Google suggested blocking the download of certain files via HTTP from links on HTTPS sites

Google has proposed that browser developers implement a practice to block the downloading of dangerous file types when the referring page is opened over HTTPS, but the download is initiated without encryption over HTTP.

The problem lies in the fact that during the download, there is no security indication; the file is simply downloaded in the background. When such a download is initiated from a page opened over HTTP, the user is already warned in the address bar about the website's insecurity. However, if the site is opened over HTTPS, the address bar shows an indicator of a secure connection, which may give the user a false sense of security about the download being initiated over HTTP, while the content may be tampered with due to malicious activity.

It is proposed to block files with extensions such as exe, dmg, crx (Chrome extensions), zip, gzip, rar, tar, bzip, and other popular archive formats that are considered particularly risky and are commonly used to distribute malware. Google plans to add this proposed block only in the desktop version of Chrome, as the Chrome for Android already implements blocking of suspicious APK package downloads through Safe Browsing.

Representatives from Mozilla welcomed the proposal and expressed a willingness to move in this direction but suggested gathering more detailed statistics on the possible negative impact on existing download systems. For instance, some companies practice unsafe downloads from secure sites, but the threat of compromise is mitigated through digital signature assurance of the files.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster