Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

151–160 of 212 posts

Re: HTTPS as a ranking signal

#151
post #16

I'm interested in statistics (especially from websites with non-technical and international audiences) about what percent of visitors are using browsers/devices that don't support SNI. I don't know how representative this is, but it looks like StatCounter Global Stats [1] says that slightly over 10% of recorded visitors are still using Windows XP, and many of these users won't have SNI support. Small websites without…

http://www.utilitydive.com/ is a US-based news site for the electric utility industry. About 4.5% of visitors are on Win XP and most of those people are using XP. It's trending down pretty sharply; it was nearly twice that at the start of the year.

Re: HTTPS as a ranking signal

#152
post #148

Earlier quoted context omitted.

But did it drop to zero? Are you willing to serve those people a big scary error message?

it's definitely not zero. as for whether or not i'm willing to serve those people a big scary error message, i'm not sure yet. It's something we're actually going to have to come to a decision on in the next couple weeks though, this isn't a hypothetical for me. a lot of my traffic is repeat, so we'll probably do a good campaign to push users off IE8 this fall and officially declare it unsupported in Nov/Dec.

Yeah, I didn't mean for that to come off as flip. We struggle with it too. Unfortunately we've still got 3 or 4 percent IE/XP on some sites, which feels like a lot to lose.

Re: HTTPS as a ranking signal

#153
post #54

It probably bugs me the way it does, because this "signal" has nothing to do with the contents or the usability of the web site (unlike speed, validity of HTML or, well, content itself), but is purely a "we just think you should do X" situation.

It has to do with preventing mass surveillance by default.

Re: HTTPS as a ranking signal

#154

Wow. For those needing to support non-SNI browsers, this is going to become a real IPv4 address land-grab. IPv6 is disturbingly uncommon still...

supporting non-SNI browsers is less common. Over the last two years i've seen a huge drop off in ie8/XP traffic on my sites.

Android 2.x doesn't support SNI either, it's not just IE. (20% of Android users: https://developer.android.com/about/dashboards/index.html)

But I agree, it has dwindled rapidly. :-)

Re: HTTPS as a ranking signal

#155
post #43

Considering the importance of HTTPS to, in Google's words, "[making the] Internet safer more broadly", this seems like a good time to again suggest that Google enable HTTPS for Google Analytics by default[1]. Google Analytics is on 50.8% of the top million domains on the Internet, and on 26.96% of a randomly selected 48.5 million domains[1]. Of the 42 billion links analyzed in my research, over 48% of them had Google…

Friendly reminder - there's a free, pro-privacy and open-source solution available:

http://piwik.org/

Re: HTTPS as a ranking signal

#156

Earlier quoted context omitted.

Link? The numbers I see for this service are: "Base certificate costs $165.00 for three domains" "After the third domain, each additional domain costs just $45.00" http://www.positivessl.com/multi_domain_ssl_certificate.php

https://www.namecheap.com/security/ssl-certificates/comodo/p...

That's only for 3 domains, not 100. 3 domains at $30/year is $10/year/domain which is no different than buying individual certs.

The multidomain cert supports up to 100 domains, but the cost is $29.88/year for the first 3 included, plus an additional $12.88/year for each additional domain.

Under this price structure, you could have 100 domains covered with one certificate, but it would cost you $1,279.24 per year for that single certificate.

Re: HTTPS as a ranking signal

#157
post #156

Earlier quoted context omitted.

https://www.namecheap.com/security/ssl-certificates/comodo/p...

That's only for 3 domains, not 100. 3 domains at $30/year is $10/year/domain which is no different than buying individual certs. The multidomain cert supports up to 100 domains, but the cost is $29.88/year for the first 3 included, plus an additional $12.88/year for each additional domain. Under this price structure, you could have 100 domains covered with one certificate, but it would cost you $1,279.24 per year for…

That's only for 3 domains, not 100.

Nobody said otherwise.

3 domains at $30/year is $10/year/domain which is no different than buying individual certs.

The problem was that shared hosting plans didn't support multiple certs, forcing people with a few sites to purchase a plan for each. The multidomain cert solves this problem.

Re: HTTPS as a ranking signal

#158

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

Hey Pierre, Quick question. Is the type of certificate also a signal? i.e. self-signed vs plain vs EV?

Self-signed is worse than not having one. Don't do that.

Re: HTTPS as a ranking signal

#159
post #66

Earlier quoted context omitted.

> People that write content for websites are not always the same people that build those websites. Wow Seriously? You don't say. Seems the irony escaped you: announcement was made on a Google site that forces (i.e redirects from HTTPS) you to read it over HTTP. If you read closely enough it refers to all of Google, not just "the search engine team" or (Google - Blogspot).

Internet law: Your good post will be ruthlessly torn apart. Agreement is drivel. The best you can hope for is a slightly different point which happens to agree. Btw, I agree with you, and I think this phenomenon is dumb.

Another internet law: Do as Google says, not as Google does.

Re: HTTPS as a ranking signal

#160
post #141

I'm surprised by the amount of negative comments. Independently of what do you think about HTTPS and CAs in general. Given there the alternative currently is plain text, I'm actually surprised that it wasn't a signal before.

I see this has negative for several reasons : * Certificates are expensive (to buy _and_ to manage) * Crypto is hard and there will be a lot of screw up with inadequate certs in the wild for a long time. Just having a certificate does not mean much if it weak or broken. * Can't help the feeling it's an indirect push for cloud business hence possibly eating the margin of freelancers / ISV * Security Theatre : a lot of…

Some refuting instead of down voting ?
Post reply on HN