Google Chrome Targets Insecure Downloads on Secure Pages

Google Chrome implements a phased approach to block non-HTTPS file downloads initiated on secure web pages to protect user privacy and security.

Google Chrome takes a major step toward a safer web by gradually blocking insecure file downloads that start on secure HTTPS pages. These mixed content downloads pose serious risks, as attackers easily swap out insecurely downloaded executables for malware or intercept sensitive documents like bank statements.

The browser handles this transition through a carefully staged rollout to minimize disruption for both users and developers. High-risk file types, such as executable programs, face restrictions first, while less dangerous formats follow in subsequent releases. This strategy quickly mitigates the worst threats while giving website owners time to update their servers.

Chrome kicks off this process with quiet console warnings for developers in earlier versions before introducing visible warnings and eventual blocks in Chrome 84. Desktop platforms like Windows, macOS, Linux, and Chrome OS receive these security updates first as Google works to completely remove support for insecure downloads.

Read More at the original source →