Geeks for your information
Google Chrome engineers want to block some HTTP file downloads - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Browsers News & Tips (https://www.geeks.fyi/forumdisplay.php?fid=109)
+--- Thread: Google Chrome engineers want to block some HTTP file downloads (/showthread.php?tid=6593)



Google Chrome engineers want to block some HTTP file downloads - silversurfer - 10 April 19

Quote:Google wants to block some file downloads carried out via HTTP on websites that load via an HTTPS URL.

According to a proposal the browser maker has put forward yesterday, only the download of certain "high-risk" file types will be blocked by default.
 
This includes EXE (Windows application binary), DMG (Mac application binary), CRX (Chrome extension package), and all the major archive formats, like ZIP, GZIP, BZIP, TAR, RAR, and 7Z. These file types are considered "high-risk" because they are most likely to be abused to hide malware.

The idea, according to Google, is to block any of these files when the download takes place via an HTTP connection, even if the site the user is downloading the data from is loaded via secure HTTPS.
 
Google said it's currently not thinking of blocking downloads started from HTTP sites, since the browser is already warning users about the site's poor security via the "Not Secure" indicator in the URL bar.
 
The plan is to block insecure downloads on sites that appear to be secure (loaded via HTTPS) but where the downloads take place via plain ol' HTTP.

SOURCE: https://www.zdnet.com/article/google-chrome-engineers-want-to-block-some-http-file-downloads/


RE: Google Chrome engineers want to block some HTTP file downloads - harlan4096 - 12 April 19

Additional info: https://www.ghacks.net/2019/04/11/chrome-may-block-some-high-risk-downloads-soon/