Live data from Hacker News

HTTPS as a ranking signal

googleonlinesecurity.blogspot.com

61–70 of 212 posts

Re: HTTPS as a ranking signal

#61

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

In my country, the cost of a SSL certificate is around 60% of my hosting costs, per year. I run a low-traffic blog with comments disabled, so users do not "interact" with the site in any way - except consume the content. I don't see any benefit from this.

Re: HTTPS as a ranking signal

#62
post #55

"Security is a top priority for Google. We invest a lot in making sure that our services use industry-leading security, like strong HTTPS encryption by default." -- Says Google site that forces HTTP.

People that write content for websites are not always the same people that build those websites. In this case, the search engine team is entirely separate from the Blogspot team.

Re: HTTPS as a ranking signal

#63
post #27

Earlier quoted context omitted.

The NSA and other state actors can use non-secure pages to inject code to exploit the browser and compromise your visitors. http://en.wikipedia.org/wiki/FOXACID#QUANTUM_attacks

State actors are probably irrelevant in this discussion; few of them won't be able to get a certificate to any website they want, in my opinion.

This is a known issue and being addressed as well.

http://tools.ietf.org/html/draft-ietf-websec-key-pinning-11

http://dev.chromium.org/sts

Re: HTTPS as a ranking signal

#64

Earlier quoted context omitted.

> I don't see how is this any different from any other signal that Google uses to prioritize sites. «Oh, they're screwing up before, too? Then I guess it's alright» > How does it prevent decentralization? Because only a handful of companies can issue certificates.

«Oh, they're screwing up before, too? Then I guess it's alright» How is it screwing up? How are they supposed to run a search engine without prioritizing? "Here's 30000 results, we've randomly sorted them for you"? Because only a handful of companies can issue certificates. Fair enough.

Apologies, I haven't made myself clear with that idiotic of a snarky remark :) What I meant is that their actions in the past shouldn't be an excuse to their actions today.

The principles behind PageRank are based on unbiased reputation, and provide for a good ranking system (spammers aside). Whatever's thrown on top needs to be carefully considered not to enforce biases towards any group in particular.

Re: HTTPS as a ranking signal

#65

I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner: 1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How man…

In my country, the cost of a SSL certificate is around 60% of my hosting costs, per year. I run a low-traffic blog with comments disabled, so users do not "interact" with the site in any way - except consume the content. I don't see any benefit from this.

I see the benefits but I have to agree. This is a very real barrier to entry, and not just financially. Making SSL a global standard is just one more thing new web developers have to appreciate.

Re: HTTPS as a ranking signal

#66
post #55

"Security is a top priority for Google. We invest a lot in making sure that our services use industry-leading security, like strong HTTPS encryption by default." -- Says Google site that forces HTTP.

People that write content for websites are not always the same people that build those websites. In this case, the search engine team is entirely separate from the Blogspot team.

> People that write content for websites are not always the same people that build those websites.

Wow Seriously? You don't say.

Seems the irony escaped you: announcement was made on a Google site that forces (i.e redirects from HTTPS) you to read it over HTTP.

If you read closely enough it refers to all of Google, not just "the search engine team" or (Google - Blogspot).

Re: HTTPS as a ranking signal

#67
post #44

I'm sorry, but this simply isn't something a search engine should be dictating. Turning enabling SSL into some arms race that panics small businesses into buying millions of new, pointless certificates just isn't very fair. This kind of policy needs to be discussed openly in a suitable forum, e.g. the IETF, not handed down to us by a single company who think they have a right to dictate how the Internet works - and h…

[deleted]

The OP was referring to the webmasters, not the search engine end users, as the ones being 'dictated'* to by Google.

Unlike end users, webmasters themselves switching to Bing or DDG in their personal capacity would have little influence on their visitor's (end users) behavior.

* 'firmly encouraged' is perhaps more appropriate ;)

Re: HTTPS as a ranking signal

#68
post #24
post #3

We recently changed our existing clients site to 100% SSL when we launched their new site. If only webmasters had an option to change http:// to https:// , the entire move would have been slightly easier as "fetch as googlebot" returns "redirect" since we direct http:// to https:// . Apart from that, we've had no ranking loss for their keywords.

Take a look at HSTS. It effectively tells clients to try HTTPS first when a user types in your domain. http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

... after the first visit...

Re: HTTPS as a ranking signal

#70

I'm sorry, but this simply isn't something a search engine should be dictating. Turning enabling SSL into some arms race that panics small businesses into buying millions of new, pointless certificates just isn't very fair. This kind of policy needs to be discussed openly in a suitable forum, e.g. the IETF, not handed down to us by a single company who think they have a right to dictate how the Internet works - and h…

This kind of policy needs to be discussed openly in a suitable forum, e.g. the IETF, not handed down to us by a single company who think they have a right to dictate how the Internet works I don't see how is this any different from any other signal that Google uses to prioritize sites. Forcing small businesses to buy certificates doesn't seem any different than forcing them to have faster websites, for example. There…

heartbleed was much much worse than unencrypted logins.
Post reply on HN