Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

161–170 of 212 posts

Re: HTTPS as a ranking signal

#161
post #141

I'm surprised by the amount of negative comments. Independently of what do you think about HTTPS and CAs in general. Given there the alternative currently is plain text, I'm actually surprised that it wasn't a signal before.

I see this has negative for several reasons : * Certificates are expensive (to buy _and_ to manage) * Crypto is hard and there will be a lot of screw up with inadequate certs in the wild for a long time. Just having a certificate does not mean much if it weak or broken. * Can't help the feeling it's an indirect push for cloud business hence possibly eating the margin of freelancers / ISV * Security Theatre : a lot of…

Google is not "enforcing" anything, people react like if you are not going to show up in the results at all, or Chrome won't work via HTTP. HTTPS is signal, just like having a link from a well ranked website like HN is a signal, and probably dozens other.

The points you mention are in fact indicators that someone has put care and resources to make their site work more securely, which says a good thing about the site, which google rewards with some points in their algorithm. Makes perfect sense to me that this will somewhat improve the quality of their results. Would you also complain about google using fast response times as a signal because that "forces" people to pay for better servers?

About your security point, google can not do that without loosing 50% of its customers, I really don't understand what that has to do with the rewarding HTTPS being good or bad. Looks like a red herring.

Re: HTTPS as a ranking signal

#162

Earlier quoted context omitted.

supporting non-SNI browsers is less common. Over the last two years i've seen a huge drop off in ie8/XP traffic on my sites.

Android 2.x doesn't support SNI either, it's not just IE. (20% of Android users: https://developer.android.com/about/dashboards/index.html ) But I agree, it has dwindled rapidly. :-)

20% of android devices, but definitely not 20% of any website's android traffic. the amount of web traffic that comes from those android phones is approximately 0 unless maybe you're in africa or china - the people who still have android 2.x phones aren't browsing the internet with them.

Re: HTTPS as a ranking signal

#163
post #43

Considering the importance of HTTPS to, in Google's words, "[making the] Internet safer more broadly", this seems like a good time to again suggest that Google enable HTTPS for Google Analytics by default[1]. Google Analytics is on 50.8% of the top million domains on the Internet, and on 26.96% of a randomly selected 48.5 million domains[1]. Of the 42 billion links analyzed in my research, over 48% of them had Google…

Sorry to jump in with a tangential reply, but BEWARE of the following! Google treat the http and https versions of a domain as SEPARATE PROPERTIES. This means that even if you 301 every http page to https when you transition, all of your current rankings and pagerank will be irrelevant. You can verify this behaviour for yourself in webmaster tools. I suppose this is because it's possible to serve up different content…

The IO talk covers this. There's a few steps involved beyond just sending a 301 such as putting a rel=canonical on the https site.

Re: HTTPS as a ranking signal

#164
post #19

My issue with SSL everywhere is that I have to effectively buy my domain twice: once for the domain, and one again for the certificate. My registrar should give me a wildcard certificate good for the time I've paid for my domain.

Maybe because there isn't much of demand for that, yet. Shall the transition come and we'd all perceive HTTPS as a default, it's very likely registrars would also offer certificate signing.

The price wars for domain registration pushed the cost way down over the past few years. Certs are starting to move in the same direction. As volume picks up, they can cut margins. And some guys will start to treat it as baseline feature and not a buy-up.

Re: HTTPS as a ranking signal

#165

Makes sense. The reason seo spam is effective is because it's so cheap to get a new site (or ten thousand new sites) up and running. If you make that cost $50 per domain for the ssl cert, that will help ensure all those sites sift nicely down to the bottom of the rankings. Bonus points if they allow a single bad site to tarnish the reputation of all sites under a milti domain cert. We could have had this from the sta…

I do agree, however remember that you can get SSL certs from $9 (e.g. from NameCheap). You might be able to pay lower if you shop around too. Also even if it was used as a fairly strong ranking signal, if Google still approach their rankings like they do now, spammers might still have sufficient ranking 'weight' to overcome a lack of SSL certificate.

[R]emember that you can get SSL certs from $9 (e.g. from NameCheap).

NameCheap provrides a wide range of certs. I'm sure this is true of other SSL-cert offerings.

Are they all at least adequate for Google's SEO purposes?

Re: HTTPS as a ranking signal

#166
post #106

Earlier quoted context omitted.

> but you need your own IP Not anymore, unless you need to support antiquities like IE7 on Windows XP or some ancient Java-based software. SNI works just fine in other cases.

OK, good to know – although there are apparently still some restrictions according to comments by other HN users. SSL is still more expensive, though. For most small content websites ( Example: Shared hosting with 4 WordPress blogs, SSL is active but only to access the control panel since the hoster allows SSL only for one domain. Costs incl. a cheap SSL certificate: 110 USD/year. All 4 WordPress blogs with SSL, i.e.…

> available for less than 10 USD if you don't care about it's quality

A cert with a larger key is better than one with a smaller key, but other than that, what's the "quality" of a SSL certificate?

Re: HTTPS as a ranking signal

#167
post #158

Earlier quoted context omitted.

Hey Pierre, Quick question. Is the type of certificate also a signal? i.e. self-signed vs plain vs EV?

Self-signed is worse than not having one. Don't do that.

Why? The crypto is just as strong with a self-signed cert as a "name brand" cert. The only downside is teaching users to ignore SSL errors, which is bad.

Re: HTTPS as a ranking signal

#168

I'm sorry, but this simply isn't something a search engine should be dictating. Turning enabling SSL into some arms race that panics small businesses into buying millions of new, pointless certificates just isn't very fair. This kind of policy needs to be discussed openly in a suitable forum, e.g. the IETF, not handed down to us by a single company who think they have a right to dictate how the Internet works - and h…

This is _exactly_ the kind of thing that only a player as heavy as Google can kickstart.

We need to "reset the net", encrypt everything possible, and Google's help is more then welcome.

Re: HTTPS as a ranking signal

#170
post #141

Earlier quoted context omitted.

I see this has negative for several reasons : * Certificates are expensive (to buy _and_ to manage) * Crypto is hard and there will be a lot of screw up with inadequate certs in the wild for a long time. Just having a certificate does not mean much if it weak or broken. * Can't help the feeling it's an indirect push for cloud business hence possibly eating the margin of freelancers / ISV * Security Theatre : a lot of…

Google is not "enforcing" anything, people react like if you are not going to show up in the results at all, or Chrome won't work via HTTP. HTTPS is signal, just like having a link from a well ranked website like HN is a signal, and probably dozens other. The points you mention are in fact indicators that someone has put care and resources to make their site work more securely, which says a good thing about the site,…

Right, you will not disappear from the results. The reaction (granted maybe overreaction) is about Google pushing HTTPS hard for security (which could be good but not automatically so) and not caring in areas where it is as important if not more.

You are just proving my point. Google rewards the richest, those who have the resources as you say. As for care, I would be clad if people were not going to do it for the wrong incentives. Will Google just check if HTTPS is available and reward or will it also check for broken cipher and penalize ?

I am not against HTTPS. Just saying that rewarding HTTPS is not enough. It's worst actually, some will set it up quickly and badly just for the extra ranking points and not the actual security it should be providing.

To me the red herring here is pretending doing it for security. What is the point of HTTPS if I receive my password by mail ? To me email is more important to secure first. Google could perfectly incentive security practices in Gmail without loosing a single customer. I would even settle for just signing instead of encrypting mails.

As for enforcing, HTTP2 (that is SPDY) IS enforcing HTTPS.

IMO, Good HTTPS where it matters is more important then Crappy HTTPS everywhere just is ridiculous and could even be dangerous thanks to a false sense of security.

Post reply on HN