Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

81–90 of 212 posts

Re: HTTPS as a ranking signal

#81

Earlier quoted context omitted.

In my country, the cost of a SSL certificate is around 60% of my hosting costs, per year. I run a low-traffic blog with comments disabled, so users do not "interact" with the site in any way - except consume the content. I don't see any benefit from this.

https://www.startssl.com/?app=1 and https://www.namecheap.com/campaigns/2014/reset-the-net.aspx ???

StartSSL is pretty harmful as evidenced by the events after Heartbleed. The certificates are free but they charge you to revoke them, and after we found out about Heartbleed and realized a lot of those free certs were compromised a lot of people refused to pay up for their free keys and continue using the compromised ones. What's more is that StartSSL refused to do the right thing and revoke them, leading a lot of folks to even go as far as petitioning to remove StartSSL from Firefox's Certificate Authorities because any given site using their free certs could be compromised. [0]

[0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744027

Re: HTTPS as a ranking signal

#82
post #43

Considering the importance of HTTPS to, in Google's words, "[making the] Internet safer more broadly", this seems like a good time to again suggest that Google enable HTTPS for Google Analytics by default[1]. Google Analytics is on 50.8% of the top million domains on the Internet, and on 26.96% of a randomly selected 48.5 million domains[1]. Of the 42 billion links analyzed in my research, over 48% of them had Google…

the default noted there seems fine? if HTTPS, then GA uses HTTPS, if HTTP, GA uses HTTP

with firefox adding in mixed-content-complaining not too long ago [1], along with IE having it for a while, and apparantly chrome having it too, its best to match protocol to minimize issues for the user

[1]: https://blog.mozilla.org/tanvi/2013/04/10/mixed-content-bloc...

Re: HTTPS as a ranking signal

#83
post #66

Earlier quoted context omitted.

People that write content for websites are not always the same people that build those websites. In this case, the search engine team is entirely separate from the Blogspot team.

> People that write content for websites are not always the same people that build those websites. Wow Seriously? You don't say. Seems the irony escaped you: announcement was made on a Google site that forces (i.e redirects from HTTPS) you to read it over HTTP. If you read closely enough it refers to all of Google, not just "the search engine team" or (Google - Blogspot).

Internet law: Your good post will be ruthlessly torn apart. Agreement is drivel. The best you can hope for is a slightly different point which happens to agree.

Btw, I agree with you, and I think this phenomenon is dumb.

Re: HTTPS as a ranking signal

#85

I'm sorry, but this simply isn't something a search engine should be dictating. Turning enabling SSL into some arms race that panics small businesses into buying millions of new, pointless certificates just isn't very fair. This kind of policy needs to be discussed openly in a suitable forum, e.g. the IETF, not handed down to us by a single company who think they have a right to dictate how the Internet works - and h…

Google is free to use any metric to score their ranking. The difference is this one they are telling us about.

HTTPS is also used to upgrade connections to stuff like HTTP2 and SPDY which give a substantial improvement to speed, which in turns improves satisfaction. So it makes sense to priotise https sites.

Re: HTTPS as a ranking signal

#86
Here's the big differentiation that the now still beta and invite-only Google Domains could take on: assign free wildcard SSL certificate for every domain registered/transferred there.

Re: HTTPS as a ranking signal

#87
post #72

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

Another advantage to we masters with money … why? SSL does not come cheap. Certificates have become cheap but you need your own IP, i.e., shared hosting is a problem and hosting becomes more expensive. Certificate sellers, hosters etc. on the other hand are certainly happy about these new business opportunities – although we all know that SSL is inherently broken. OK, probably still better than nothing! :)

> but you need your own IP

Not anymore, unless you need to support antiquities like IE7 on Windows XP or some ancient Java-based software. SNI works just fine in other cases.

Re: HTTPS as a ranking signal

#88
post #60

Earlier quoted context omitted.

"Having HTTPS support will only get you a very minor boost in rankings." If your livelihood depends on getting traffic from Google - and a lot of sites do - then even a minor boost may equal a lot of money. Plus the fact that you can never know quite how much, so to be safe you must assume it's worthwhile. The problem I have with this move is that to me it appears as Google are furthering their own political agenda.…

Well, if your livelihood depend on Google you do what they say, what's the problem? They did not force you to depend on them, did they?

Depends on your definition of force. They have a monopoly.

Re: HTTPS as a ranking signal

#89
post #19

My issue with SSL everywhere is that I have to effectively buy my domain twice: once for the domain, and one again for the certificate. My registrar should give me a wildcard certificate good for the time I've paid for my domain.

Maybe because there isn't much of demand for that, yet.

Shall the transition come and we'd all perceive HTTPS as a default, it's very likely registrars would also offer certificate signing.

Re: HTTPS as a ranking signal

#90
post #72

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

Another advantage to we masters with money … why? SSL does not come cheap. Certificates have become cheap but you need your own IP, i.e., shared hosting is a problem and hosting becomes more expensive. Certificate sellers, hosters etc. on the other hand are certainly happy about these new business opportunities – although we all know that SSL is inherently broken. OK, probably still better than nothing! :)

I think it would be much nicer if the browser vendors started pushing for DANE + DNSSEC.

Together, they are a quite neat combo and we wouldn't have to pay for certificates anymore.

Post reply on HN