It seems this was supposed to go in Chrome 41, but was deferred to Chrome 42.
What is the official communications channel from Google on these matters? I can't find anything expect the blog post from September, and absolutely nothing on the supposed deferral. The deadline came and went and I was left crying wolf.
I need something to point to in order to get people to understand the severity of this, and Google is not making it easy.
They also could do a better job of informing webmasters exactly what is wrong with their certificates. If you go to XKCD, for example, Chrome's handling of https is very scary-looking and it has a message about the site using "obsolete cryptography", but it doesn't call out SHA-1 as the culprit or point toward an article explaining what's wrong & how to fix it.
What's also odd is that it says "obsolete security" in that section of the security pane, but it still has a green lock next to it, not the yellow warning. So the text says one thing and the iconography says another, which is very confusing.
Yes, I agree,Its not ideal. But I follow the industry very closely and I trust that Google's team is working on it and nearing some major improvements.
What is the official communications channel from Google on these matters? I can't find anything expect the blog post from September, and absolutely nothing on the supposed deferral. The deadline came and went and I was left crying wolf.
I need something to point to in order to get people to understand the severity of this, and Google is not making it easy.