{"id":38655,"date":"2019-10-31T22:25:05","date_gmt":"2019-10-31T19:25:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej\/"},"modified":"2019-10-31T22:25:05","modified_gmt":"2019-10-31T19:25:05","slug":"chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej","title":{"rendered":"Chrome will begin blocking HTTP resources on HTTPS pages and checking password security","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Google Inc. <noindex><a rel=\"nofollow\" href=\"https:\/\/security.googleblog.com\/2019\/10\/no-more-mixed-messages-about-https_3.html\">warned<\/a><\/noindex> about the change in the approach to handling mixed content on pages served over HTTPS. Previously, a special indicator was displayed when there were components loaded over unencrypted connections (via http:\/\/) on pages served over HTTPS. In the future, it has been decided to block the loading of such resources by default. Therefore, pages served over 'https:\/\/' will only contain resources loaded through a secure communication channel.<\/p>\n<p>It is noted that currently, over 90% of websites are accessed by Chrome users using HTTPS. The presence of unencrypted inserts poses security risks through the modification of unsecured content when there is control over the communication channel (for example, when connecting via open Wi-Fi). The mixed content indicator has been deemed ineffective and misleading, as it does not provide a clear assessment of the page's security.<\/p>\n<p>Currently, the most dangerous types of mixed content, such as scripts and iframes, are already blocked by default, but images, audio files, and videos can still be loaded via http:\/\/. By substituting images, an attacker can inject tracking cookies, attempt to exploit vulnerabilities in image handlers, or commit forgery by replacing the information presented in the image.<\/p>\n<p> The introduction of blocking is divided into several stages. In Chrome 79, scheduled for December 10th, a new setting will appear that allows users to disable blocking for specific sites. This setting will apply to already blocked mixed content, such as scripts and iframes, and will be accessed through the menu that appears when clicking on the lock icon, replacing the previously suggested indicator for disabling blocking.<\/p>\n<p><center><img decoding=\"async\" alt=\"Chrome will begin blocking HTTP resources on HTTPS pages and checking password security\" src=\"\/wp-content\/uploads\/2019\/10\/163057d6723106e4088c356d59f82e0f.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>In Chrome 80, expected on February 4, a soft blocking scheme for audio and video files will be applied, implying automatic replacement of http:\/\/ links with https:\/\/, allowing functionality to be maintained if the problematic resource is also available via HTTPS. Images will continue to load unchanged, but if loaded via http:\/\/ on https:\/\/ pages, an insecure connection indicator will start to appear for the entire page. For automatic replacement to https or blocking of images, site developers can use CSP properties upgrade-insecure-requests and block-all-mixed-content. In the upcoming Chrome 81, scheduled for March 17, automatic replacement of images loaded via http:\/\/ to https:\/\/ will be enforced.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lh5.googleusercontent.com\/jvfl8cszpNDLQxRMfz52dVZXE9uBE6UtxdEWrwz6yfbLrW9ELHZuZOP0Xyq8lhV7-yIR6TA0WY99oI6TroZ6i6VT-MJy1dsBFGfviF3hPu1uQDx9LtxmLcSrre0sjiZ0fWTTMkuc\"><img decoding=\"async\" alt=\"Chrome will begin blocking HTTP resources on HTTPS pages and checking password security\" src=\"\/wp-content\/uploads\/2019\/10\/ea7468e9b0b46b1eff6c2dff76e48c0a.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Additionally, Google <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blog.google\/technology\/safety-security\/password-checkup\/\">announced<\/a><\/noindex> is integrating a new component called Password Checkup into one of the upcoming releases of the Chrome browser, which <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50103\">has been developed<\/a><\/noindex> in the form of <noindex><a rel=\"nofollow\" href=\"https:\/\/chrome.google.com\/webstore\/detail\/password-checkup-extensio\/pncabnpcffmalkkjpajodfhijclecjno\">an external extension<\/a><\/noindex>The integration will introduce tools in Chrome's built-in password manager to analyze the reliability of the passwords used by the user. When attempting to log into any website, the username and password will be checked against a database of compromised accounts with a warning issued in case of any issues. The check will be performed against a database covering over 4 billion compromised accounts that have appeared in user data leaks. A warning will also be issued when trying to use trivial passwords like 'abc123'. <noindex><a rel=\"nofollow\" href=\"https:\/\/storage.googleapis.com\/gweb-uniblog-publish-prod\/images\/PasswordCheckup-HarrisPoll-InfographicFINA.max-2000x2000.png\">statistics<\/a><\/noindex> To maintain privacy when accessing external APIs, only the first two bytes of the hash from the combination of the username and password are sent (using the algorithm<\/p>\n<p> Argon2 <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Argon2\">). The full hash is encrypted with a key generated on the user\u2019s side. The original hashes in Google\u2019s database are also additionally encrypted, retaining only the first two bytes of the hash for indexing. The final verification of hashes matching the provided two-byte prefix is performed on the user\u2019s side using the cryptographic technique of<\/a><\/noindex>The full hash is encrypted with a key generated on the user side. The original hashes in Google's database are also additionally encrypted, and only the first two bytes of the hash are kept for indexing. The final verification of hashes matching the submitted two-byte prefix occurs on the user side using a cryptographic technique.<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Blinding_(cryptography)\">dazzling<\/a><\/noindex>', in which neither party knows the contents of the data being verified. To protect against determining the contents of the database of compromised accounts through brute force by querying random prefixes, the data returned is encrypted in relation to a key generated based on the verified username and password pair. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51612\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0430 \u043e\u0431 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0445\u043e\u0434\u0430 \u043a \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043c\u0435\u0448\u0430\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0430 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u043e HTTPS. \u0420\u0430\u043d\u0435\u0435 \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u043d\u0430 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u043e HTTPS \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432, \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0445 \u0441 \u0431\u0435\u0437 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f (\u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0443 http:\/\/), \u0432\u044b\u0432\u043e\u0434\u0438\u043b\u0441\u044f \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0439 \u0438\u043d\u0434\u0438\u043a\u0430\u0442\u043e\u0440. \u0412 \u0431\u0443\u0434\u0443\u0449\u0435\u043c \u0440\u0435\u0448\u0435\u043d\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u0445 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e. \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0435 \u043f\u043e &#171;https:\/\/&#187;, \u0431\u0443\u0434\u0443\u0442 \u0433\u0430\u0440\u0430\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u0442\u043e\u043b\u044c\u043a\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u044b, \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":28995,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0430 \u043e\u0431 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0445\u043e\u0434\u0430 \u043a \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043c\u0435\u0448\u0430\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Chrome \u043d\u0430\u0447\u043d\u0451\u0442 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c HTTP-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u043d\u0430 HTTPS-\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445 \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0442\u044c \u043d\u0430\u0434\u0451\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0430 \u043e\u0431 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0445\u043e\u0434\u0430 \u043a \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043c\u0435\u0448\u0430\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:25:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:25:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Chrome will start blocking HTTP resources on HTTPS pages and verifying the reliability of passwords | ProHoster","description":"Google has warned about changes in the approach to handling mixed content on.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Chrome \u043d\u0430\u0447\u043d\u0451\u0442 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c HTTP-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u043d\u0430 HTTPS-\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445 \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0442\u044c \u043d\u0430\u0434\u0451\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0430 \u043e\u0431 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0445\u043e\u0434\u0430 \u043a \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043c\u0435\u0448\u0430\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/chrome-nachnyot-blokirovat-http-resursy-na-https-stranitsah-i-proveryat-nadyozhnost-parolej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:25:05+00:00","article:modified_time":"2019-10-31T19:25:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38655","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:55:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:05:22","updated":"2026-01-23 22:55:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38655"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/28995"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}