Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

201–210 of 212 posts

Re: HTTPS as a ranking signal

#201
post #170

Earlier quoted context omitted.

Right, you will not disappear from the results. The reaction (granted maybe overreaction) is about Google pushing HTTPS hard for security (which could be good but not automatically so) and not caring in areas where it is as important if not more. You are just proving my point. Google rewards the richest, those who have the resources as you say. As for care, I would be clad if people were not going to do it for the wr…

> Google rewards the richest, those who have the resources as you say. Google doesn't care who is it rewarding, google cares about the users that search, they've said that multiple times. And yes, people with better resources build on average better things than people without them. > I am not against HTTPS. Just saying that rewarding HTTPS is not enough. It's worst actually, some will set it up quickly and badly just…

> Google doesn't care who is it rewarding, google cares about the users that search, they've said that multiple times.

Hum, well I've grown wary of what Google say. Like puting comercial mail in a separated inbox is to help the user. It also happens to indirectly help Adsense.

> And yes, people with better resources build on average better things than people without them.

Does that mean content created by association without a dime for instance is on average inferior ?

I happen to like cooking. I often find websites with great content by word of mouth. They are generally badly ranked because they look like they were done on Frontpage and from Geocities ages. Yet the content is very good and even sometime quite unique. They rank badly because they are not speedy and in beautiful html5. That's elitism. Maybe they should by Adwords.

> Even then, still 10 times better than plain text HTTP so my whole office can see what I'm browsing with a simple console command.

That is one of the few good arguments for HTTPS everywhere : privacy.

> And while you don't control the origin (nobody can without breaking compatibility)

You can encrypt or even just sign emails without breaking compatibility. Put commercial email in a separated inbox is OK but put unencrypted and/or unsigned email in a separated inbox is not ?

> While getting that password over HTTP is almost trivial for anyone sitting around me. > I really can not get which scenario you are picturing here. Setting it up is not rocket science.

Is it better to have open WiFi or WiFi with WEP ? It's the same because WEP is nowadays easily broken by script kiddies with simple tools.

That the scenario I'm picturing here. A web full of weak/broken certs to comply for ranking, people feeling safe (it's encrypted right ?) and script kiddies with trival tools to break the WEP equivalent of weak/broken HTTPS certs.

Granted, maybe I'm over-pessimistic here but the trend annoy me. i don't take Google at face value anymore. You know they excel at long play.

On the bright side, maybe people will use their certs for more than HTTPS ... say mail server for instance :)

Re: HTTPS as a ranking signal

#202
I'm going to come out and say it. HTTPs is borked, in a functional way. On a social/technical level, it has become a false sense of security. The PRISM revelations let us know that the three letters and any corporate wannabe was doing MITM not just on http but on HTTPS whenever possible. I would say the ISP's and the CA's should all be considered compromised.

We need something new and better, not to push HTTPs on everything as an imagined stop gap...

That being said though, I do understand that if this was pushed to wider adoption, it would create a higher cost to perform such attacks, for ISP's and three letters?

Re: HTTPS as a ranking signal

#203
post #158

Earlier quoted context omitted.

Hey Pierre, Quick question. Is the type of certificate also a signal? i.e. self-signed vs plain vs EV?

Self-signed is worse than not having one. Don't do that.

Please stop spreading this lie. It's been debunked many, many times. Just because something doesn't provide 100% security doesn't mean you should give up and use nothing.

Once again, self-signed SSL raises the cost of an attack from "basically free" passive monitoring to a much more expensive[1] MitM attack. It's a travesty that apache doesn't simply auto-create a self-signed certificate if it doesn't have one so plain HTTP can be retired forever.

Note: this is about transport security, and the UI presented should not suggest any kind of authentication has been achieved. In firefox, this means not showing the "locked padlock" and other changes usually associated with SSL.

So please, stop undermining the security of the web. We could have been all-HTTPS a long time ago if this nonsense wasn't brought up each time.

[1] and hard to use against everybody simultaneously

Re: HTTPS as a ranking signal

#204
post #172

Earlier quoted context omitted.

If X is a positive signal, then not-X is a negative signal.

That does not follow logically. not-X is typically zero, just like not having an inbound link from a high pagerank page is not a negative. Besides, there are three situation: no-https, both http/https and http-only, which makes your claim that the middle one is negative seem less likely.

Say there are five sites that would normally be returned for a query and they have scores A:20 B:18 C:10 D:8 E:4. The results will look like "A, B, C, D, E". Say none of them support https, and then the search engine adds https as a positive ranking factor worth +3. Site C turns on https, the order still is "A, B, C, D, E". Now site B turns on https, the order is now "B, A, C, D, E".

Imagine instead they had added "lack of https" as a ranking factor worth -3. The rankings on the page would have changed exactly the same way.

"not having an inbound link" can be thought of as a negative without changing rankings. In the example above, if getting an inbound link from apple.com would move you up 4 points, then if B got a link from apple that would put them at 22 to A's 20. If instead "not having a link from apple" was worth -4 points, then A would be at 16 and B at 18.

Re: HTTPS as a ranking signal

#205

Google has a strong case to have HTTPS implemented: It prevents ISPs etc. from being able to profile your traffic, but not Google's, since you're probably visiting a site with Adsense or Analytics running on it anyway. Through HTTPS, Google is the only one with a profile of your traffic, and your ISP is no longer a competitor to them.

Hm. I think this is the real answer.

Re: HTTPS as a ranking signal

#206

Earlier quoted context omitted.

Why? The crypto is just as strong with a self-signed cert as a "name brand" cert. The only downside is teaching users to ignore SSL errors, which is bad.

The crypto strength of a self-signed cert is irrelevant because a MITM can generate their own self-signed cert with the your website's name.

Right, so you have to verify the certificate through some "out of band" (relative to the browswer) mechanism.

Re: HTTPS as a ranking signal

#207
post #81

Earlier quoted context omitted.

https://www.startssl.com/?app=1 and https://www.namecheap.com/campaigns/2014/reset-the-net.aspx ???

StartSSL is pretty harmful as evidenced by the events after Heartbleed. The certificates are free but they charge you to revoke them, and after we found out about Heartbleed and realized a lot of those free certs were compromised a lot of people refused to pay up for their free keys and continue using the compromised ones. What's more is that StartSSL refused to do the right thing and revoke them, leading a lot of fo…

Do any current browsers even correctly support CRLs?

Re: HTTPS as a ranking signal

#208
post #204

Earlier quoted context omitted.

That does not follow logically. not-X is typically zero, just like not having an inbound link from a high pagerank page is not a negative. Besides, there are three situation: no-https, both http/https and http-only, which makes your claim that the middle one is negative seem less likely.

Say there are five sites that would normally be returned for a query and they have scores A:20 B:18 C:10 D:8 E:4. The results will look like "A, B, C, D, E". Say none of them support https, and then the search engine adds https as a positive ranking factor worth +3. Site C turns on https, the order still is "A, B, C, D, E". Now site B turns on https, the order is now "B, A, C, D, E". Imagine instead they had added "l…

There is no doubt that https adds a positive value, and not having it would put you at a disadvantage. But that is not what is being discussed here, the question is whether having BOTH https and http is a negative.

Re: HTTPS as a ranking signal

#209
post #54

It probably bugs me the way it does, because this "signal" has nothing to do with the contents or the usability of the web site (unlike speed, validity of HTML or, well, content itself), but is purely a "we just think you should do X" situation.

I would definitely prefer to use a site that supports HTTPS over HTTP. For personal safety reasons in addition to privacy and general welfare of the web.

If you're searching for something and roughly the same content is available at safedomain.com vs. notoriouslysketchy.ru, I'd think you'd prefer to be shown the former above the latter. I don't see how this is much different.

Re: HTTPS as a ranking signal

#210

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

I am more than happy to migrate my site to https and I took a two days to watch your youtube video to ensure i do not miss anything

But I got one very valid concern. Most websites running some kind of affiliate links and banners. Most of the affiliate links and banners is not on the https platform. This will cause mixed content error message by the browser. First, is using protocol relative urls solve this mixed content error issue? Second, can the non-https affiliate links and banners work correctly(tracking etc) on https website?

I am sure this is the one big hurdle need to be addressed or else more than 50% of the websites in existence will have difficulty to migrate.

Post reply on HN