Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Author of the embedded tweet here. I'd like to clarify, since my tweet was vaguely imprecise and this post sadly got it wrong.

The official timeline is on Google Online Security blog [1]. BUT you have to replace "41" with "42" [2].

SO, what changes? From version 42, the current "beta", which according to schedule [3] should become "stable" in a week on the 14th:

- certs that expire in 2016 will be yellow

- certs that expire after 2016 (like xkcd's) will be red

Nothing else will change after 42, and Firefox will follow next year [4]. Certs expiring in 2015 are fine.

Also note that this only affects the lock icon and "https" color, there will be no warning screen AND no connection will be blocked.

EDIT: thanks to the author for amending.

[1]: http://googleonlinesecurity.blogspot.co.uk/2014/09/gradually...

[2]: https://twitter.com/sleevi_/status/585429689646260224

[3]: https://docs.google.com/presentation/d/1uv_dNkPVlDFG1kaImq7d...

[4]: https://twitter.com/sleevi_/status/585429901848608769



Thanks for the reminder that this is coming. I think that sites whose sub-resources come under certs under long-lived SHA-1 intermediates may have problems—they'll be treated as "active mixed content."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: