{"id":7243,"date":"2020-02-10T13:55:00","date_gmt":"2020-02-10T13:55:00","guid":{"rendered":"https:\/\/gtechbooster.com\/?p=7243"},"modified":"2026-01-03T15:26:17","modified_gmt":"2026-01-03T15:26:17","slug":"chrome-to-block-http-downloads","status":"publish","type":"post","link":"https:\/\/gtechbooster.com\/chrome-to-block-http-downloads\/","title":{"rendered":"Chrome to block HTTP downloads"},"content":{"rendered":"\n<p>Google Chrome will soon restrict certain files, like PDFs or \nexecutables, from being downloaded via an HTTP connection&nbsp;\u2013 even if they\n are loaded on HTTPS webpages.<\/p>\n\n\n\n<div class=\"gtech-migrated-from-ad-inserter-placement-2\" style=\"text-align: center;\" id=\"gtech-2928121199\"><div style=\"margin-left: auto;margin-right: auto;text-align: center;\" id=\"gtech-4036299830\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/78935\" rel=\"noopener\" class=\"notrack\" aria-label=\"auyvc003\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003.webp\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003.webp 1200w, https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003-768x768.webp 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" width=\"500\" height=\"500\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div><p>HTTPS indicates that a website has an encrypted connection. When  connecting to an HTTP website, browsers merely look up the IP address  and send data over to it in clear text. When using an HTTPS website, on  the other hand, the browser checks that it has a legitimate SSL  certificate before sending data in encrypted form \u2013 preventing man-in-the-middle (MiTM) attacks and more.<\/p>\n\n\n\n<p>With Chrome 56\u2019s 2018 release, <strong>Chrome cracks down on sites that don&#8217;t use encryption<\/strong> ie. HTTP websites with an \u201cinsecure\u201d warning label in the navigation bar.  However, just because websites use an HTTPS connection does not  guarantee that they are safe from all threats. For example, phishing  landing pages can easily make use of SSL certificates.  Similarly, HTTPS websites can still serve up images, scripts or other  file types that are downloaded using the less-secure HTTP connection.<\/p>\n\n\n\n<p>Starting in Chrome 82, set to be released in April, Google wants to \nuproot this issue by first warning users of, and later blocking, \u201cmixed \ncontent downloads,\u201d over HTTP, which could consist of HTTP executables \n(such as .exe and .apk files), archives (like .zip or .iso files), \nmultimedia files (such as .png, .mp3 files) and all other \u201cnon-safe\u201d \ntypes (.pdf, .docx, etc.).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><a href=\"blob:https:\/\/gtechbooster.com\/d4472819-688b-4c04-9f36-ef5c411fa112\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"343\" src=\"https:\/\/gtechbooster.com\/media\/2020\/02\/chrome-to-block-http-downloads.png\" alt=\"Chrome HTTP Blocking Chart\" class=\"wp-image-7244\" srcset=\"https:\/\/gtechbooster.com\/media\/2020\/02\/chrome-to-block-http-downloads.png 1024w, https:\/\/gtechbooster.com\/media\/2020\/02\/chrome-to-block-http-downloads-768x257.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>Chrome HTTP Blocking Chart<\/figcaption><\/figure><\/div>\n\n\n\n<p>\u201cInsecurely-downloaded files are a risk to users\u2019 security and privacy,\u201d said Joe DeBlasio, with the Chrome Security Team, <a rel=\"noreferrer noopener\" href=\"https:\/\/security.googleblog.com\/2020\/02\/protecting-users-from-insecure_6.html\" target=\"_blank\">in a Thursday post<\/a>.  \u201cFor instance, insecurely downloaded programs can be swapped out for  malware by attackers, and eavesdroppers can read users\u2019 insecurely  downloaded bank statements. To address these risks, we plan to  eventually remove support for insecure downloads in Chrome.\u201d<\/p><div class=\"gtech-mid-cont\" style=\"text-align: center;\" id=\"gtech-3981436635\"><div style=\"margin-right: auto;margin-left: auto;text-align: center;\" id=\"gtech-2874190042\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/75343\" rel=\"noopener\" class=\"notrack\" aria-label=\"jesdphis\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis.avif\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis.avif 1179w, https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis-768x950.avif 768w\" sizes=\"(max-width: 1179px) 100vw, 1179px\" width=\"300\" height=\"300\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div>\n\n\n\n<p>Google, which <a href=\"https:\/\/lists.w3.org\/Archives\/Public\/public-webappsec\/2019Apr\/0004.html\" target=\"_blank\" rel=\"noreferrer noopener\">first dropped proposals<\/a>\n around this idea last April, has outlined a roadmap to eventually ban \nthe files downloads in question over the next seven months. Starting \nwith Chrome 82, Google Chrome will first merely warn users if they are \ndownloading executables using an HTTP connection \u2013 then, with Chrome 83 \n(June 2020) the browser will begin to block them. It will do the same \nwith other mixed content downloads until blocking everything in Chrome \n86, set to be released September 2020.<\/p>\n\n\n\n<p>\u201cFile types that pose the most risk to users (e.g., executables) will\n be impacted first, with subsequent releases covering more file types,\u201d \naccording to DeBlasio. \u201cThis gradual rollout is designed to mitigate the\n worst risks quickly, provide developers an opportunity to update sites,\n and minimize how many warnings Chrome users have to see.\u201d<\/p>\n\n\n\n<p>The gradual rollout will also give developers a head start toward  fully migrating to HTTPS by ensuring that downloads on their websites  also use HTTPS connections. Google also said that in the current version  of Chrome Canary (Google\u2019s web browser aimed for developers) and in  Chrome 81 (once it\u2019s released), developers can activate a warning on all  mixed content downloads for testing by enabling the \u201cTreat risky  downloads over insecure connections as active mixed content\u201d flag at  [chrome:\/\/flags\/#treat-unsafe-downloads-as-active-content].<\/p>\n\n\n\n<p>Fausto Oliveira, principal security architect at Acceptto, told Threatpost the move is a \u201cgood idea.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cWe have been using HTTPS as the de facto standard for web pages,  however, annoyingly some implementations such as those mentioned by  Google (i.e. banking statements) come to your browser unencrypted,\u201d he  said. \u201cThis allows anyone in the middle to have access to confidential  data. I hope that this move by Google leads to other browsers following  and also blocking the download of files from unencrypted connections.\u201d<\/p><cite> Fausto Oliveira, principal security architect at Acceptto <\/cite><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">More Information<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/yahoodatabreachsettlement.com\/\">HTTP Cookies are evil<\/a><\/li><li><a href=\"https:\/\/security.googleblog.com\/2020\/02\/protecting-users-from-insecure_6.html\">Chrome Security Team<\/a> <\/li><li><a href=\"https:\/\/lists.w3.org\/Archives\/Public\/public-webappsec\/2019Apr\/0004.html\">Blocking high-risk non-secure downloads<\/a><\/li><\/ul>\n<div class=\"gtech-end-cont\" id=\"gtech-2877495805\"><div style=\"margin-right: auto;margin-left: auto;text-align: center;\" id=\"gtech-2813171537\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/75343\" rel=\"noopener\" class=\"notrack\" aria-label=\"jesdphis\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis.avif\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis.avif 1179w, https:\/\/gtechbooster.com\/media\/2025\/08\/jesdphis-768x950.avif 768w\" sizes=\"(max-width: 1179px) 100vw, 1179px\" width=\"300\" height=\"300\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Google Chrome will soon restrict certain files, like PDFs or executables, from being downloaded via an HTTP connection&nbsp;\u2013 even if they are loaded on HTTPS webpages. HTTPS indicates that a website has an encrypted connection. When connecting to an HTTP website, browsers merely look up the IP address and send data over to it in [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":7266,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1915],"tags":[2657,171,2660,372,425,426,146],"class_list":["post-7243","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ndocs","tag-browser","tag-google-chrome","tag-download","tag-google","tag-hypertext-transfer-protocol","tag-hypertext-transfer-protocol-secure","tag-web-browser"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":6}},"_links":{"self":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/7243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/comments?post=7243"}],"version-history":[{"count":1,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/7243\/revisions"}],"predecessor-version":[{"id":78271,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/7243\/revisions\/78271"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media\/7266"}],"wp:attachment":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media?parent=7243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/categories?post=7243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/tags?post=7243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}