Google Online Security Blog
Follow
HTTPS by default
Chrome will enable "Always Use Secure Connections" by default for all users in October 2026, starting with Chrome 154. This change aims to enhance user safety by prioritizing HTTPS connections and warning users before they access sites without secure protocols. The decision follows a decade of increasing HTTPS adoption, which has now plateaued around 95-99% for public sites. While this represents a significant security improvement, the remaining HTTP navigations, though a small percentage, still pose risks. Attackers can exploit insecure HTTP connections to redirect users to malicious sites, leading to malware or data breaches. The "Always Use Secure Connections" setting, first introduced as an opt-in feature in 2022, will now be the default. This mode will attempt HTTPS connections first and display a bypassable warning if HTTPS is unavailable. To minimize user annoyance, Chrome will avoid repeatedly warning about the same insecure site. The primary remaining use of HTTP is for private, local network sites, where obtaining HTTPS certificates is more complex. However, a new local network access permission in Chrome is designed to facilitate migrating these sites to HTTPS. Before the full rollout, Chrome 147 in April 2026 will enable this setting for users with Enhanced Safe Browsing protections. Website developers and IT professionals are encouraged to test and migrate their sites to HTTPS now. Future work will focus on further reducing barriers to HTTPS adoption, particularly for local network sites.