Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.
Google is a large company, with multiple branches. I can't remember what services it is now, but there was some Google service that was deranked because it broke some Google search ranking policy. It shows some integrity for the company that they're (sort of) operating their search engine objectively. I presume that google doesn't uprank sites that specifically use Adsense versus other competing ad services?
Google Will Soon Shame All Websites That Are Unencrypted
281–290 of 369 posts
Re: Google Will Soon Shame All Websites That Are Unencrypted
#282Earlier quoted context omitted.
Please do not put Cloudflare in front of your site. It makes it impossible for tor and VPN users to view your site since they have to solve an impossible captcha to even see the static content.
It's possible to turn off security in the CloudFlare control panel. I think the bigger issue is that CloudFlare has become a single point of interception for MITM'ing huge portions of web traffic.
But yeah, this NSA slide is extremely relevant to cloudflare: http://cdn01.androidauthority.net/wp-content/uploads/2014/06...
Re: Google Will Soon Shame All Websites That Are Unencrypted
#283Consider this: - Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1] - Weebly only allows it on their $25/mo business plan [2] - Wordpress.com doesn't support SSL for sites with custom domains [3] - If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare…
Then maybe those platforms will finally implement it. In any case, there's an alternative: putting Cloudflare in front of the site. In fact, Google shows me a guide to do so when I search for "squarespace ssl". Of course, that's hardly as secure as end-to-end HTTPS, but still, I trust the path between CF and SquareSpace much more than between the user's browser and SquareSpace.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#284Earlier quoted context omitted.
Being ranked #1 in a Google search for 'calendar' does mean a lot. Also, let's say they are penalizing themselves, but the penalty isn't enough to change their ranking. Why, then, would they claim that they are making this change because it's better for users to not have these ads but to still run these ads themselves? > Our analysis shows that it is not a good search experience and can be frustrating for users becau…
A penalty that doesn't knock down one of the largest sites on the internet can still be a big deal to everyone else. I assume different departments run calendar and search.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#285Why do we have to go through this whole SSL certificates thing and can't just have a simple, automatically secure, I-do-nothing-and-my-website-is-secure protocol? Seriously though. If secure is the default from now on, why can't it actually be the default?
Seriously this. I don't see why encryption and website verification have been wrapped up in the same thing (SSL certs). They're two different things. Encryption should be free, automatic and default.
See eg https://bugzilla.mozilla.org/show_bug.cgi?id=220240#c6
Re: Google Will Soon Shame All Websites That Are Unencrypted
#286Earlier quoted context omitted.
Not all countries have feminine gender, just check https://en.wikipedia.org/wiki/Fatherland
I never thought about the question of whether, in languages that require nouns to have grammatical gender, particular countries may have a different grammatical gender from others, but on reflection I already know examples where they do in Portuguese: o Brasil, o Canadá (amusing to me because of the national anthem), but a Argentina, a Alemanha. I wonder if this also happens in German; the only examples I'm thinking…
Re: Google Will Soon Shame All Websites That Are Unencrypted
#287Earlier quoted context omitted.
However, having one and not the other isn't totally useless. Having the browser be able to track and tell me that "Though we aren't sure this is actually google.com, we do know that the exact same cert has been used the last 50 times you visited this website" is something I'd consider to be useful. (Actually, telling me if it changes would be the useful bit). That would be at least be useful for self-signed certs (th…
> (Actually, telling me if it changes would be the useful bit). I'm curious. Has anyone ever encountered that scary warning you get when an SSH host key changes, and thought "oh man, I'm getting MITMed, I'd better not connect to this server!", instead of thinking "oh right, I guess they reconfigured the server, now what command do I type to make the warning go away"?
Re: Google Will Soon Shame All Websites That Are Unencrypted
#288Earlier quoted context omitted.
I do have the app. And that fact makes this double-annoying. When trying to visit a website, I'm told not to do that. That would be annoying on its own, and in fact it was for the first few years that it happened. But that's not at all what is frustrating me right now. What's super annoying is that Google claimed last year that they would penalize websites that do this, because they find it annoying too. Except they…
> I do have the app. And that fact makes this double-annoying. It really just shows the sad state of mobile advertising when they're showing you ads for an app you already have.
How do you expecet them to know all the apps installed on your phone? And if they DID know this information, people would be up in arms about privacy or lack there-of.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#289HTTP + HTTPS is fine HTTPS for SaaS and e-commerce web apps is fine HTTP for normal websites is okay (for me, I have no hidden agenda) HTTPS-only for normal websites is silly, why not offer HTTP too? Every request is unique, no internet anonymity.
Happened to GitHub once.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#290The article title really, really needs an extra word: "Chrome", between "Google" and "Will". At first glance I thought it would be about the search engine, which would be a very disturbing thought indeed; it's already hard enough to find the older, highly informative and friendly sites --- which often are plain HTTP. Nevertheless, quite convincing security arguments aside, I feel this also has a very authoritarian si…
Not to mention that, of course, access to most websites is already gated by a central group of authorities - the domain registries - which can and do seize domains. Using raw IPs is one alternative, but if you're in that kind of position, chances are you want to be a Tor hidden service anyway.