Google's Chrome browser will start labelling insecure FTP sites

Ongoing effort to secure all web traffic by Google

Unencrypted FTP transfers will soon be labelled as insecure in Google Chrome, the search giant has announced.

According to a posting on the Chromium Google Groups forum, the move forms part of the firm's "ongoing effort to accurately communicate the transport security status of a given page".

Google employee and Chrome security team member Mike West said that Google would label resources delivered over the FTP protocol as "Not secure", beginning in Chrome 63 (sometime around December, 2017).

"We didn't include FTP in our original plan, but unfortunately its security properties are actually marginally worse than HTTP (delivered in plaintext without the potential of an HSTS-like upgrade). Given that FTP's usage is hovering around 0.0026% of top-level navigations over the last month, and the real risk to users presented by non-secure transport, labelling it as such seems appropriate," he said.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

He encouraged developers to follow the example of the linux kernel archives by migrating public-facing downloads (especially executables) from FTP to HTTPS.

FTP dates back to 1971 and does not encrypt data passing between clients and servers, this means that traffic can be read by anyone able to perform packet capture on the network. It can be secured with SSL/TLS (this is FTPS), but many browsers do not support this.

"Because FTP usage is so low, we've thrown around the idea of removing FTP support entirely over the years. In addition to not being a secure transport, it's also additional attack surface, and it currently runs in the browser process," said Chris Palmer, another member of the Chrome security team.

As such, it would appear that branding FTP transfers as insecure will not have an enormous affect on the use of FTP, however, for companies still using the rather ancient technique, the labeling could serve as a means to promote them to upgrade and update thier IT infastructure and processes. 

Featured Resources

How inkjet can transform your business

Get more out of your business by investing in the right printing technology

Download now

Journey to a modern workplace with Office 365: which tools and when?

A guide to how Office 365 builds a modern workplace

Download now

Modernise and transform your sales organisation

Learn how a modernised sales process can drive your business

Download now

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now
Advertisement

Recommended

Visit/hardware/routers/354782/google-nest-wifi-review-a-solid-improvement-but-not-for-long
routers

Google Nest Wifi review: A solid improvement, but not for long

14 Feb 2020
Visit/marketing-comms/unified-communications-uc/354662/google-developing-all-in-one-messaging-app-for
unified communications (UC)

Google developing all in one messaging app for business

29 Jan 2020
Visit/security/privacy/354542/google-looks-to-replace-third-party-cookies-in-two-years
privacy

Google looks to replace third-party cookies in two years

15 Jan 2020
Visit/cloud/cloud-computing/354479/google-adds-partners-to-real-time-translation-tools
cloud computing

Google adds partners to real-time translation tools

8 Jan 2020

Most Popular

Visit/operating-systems/microsoft-windows/354789/microsoft-pulls-disastrous-windows-10-security-update
Microsoft Windows

Microsoft pulls disastrous Windows 10 security update

17 Feb 2020
Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/business/business-operations/354790/hp-shareholders-invited-to-come-dine-with-xerox
Business operations

HP shareholders invited to come dine with Xerox

17 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020