Well, the time is now here. Starting this week, Google\u00a0Chrome will start sending \u201cnot secure\u201d warnings to every user visiting a non-https\u00a0site. We took a look at our own threat blocking data to see how often HTTP sites are classified as malicious.\u00a0<\/p>\n","protected":false},"featured_media":2237,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Another nail in the coffin for HTTP - CIRA","description":"Well, the time is now here. Starting this week, Google\u00a0Chrome will start sending \u201cnot secure\u201d warnings to every user visiting a non-https\u00a0site. We took a look a"},"footnotes":""},"topic":[1066],"class_list":["post-42013","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blogue","cira_topic-cira-topic-cybersecurity-fr","cira_author-robwilliamson-fr"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42013\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/media\/2237"}],"wp:attachment":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/media?parent=42013"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/topic?post=42013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}