
But wait, there’s more!
This isn’t the last change that Google has in store for us either. Google just announced this May that they are also changing how they handle HTTPS sites in September 2018 as well. Chrome 69 will stop displaying the “Secure” verbiage in the address bar and just go back to the lock symbol. Their plans are to eventually not display any indication at all when a site uses HTTPS and only highlight when they are NOT using HTTPS. Here’s what you can expect to see in September.

Preparing the Help Desk
So what’s the impact to us as security professionals? First, we need to make sure our desktop support staff have been informed of the change and are ready to respond to questions. It does not inspire confidence when someone calls up support and the expert on the other side is surprised by the change and is trying to figure out what is going on. The support folks need to be prepared and ready to go. They also need to understand that this only impacts those who use Chrome. Users of Edge, Firefox, Safari, etc will not receive a change in how HTTPS sites are handled. This will be something to deal with until these browsers decide to follow Chrome’s lead.Migrating to HTTPS
Next, it is time to take a look at the sites your company is hosting. Are they using HTTPS? Are they enforcing HTTPS? If not, then it’s time to start asking what the impact of getting tagged with a “Not secure” label is in the address bar. On top of what the end users think of this change, you need to be ready for what people inside the business will think. Politics is real in the work place and if the VP of Marketing just came in freaking out because a bunch of web sites are marked as insecure, then you just lost some political capital. So don’t wait for that unfortunate event and try to get out ahead of it. Explain what is happening to people (such as our fictional VP of Marketing) and ask them if they want to start moving the sites to HTTPS.Obviously, any change to use HTTPS is going to require SSL/TLS certificates to make the encryption possible. There are a number of different types of certificates you can select and they each have different benefits. DigiCert, our Security Weekly partner, has created a page with information to help you with this process. You can check out this resource by visiting digicert.com.Beyond certificate selection, there are other things we need to do to prepare sites to use HTTPS as well. Missing some of these can cause some real headaches and emergency changes to fix the fallout.-
- Configure your SEO tools to use the HTTPS version of your sites ahead of time. If you forget to reconfigure these, then you’ll start losing data in your analysis tools and indexing from search engines.
- Do you have hard coded links to HTTP resources within your web site? Those will need to be changed to use HTTPS instead.
- Do you have redirects in place to send users to the HTTPS link for resources? Old links live for a long time on the internet, so you need to have redirects in place to seamlessly send users to the correct location.
- You may need to make changes to CDN settings, load balancers, proxies and more. Anything that is configured to serve content over HTTP will need to be checked out.



