Forum Moderators: phranque
Nonsecure Collection of Passwords will trigger warnings in Chrome 56 for www.example.com
Beginning in January 2017, Chrome (version 56 and later) will mark pages that collect passwords or credit card details as “Not Secure” unless the pages are served over HTTPS.
The following URLs include input fields for passwords or credit card details that will trigger the new Chrome warning. Review these examples to see where these warnings will appear, and so you can take action to help protect users’ data. The list is not exhaustive.
....
The new warning is the first stage of a long-term plan to mark all pages served over the non-encrypted HTTP protocol as “Not Secure”.
[edited by: not2easy at 4:15 pm (utc) on Dec 29, 2016]
[edit reason] See Sticky/TOS [/edit]
Sending and storing passwords in plaintext is the issue which ought to be focused on.
Password field present, warning shown. No password field.. no warning shownYes, at first. Then later (to be determined) the warnings will display on all sites not secure.
Since we mention evidence though, show me the evidence that MITM attacks are a high priority security risk.