A major change is coming to Firefox in the near future: if you use any form on your site, and it isn’t secured with HTTPS, the browser will mark it as insecure.
New York, are you ready?
We’re building Momentum: an all killer, no filler event this November.
On that build, you’ll see a lock with a cross through it when there’s a form element on the page but no HTTPS. This will happen even if you have HTTPS enabled but the form itself isn’t delivered over the secure protocol.
If it’s rolled out to all versions of Firefox, the change will have wide-reaching implications for a number of sites, since many include forms for things like newsletter signups but don’t bother encrypting those in transit as it’s not exactly sensitive information.
Mozilla says that the change isn’t planned to be dropped into the beta or general release Firefox yet, but it’s expressed the intent in the past to make the change eventually.
It’s good progress for browser builders to enforce stricter rules around HTTPS, given that it’s still frequently misused or forgotten. Google also added a feature to Chrome that will push developers to use HTTPS this week.