February 1, 2016 By Douglas Bonderud 2 min read

Passwords are a problem. As noted by Gizmodo, 2015 was a banner year for terrible choices, with “123456” and “password” topping the list. But there’s another problem looming for passwords, even those chosen with care: requests over HTTP.

Despite pressure from search giant Google and the success of projects like Let’s Encrypt, HTTPS adoption remains slow — and password requests over its nonsecure sibling pose big problems for users and site owners alike. As a result, some companies are taking steps: Non-HTTPS password requests are now flagged by Firefox in an effort to beef up security and lower corporate risk.

Warning Signs for HTTP

According to SecurityWeek, Firefox DevEdition 46 will alert developers whether passwords are requested on nonsecure pages, displayed as a lock with a red strikethrough. Mozilla security engineer Tanvi Vyas said the new Firefox effort examines any Web page with an embedded password field against the WC3’s Secure Contexts Specification.

HTTP password fields fail this test since they carry the risk of allowing man-in-the-middle (MitM) attacks using JavaScript for keylogging or changing the destination of the submitted password to an attacker-controlled server.

Even password fields hidden without user interaction are still at risk. The only way to avoid getting flagged is by hosting login pages on HTTPS or migrating an entire website to the secure server. It’s worth noting, however, that only the Developer Edition of Firefox comes with a warning; the public doesn’t get the notification yet.

Risky Business

For businesses, this HTTP risk should act as a wake-up call: Users often duplicate passwords across multiple sites, meaning that a single MitM attack on a nonsecure page could compromise everything from user devices to essential network services. In other words, avoiding HTTPS doesn’t just put company data at risk, but also impacts the privacy of employees and consumers. This privacy is quickly becoming legislated instead of merely assumed, enforced instead of simply encouraged.

Consider a recent Google demonstration at the Usenix Enigma 2016 security conference where the search giant showcased an experimental marking system that flags all HTTP pages as insecure. ZDNet reported that users can get a sneak peek of the feature by typing “chrome://flags/” into the browser’s URL bar and then enabling “Mark nonsecure origins as nonsecure.”

While there’s no official release date for the feature to become a default security setting in Chrome, the Chromium issue tracker indicated the company’s goal is to “mark nonsecure pages like HTTP using the same bad indicator as broken HTTPS.”

Developer warnings from Firefox and experimental efforts from Google lead to the same conclusion: Browser builders are calling out HTTP insecurities to enhance user privacy and encourage HTTPS adoption. Businesses have two choices: Get on board with the transition, or face the backlash as users seek secure alternatives.

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today