--- title: "Sean Wright -- Google Chrome and the Case of the Disappearing HTTP" url: https://appsecpodcast.com/sean-wright-google-chrome-and-the-case-of-the-disappearing-http/ date: 2018-07-30 duration_seconds: 1472 guests: ["Sean Wright"] topics: ["Secure Development"] audio: https://www.buzzsprout.com/1730684/episodes/8122679-sean-wright-google-chrome-and-the-case-of-the-disappearing-http.mp3 transcript: true --- # Sean Wright -- Google Chrome and the Case of the Disappearing HTTP *July 30, 2018 · 25 min* with [Sean Wright](https://appsecpodcast.com/guests/sean-wright/) on [Secure Development](https://appsecpodcast.com/topics/secure-development/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122679-sean-wright-google-chrome-and-the-case-of-the-disappearing-http.mp3) ## Show notes What changed when Chrome began labeling ordinary HTTP pages as not secure, and why did that decision provoke resistance? Application security practitioner Sean Wright explains the browser changes in their 2018 context and makes the case for protecting every website with TLS. He separates encrypted transport from trust in a website, examines how unencrypted traffic can be read or modified, and discusses the objections that complicated wider HTTPS adoption. The conversation covers accessible certificate options such as Let’s Encrypt, the role of Cloudflare, and the usability benefits of safer browser defaults. Sean also explains how HTTP Strict Transport Security and preload lists address downgrade opportunities. It is a useful historical discussion of the shift from optional encryption toward an HTTPS-first web. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Sean Wright: → [Sean Wright’s blog](https://blog.sean-wright.com/) → [Sean Wright’s portfolio](https://portfolio.sean-wright.com/) Mentioned in this episode: → [Let’s Encrypt](https://letsencrypt.org/) → [HSTS Preload List](https://hstspreload.org/) → [HTTPS Everywhere — retired browser extension](https://www.eff.org/https-everywhere) Chapters: 00:00 Chrome, HTTP, and Sean Wright 01:49 Sean’s route from development into security 03:23 What TLS protects 04:11 Why every website needs encrypted transport 05:34 The controversy around HTTP warnings 07:45 How unencrypted traffic can be modified 08:46 Misinformation and objections to HTTPS 10:34 Let’s Encrypt and accessible certificates 16:20 Safer defaults and usable security 20:22 HSTS headers and preload protection 22:38 Resources for understanding the change ## Transcript *3,593 words · assemblyai* **0:01 Chris Romeo:** Hey folks, welcome to season 4 of the Application Security Podcast. On this episode, I'm joined by Sean Wright, and we speak about Google Chrome and the case of the disappearing HTTP. Google made some changes in regards to how they handle the HTTP protocol just recently, and Sean breaks it down for us and also talks about TLS and other crypto things in regards to web application security. For purposes of this interview, Sean is not representing his employer, but is in fact speaking on behalf of only himself. We hope you enjoy. The Application Security Podcast. Here we go. Alright, we are here at AppSecEU once again, and we are going to talk about TLS and integrity. Sean, first of all, why don't you introduce yourself? **1:15 Sean Wright:** Great, well, thanks for having me, Chris. So I'm Sean Wright. I work at— currently work at SecureWorks. And my background is, well, was development primarily, but I've always had an interest in security. And slowly along the years, I've moved into an AppSec role. And yeah, and today I'm one of our lead AppSec security engineers on our team. **1:49 Chris Romeo:** Okay, so, uh, what— so we always ask our guests here what their security origin story is. So where did your security superpowers originate from? If there was a comic book, what's the first episode sound like? **2:01 Sean Wright:** All right, um, so I would have to go back to university. Um, it started off with a security course that was primarily focused on network security at the time. But I really got excited with the whole notion of trying to test the bounds of breaking things, exploiting things, and then learning how to protect them by using those type of approaches. And that really sparked my whole interest in security from there. **2:37 Chris Romeo:** Okay, so now did you— so you said you were a developer as well, you had a development background. So were you an AppSec focused developer, or did you start— would you start programming in? **2:46 Sean Wright:** So primarily I started programming in Java in university, then I moved on to a bit of C, okay, and then back to Java. Um, I've always tried to delve into security while doing that, but I wouldn't say it was primarily focused on AppSec. And then as I moved into my current company, I focused a lot more on AppSec. Just because who we are. And then from there, it's moved on to myself moving on to our security engineering team that I really grew on the app side. **3:23 Chris Romeo:** Okay, and so the, the issue that we want to talk about here today is in regards to TLS and integrity. So why don't you give us just a real quick 30-second overview for those who— we may have some people who don't know TLS, so give us a quick overview. What is TLS? **3:41 Sean Wright:** Right, so TLS is a protocol that's used to protect the transmission of data between 2 systems, typically a client and server. It encrypts the data as well as ensures that that data cannot be tampered with. That is the long and short of it. It also has some kind of authenticity to it, so making sure that data can't come from a resource that you don't trust. **4:11 Chris Romeo:** And so in our modern web application world, TLS should be used for every web application that's out there? **4:20 Sean Wright:** Yes. **4:21 Chris Romeo:** And so if— it's hard to imagine somebody having a web application that does not use Encryption at this point, but they may be out there floating around somewhere. **4:31 Sean Wright:** So if you look at the, the history of the internet, it started with HTTP. There was no HTTPS at the time of the initial beginnings of the internet, and as time moved on, we've grown more and more towards HTTPS, and now you suddenly see a bigger upsurge in sites using HTTPS. And the industry is moving towards a direction where HTTPS is now going to become the default and HTTP will be more the exception. Looking at the likes of Google now marking sites, it's— I think it's on the 28th of July they released their version, I think it's 68, that will now mark all sites, all HTTP sites, as not secure. **5:20 Chris Romeo:** That's in the Google Chrome browser, right? **5:22 Sean Wright:** Google Chrome. Firefox will only support new features on HTTPS, and I suspect many of the browsers will follow Chrome's suit. **5:34 Chris Romeo:** Yeah, and so I guess if there's anybody out there who's for some reason not using encryption at this point in their web applications, it's hard to imagine that person could be out there, but if they are, they need to be doing that now. So What's the— I guess, what's the controversy in the world of TLS right now? **5:53 Sean Wright:** So, one of the things that some of those people who are advocating against this move by Google is that the information being sent is public and easily accessible. And this is true. HTTPS doesn't really resolve anything in terms of that aspect. I can simply just go to the site and get the information anyway. **6:21 Chris Romeo:** Are you talking about the information in the certificate? **6:22 Sean Wright:** No, the actual information. Say I go to, I don't know, Joe Bloggs' website, publicly accessible. All the information on that page is publicly accessible. There's nothing sensitive about that information. That is true. But if I go and view that site over plain HTTP, a malicious actor could then do a man-in-the-middle and alter the content that's sent back. **6:51** Okay. **6:52 Sean Wright:** And the way I view it is there's 2 kind of avenues to that. They could either modify the content of the site itself— think like fake news. **7:02 Chris Romeo:** Yep. **7:02 Sean Wright:** Perfect opportunity for nation-states to spread propaganda. And then the other is to inject malicious content into there. B-Fox, personally I would do that if I was a malicious person, but there's other things such as spyware, crypto miners, good example today. Recently Tor, in fact I think it was the beginning of the week, they put a tweet out stating that Egypt was working with their ISPs to inject I think it was adware into non-HTTPS sites. **7:45 Chris Romeo:** Okay, so the only thing that makes that possible is the fact that it's HTTP, it's unencrypted, right? **7:53 Sean Wright:** That— **7:53 Chris Romeo:** so if you have— so, so if you have— if you're using HTTPS with TLS, then that's going to provide you protection against those type of injection attacks. And man-in-the-middle style attacks. **8:06 Sean Wright:** Exactly. So when people view HTTPS, they always— a lot of them always think HTTPS is there to solely protect the privacy of data, thinking, perfect example, online banking. I don't want people to know my passwords. I don't want people to see my account numbers. But many people lose sight of the fact that HTTPS is also there for integrity. Making sure that someone can't tamper with the data that's been sent to you. And in this day and age of crypto miners and, and beef hooks and that kind of thing, it's really important that we ensure the integrity of the data as well. **8:46 Chris Romeo:** And so you mentioned that there was some misinformation that might have been going around in the industry, which I'm shocked because, you know, in the security industry, I mean, Somebody might be saying one thing that not everybody else agrees with and whatnot, but what's kind of— what's happening in the world of TLS and conversations about TLS? **9:08 Sean Wright:** So, I don't think it's so much per TLS, it's more around the moves that Google Chrome is making. So, just setting the record straight, HTTP will still work. There's no move to deprecate it. If you have a site running on HTTP, people will still be able to access it. The only difference is they'll now see a little gray not secure in the URL bar. And in fact, Google Chrome is already doing this today. If you go to a site over HTTP and there's an input form, it will show up as not secure, which is why I find this quite surprising that people are taking this current move by Google so strongly. **9:56 Chris Romeo:** So there's people that are opposed? **9:58 Sean Wright:** Yes. **9:59 Chris Romeo:** To this change? **10:00 Sean Wright:** Yes, and some of the arguments I can kind of see. So one of the arguments is customers might move away from sites that have the not secure on them. So think really small businesses who do not, who do not have the technical expertise I can kind of see that argument, but at the same time, there's a lot been done over the years to make HTTPS really simple. Let's Encrypt. I did the other day. It took me 30 seconds. **10:34 Chris Romeo:** Yeah, what's— just for those that might not know, what's Let's Encrypt? **10:38 Sean Wright:** Sure. So Let's Encrypt is a CA, which is certificate authority, It's responsible for issuing certificates, but the way they've gone about it is twofold. One, they are free. That was certainly the biggest hurdle before. **10:53 Chris Romeo:** Yeah, because sometimes you could— they could charge you up to $500. **10:57 Sean Wright:** Bro, exactly. Certificates were expensive, and for small company or personal use, it— that was one of the biggest hindrances. Let's Encrypt has completely been a game changer in that. And then the other thing that they've done a really good job of is the automation. Um, run a little tool, you don't need to know the complexities behind creating a CSR, which is a signing request, to get a certificate. It does that all for you. You just enter in a few details and it's done. Not only that, it sets up the appropriate cron jobs, automated tasks to make sure that the certificate's automatically updated. **11:41 Chris Romeo:** And they regenerate every 90 days. So unlike a commercial certificate that might regenerate once a year, once every 2 years, you actually are getting, I would say, a higher level of security for the cost of zero. **11:55 Sean Wright:** Exactly. **11:56 Chris Romeo:** Which is a great feature. **11:57 Sean Wright:** And it's trivial to set up. I mean, there's probably hundreds of blog posts out there illustrating how you set up Let's Encrypt. **12:06 Chris Romeo:** Yeah. **12:07 Sean Wright:** Cloudflare is another one. Troy Hunt actually set up a series where he gave a set of instructions how to set up Cloudflare in front of your site. So while the connection between Cloudflare and your site might not be encrypted, that certainly reduces the risk of significantly than to the entire internet. And again, that's even simpler. It's a few mouse clicks. **12:35 Chris Romeo:** Yeah, yeah. So I mean, and so Cloudflare, people usually think about that from a DDoS perspective of protection, but who knew it could provide some additional security as well? After the break, Shaun describes the thought process going through people's minds as a result of this change in Google Chrome. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. **13:16 Sean Wright:** I often think The same, along the same lines. And I don't know if it's just a front to change, people are uncomfortable with the change, uncomfortable with something being thrust upon them, or it's they really don't know and they're scared of the change. Some arguments have been used like Google's trying to take over the internet, where Google in fact has no vested interest in this move. **13:48** No. **13:48 Sean Wright:** They're not a CA, so they're not going to gain any monetary value out of certificates. There's even been arguments that Google will be able to track even better. Well, again, they're not a CA, so any OCSP requests or CRL requests and that won't go to Google. If Google was going to do that, they'd bake it directly into the browser without you knowing. **14:14 Chris Romeo:** Yeah, so then they'd have their own cert. They'd embed their own cert so that they could decrypt everything. Yeah, so with them— yeah, that's a good point. With them not being a CA and they really don't have— if anything, this is— if they were the evil empire that was trying to monitor everything, this would actually be the wrong direction. **14:33 Sean Wright:** Exactly. **14:34 Chris Romeo:** They should go the other direction into, no, we're going to penalize you for having an encrypted site. **14:39 Sean Wright:** Exactly. So And I mean, even heard terms like censorship and that, where it doesn't— that's not correct because HTTPS actually helps prevent that. Think nation-states. It's going to be a lot simpler to prevent or tamper with information to their citizens via HTTP than HTTPS. **15:05 Chris Romeo:** Yeah. **15:06 Sean Wright:** But coming back to your point about businesses, I think it's this whole notion around security. It often gets a front in front of it. It's often seen as a barrier. Oh no, these security guys again are interfering and trying to control things, without them realizing that a lot of effort and time from several people in the industry are there trying to help them. **15:33** Yeah. **15:35 Sean Wright:** For example, I went to my local business forum group and I said, look, I'm willing to offer my time free of charge to local businesses because I want to help them. **15:47 Chris Romeo:** Mm-hmm. **15:47 Sean Wright:** The small businesses that don't have the expertise, whereas I do, I'd love to help them to get HTTPS implemented. I kind of got brushed off to the side, and until businesses start actually engaging with scenarios like that and actually grasping at them, I think we're going to have to come to a point where we're going to have to start forcing these kind of things onto them, such as enforcing HTTPS and say, look, if you're not going to comply, well, you're going to get penalized for it. **16:20 Chris Romeo:** Yeah, I think about— I think this really brings us all the way back around to the whole usable security. idea. And when I think of usable security, usable security should be built in and it should be— you should have to make an active decision to disable it, and it should ultimately make the world a better place. And I think this example of Google making this change in the browser is really a positive move towards usable security. It's going to a more secure default, and granted, there is a penalty for those that aren't going to move towards the more secure default. But the average user, think about— I always try to bring it back to the average user, right? You and I, we're not average users, and most people who listen to the podcast here are not average users. The average users are our family members who are— they don't know it. All they know is they put the address in, they hit go, and some magic happens. Dust flies in the background, and then they get some information that comes to them. They don't have any idea what happens. And so when I think about this from their perspective, This is nothing but a positive for them because I don't want them— if they ask me, hey, I had this site HTTP and then it asked me to put my credit card number in, I'm going to say, no, don't do that. And now their browser is going to tell them that. So that's why when I think of this, I think I can't think of a negative that is going to take away. So are there any other arguments that people are throwing out for why we should not do this? **17:49** No. **17:49 Sean Wright:** So another argument that I've seen, and again, it, it does have some sort of backing to it, and is that by having so many warnings, people get fatigued by those warnings. **18:06 Chris Romeo:** That's an aspect of the usable security. **18:08 Sean Wright:** Exactly. But to counter that, this move by Google is moving towards, as you said, secure by default. HTTPS will become the default where Google— I forgot which releases it's coming in, but Google is eventually going to drop the whole secure bits and it'll just become the norm. **18:29 Chris Romeo:** Yep. **18:30 Sean Wright:** And then it will then only start reporting on sites that are not secure, that are an exception to the norm. So it's going to be a lot easier to train users then to say, hey, look, instead of let's look for the green padlock, which is probably one of the worst pieces of advice the industry has given over the years. **18:49 Chris Romeo:** Yep. **18:50 Sean Wright:** To say, hey, look for a red padlock, and if you're not sure, don't continue. That's going to be a lot more secure for a user when it comes to entering in their credit card details. **19:04** Yeah. **19:05 Sean Wright:** Or even just visiting a normal site to make sure that they suddenly don't go get redirected to your site with malware. **19:11 Chris Romeo:** Yeah, so I wonder if the next step is giving enterprises the ability to say if it's a red site, just don't even go. Don't even let the browser go there. Just shut it down. **19:25 Sean Wright:** Well, that's where things like HSTS come in. So today, if you go visit a site with a certificate that's not valid, so it could be signed by a certificate authority that your browser does not trust, Okay. Or the hostname does not match the hostname in the certificate itself, you'll get an error. And if the certificate's expired, you'll get an error on the browser saying whatever message it is. Typically in the past, you've been able to click through those and go, yes, I agree, proceed, blah, blah, blah. With things like HSTS, it's no longer possible to do that. You cannot— if the site's serving up an HSTS header on Chrome, I don't know how it is with the other browsers, but certainly on Chrome, you cannot proceed forward. That's the end of the road. **20:22 Chris Romeo:** Okay, so HSTS is an extension to the HTTP protocol that allows this. There's a special header. **20:29 Sean Wright:** Yes, it's, it's a header that's set That tells the browser that this site will always be served over HTTPS. **20:37 Chris Romeo:** Okay, so then that, that allows the— if somebody tries to inject malware or something and it's coming over a non-secure link, the browser is just gonna ignore it and just drop it. **20:48 Sean Wright:** Exactly. So if, if you— so there's 2 aspects to HSTS headers. One is the browser needs to get it somehow. So typically, as you imagine, you visit a site over HTTP, gets a response, says HTTPS, and then the browser goes, okay, this site from now on will always be served over HTTPS. Even if I try to call over HTTP, the browser will automatically call HTTPS. But that initial step to get to that site over the plain HTTP is still vulnerable to Man-in-the-middle. **21:25 Chris Romeo:** Yep. **21:25 Sean Wright:** So the attacker could then alter the header or remove it or whatever. So that's where HSTS preload comes in, where it's a list of sites that is actually baked into the browser that says these sites are always loaded over HTTPS. So even if you've never visited the site before and go http://google.com, your browser will straight away go to https://google.com. And then obviously if there's any certificate errors, that's the end of the road. You can't proceed any further. **21:58 Chris Romeo:** That's, yeah, that's good. I was using an extension to do that in my browser for years, HTTPS Everywhere, that would just forward you on. So it's good to know that's being done kind of in a more industry-standard manner. **22:11 Sean Wright:** It's probably one of the most powerful tools in the HTTPS arsenal when you combine it with like obviously certificates and the protocol, but if you're doing HTTPS, certainly make sure you're using HSTS headers because it's so easy to do and the benefits of doing it is significant. **22:36 Chris Romeo:** Yep. **22:37 Sean Wright:** So what— **22:38 Chris Romeo:** so I guess just wrapping up this conversation, what— any things you would recommend people take a look at if they want to dive into this issue? Any resources? that you would point people to if they wanted to get into this issue in more depth? **22:52 Sean Wright:** Sure. So there are a few people on Twitter that are good to follow, the likes of Scott Helm, Troy Hunt. They're pretty active in this area, as well as their blogs. They have several blogs or posts on how to set up headers and secure headers. I've also blogged about it on my site as well a bit. I also gave an illustration of why HTTP integrity is so important. Definitely OWASP has some resources on their site as well. Generally, Google HTTPS and integrity, you'll probably find loads of resources on that. **23:40 Chris Romeo:** Loads of good stuff there. **23:41 Sean Wright:** Okay, cool. **23:41 Chris Romeo:** Well, hey, Thanks for taking the time today to share this knowledge with us about TLS and this issue with Google and the browser and everything. I think this is an important issue for AppSec professionals and new AppSec folks to understand and just have some perspective on. So thank you for taking the time. **24:00 Sean Wright:** Well, thank you for having me. It's been a great pleasure. **24:02** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/sean-wright-google-chrome-and-the-case-of-the-disappearing-http/