Upgrade to Pro — share decks privately, control downloads, hide ads and more …

HTTPS - this time it is not optional!

HTTPS - this time it is not optional!

Arne Jørgensen

March 24, 2017
Tweet

More Decks by Arne Jørgensen

Other Decks in Technology

Transcript

  1. Future warnings / “Not Secure” - Incognito mode - Pages

    containing downloads - Everything HTTP http://
  2. Future browser features only HTTPS - Geolocation - Device motion

    / orientation - Encrypted Media Extensions (EME) - getUserMedia - AppCache - Notifications https://sites.google.com/a/chromium.org/dev/Home/chromium-security/deprecating-powerful-features-on-insecure-origins
  3. Misconceptions about HTTPS - My page is HTTP but the

    form posts to HTTPS - My page is HTTP but the form is in a HTTPS iframe
  4. Free, short lived certificates - Let’s Encrypt - Free -

    Only lasts 3 months - Automated - Open Standard
  5. Drupal & HTTPS: Usual Suspects - Mixed content — images,

    CSS, javascript, etc. via HTTP: - Developers - Editors - Drupal behind a proxy thinks it is running HTTP - Cronjobs think it is running HTTP
  6. Connoisseur - Extended Validation (EV) certificates - HSTS - Browser

    preloading - DNS CAA and TLSA records - ...