Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

121–130 of 212 posts

Re: HTTPS as a ranking signal

#121

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

Hey Pierre, Quick question. Is the type of certificate also a signal? i.e. self-signed vs plain vs EV?

I assume self-signed will be treat as having no certificate at all, if the reason for the difference in ranking is that a certificate implies the user will more definitely read what the server sends, as a self-signed certificate protected site is just as easy to MitM as one without a certificate at all.

Re: HTTPS as a ranking signal

#122
So what reasonable options does a small to medium site operator now have to buy SSL certs?

For example there is Comodo "FREE" certificate and the one that costs 64.95 Euros.

What is the catch with the free one?

Re: HTTPS as a ranking signal

#123
post #66

Earlier quoted context omitted.

People that write content for websites are not always the same people that build those websites. In this case, the search engine team is entirely separate from the Blogspot team.

> People that write content for websites are not always the same people that build those websites. Wow Seriously? You don't say. Seems the irony escaped you: announcement was made on a Google site that forces (i.e redirects from HTTPS) you to read it over HTTP. If you read closely enough it refers to all of Google, not just "the search engine team" or (Google - Blogspot).

>Seems the irony escaped you

Oh no, I commented on it directly. By the way I noticed you comment on Hacker News, you should probably stop using table-based layouts on your websites.

Re: HTTPS as a ranking signal

#124
post #99
post #93

Earlier quoted context omitted.

Erm... Heartbleed has absolutely nothing to do with what version of OpenSSL you use to generate the cert.

No, but if your SSL certificate has been exposed by Heartbleed, it would be sensible to revoke that certificate to prevent potential spoofing attacks, wouldn't it? StartSSL charge you for revoking that exposed certificate, so your choices are you pay for the revocation, or wait until the certificate expires.

In there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC).

Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost.

OK, they could have done that anyway (or perhaps offered a discount on the revoke charge) as an good will gesture, but they didn't, so what.

Re: HTTPS as a ranking signal

#125
post #99

Earlier quoted context omitted.

No, but if your SSL certificate has been exposed by Heartbleed, it would be sensible to revoke that certificate to prevent potential spoofing attacks, wouldn't it? StartSSL charge you for revoking that exposed certificate, so your choices are you pay for the revocation, or wait until the certificate expires.

In there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC). Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost. OK, they could have done that anyway (or perhaps…

Leaving aside the question of whether their response was reasonable (I see the arguments either way), it turned out that using their service to secure your website was not free.

Re: HTTPS as a ranking signal

#126

Earlier quoted context omitted.

> Google treat the http and https versions of a domain as SEPARATE PROPERTIES. That's not quite accurate. It's on a per-URL basis, not properties. Webmaster Tools asks you to verify the different _sites_ (HTTP/HTTPS, www/non-www) separately because they can be very different. And yes I've personally seen a few cases - one somewhat strange example bluntly chides their users when they visit the HTTP site and tells them…

Nope, we followed the instructions to the tee. Straight 301 redirects from http to https, appropriate canonicals on all pages referencing https, and their SEO has seemingly started from scratch - used to be in position 1 for a variety of important keywords and searches, now they're beyond page 10. Oh, and you can't do a change of address from http://www.whatever.com to https://www.whatever.com - you don't allow it!

This suggests something else is going on. Please post in the forums with the site details.

Re: HTTPS as a ranking signal

#127
post #125

Earlier quoted context omitted.

In there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC). Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost. OK, they could have done that anyway (or perhaps…

Leaving aside the question of whether their response was reasonable (I see the arguments either way), it turned out that using their service to secure your website was not free.

actually, what i think is.. they're as near 'free' as it gets, probably. at least there's no up front cost using them. then its a lottery as to when u need to pay them to revoke... it could still end up cheaper than paying yearly fees for other certs, i imagine.. total cost of ownership or something..

Re: HTTPS as a ranking signal

#128

Earlier quoted context omitted.

Nope, we followed the instructions to the tee. Straight 301 redirects from http to https, appropriate canonicals on all pages referencing https, and their SEO has seemingly started from scratch - used to be in position 1 for a variety of important keywords and searches, now they're beyond page 10. Oh, and you can't do a change of address from http://www.whatever.com to https://www.whatever.com - you don't allow it!

This suggests something else is going on. Please post in the forums with the site details.

Done. Thanks.

Re: HTTPS as a ranking signal

#129
post #109
post #23

Would be more awesome if they offered free certificates and an API to renew them. Right now enabling https is not a one-time investment, since a new certificate has to be requested and installed each time the old one expires. Computers are supposed to bring down cost and automate tedious tasks, for https the opposite is the case. It’s worth mentioning that https://www.startssl.com/ does offer free certificates. But w…

They are free to get, but you have to pay money if you need to revoke that certificate.

Which you don't really need to. Sure it disables all the security, but if you only care about the speed boost/cover your ass part it is a non-issue.

Re: HTTPS as a ranking signal

#130
post #122

So what reasonable options does a small to medium site operator now have to buy SSL certs? For example there is Comodo "FREE" certificate and the one that costs 64.95 Euros. What is the catch with the free one?

Likely nothing relevant - you just can't revocate it, but it should still give you the speed boost.
Post reply on HN