Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

131–140 of 212 posts

Re: HTTPS as a ranking signal

#131
post #125

Earlier quoted context omitted.

In there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC). Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost. OK, they could have done that anyway (or perhaps…

Leaving aside the question of whether their response was reasonable (I see the arguments either way), it turned out that using their service to secure your website was not free.

> it turned out that using their service to secure your website was not free

All they claim is to provide free certificates for non-commercial use, and that they do provide. If people read something else into that it isn't because they were deliberately led to.

Though many people picking up a cert without really knowing the infrastructure won't know about revocation infrastructure and such so might have mislead themselves by having not read the Ts&Csm.

Re: HTTPS as a ranking signal

#132
Let's kill small ISV and raise the bar of entrance to the internet. Oh certificate management is too complex and expensive for too little ROI ? Well see, here we have a nice "cheap to the eye" cloud solution just for you.

Security isn't the priority here. Selling cloud is.

Edit: IMHO, same goes for SPDY/HTTP2 by the way

Re: HTTPS as a ranking signal

#133
post #106

Earlier quoted context omitted.

OK, good to know – although there are apparently still some restrictions according to comments by other HN users. SSL is still more expensive, though. For most small content websites ( Example: Shared hosting with 4 WordPress blogs, SSL is active but only to access the control panel since the hoster allows SSL only for one domain. Costs incl. a cheap SSL certificate: 110 USD/year. All 4 WordPress blogs with SSL, i.e.…

PositiveSSL Multi-Domain certs allow enterprises and web hosts to secure multiple websites by including up to 100 domains within a single certificate. $29.88/year.

Link? The numbers I see for this service are:

"Base certificate costs $165.00 for three domains"

"After the third domain, each additional domain costs just $45.00"

http://www.positivessl.com/multi_domain_ssl_certificate.php

Re: HTTPS as a ranking signal

#134
post #107

Earlier quoted context omitted.

Get a free cert instead?

Free certificates tend to result in ugly warning messages in browsers … Cheap certificates are available, however, they are still not for free. And hosting more than one domain with SSL is a problem too with most hosting providers if you do not want to book additional hostings.

> Free certificates tend to result in ugly warning messages in browsers

StartSSL is free, and as long as you correctly bundle the intermediate cert (something you have to do with many, many other CA's anyway) your SSL will look no different than a $100+/year one from an A-list provider.

Re: HTTPS as a ranking signal

#135
post #106

Earlier quoted context omitted.

> but you need your own IP Not anymore, unless you need to support antiquities like IE7 on Windows XP or some ancient Java-based software. SNI works just fine in other cases.

OK, good to know – although there are apparently still some restrictions according to comments by other HN users. SSL is still more expensive, though. For most small content websites ( Example: Shared hosting with 4 WordPress blogs, SSL is active but only to access the control panel since the hoster allows SSL only for one domain. Costs incl. a cheap SSL certificate: 110 USD/year. All 4 WordPress blogs with SSL, i.e.…

StartSSL is 0 USD/year. There should be more providers like them, and if the barriers to entry ($$$$) weren't so insurmountable, I'd happily start one myself. But they do a good job, and I've used several free certs from them with no issues.

https://www.startssl.com/?app=1

You also don't need "expensive" hosting, it just needs to support SSL which is free from a technical perspective. You no longer need a dedicated IP either.

Re: HTTPS as a ranking signal

#136
post #90
post #72

Earlier quoted context omitted.

Another advantage to we masters with money … why? SSL does not come cheap. Certificates have become cheap but you need your own IP, i.e., shared hosting is a problem and hosting becomes more expensive. Certificate sellers, hosters etc. on the other hand are certainly happy about these new business opportunities – although we all know that SSL is inherently broken. OK, probably still better than nothing! :)

I think it would be much nicer if the browser vendors started pushing for DANE + DNSSEC. Together, they are a quite neat combo and we wouldn't have to pay for certificates anymore.

And emails too then, no ?

Lot of critical information is still transmitted through emails.

Re: HTTPS as a ranking signal

#137

Earlier quoted context omitted.

> I don't see how is this any different from any other signal that Google uses to prioritize sites. «Oh, they're screwing up before, too? Then I guess it's alright» > How does it prevent decentralization? Because only a handful of companies can issue certificates.

«Oh, they're screwing up before, too? Then I guess it's alright» How is it screwing up? How are they supposed to run a search engine without prioritizing? "Here's 30000 results, we've randomly sorted them for you"? Because only a handful of companies can issue certificates. Fair enough.

> How are they supposed to run a search engine without prioritizing?

Maybe quality of content? If the best info gets buried because they can't afford a cert or don't have a need for one then this hurts the Internet.

Re: HTTPS as a ranking signal

#138
post #70

Earlier quoted context omitted.

heartbleed was much much worse than unencrypted logins.

I agree that the worst case scenario is much worse; I don't see how it was much worse for the average website of a small business.

Maybe because it can lead to security theatre ? People feeling safe when there not really safe ?

I think that's what hnha meant.

Re: HTTPS as a ranking signal

#139

Makes sense. The reason seo spam is effective is because it's so cheap to get a new site (or ten thousand new sites) up and running. If you make that cost $50 per domain for the ssl cert, that will help ensure all those sites sift nicely down to the bottom of the rankings. Bonus points if they allow a single bad site to tarnish the reputation of all sites under a milti domain cert. We could have had this from the sta…

I do agree, however remember that you can get SSL certs from $9 (e.g. from NameCheap). You might be able to pay lower if you shop around too. Also even if it was used as a fairly strong ranking signal, if Google still approach their rankings like they do now, spammers might still have sufficient ranking 'weight' to overcome a lack of SSL certificate.

Don't forget you have to manage your certs. It's an extra burden.

Let's say I am a freelancer, I make website for small restaurant. Until now I could make a website with frontpage, menu and gallery put it on a server and be done with it and collect a monthly fee.

Now, you have to manage the cert, that is say every year re-issue a new cert and invalidate the old. It adds costs. Without much if any benefits for some class of websites.

Re: HTTPS as a ranking signal

#140

Earlier quoted context omitted.

PositiveSSL Multi-Domain certs allow enterprises and web hosts to secure multiple websites by including up to 100 domains within a single certificate. $29.88/year.

Link? The numbers I see for this service are: "Base certificate costs $165.00 for three domains" "After the third domain, each additional domain costs just $45.00" http://www.positivessl.com/multi_domain_ssl_certificate.php

https://www.namecheap.com/security/ssl-certificates/comodo/p...
Post reply on HN