Live data from Hacker News

Https hurts users far away from the server

antoine.finkelstein.fr

81–90 of 128 posts

Re: Https hurts users far away from the server

#81
post #71

Earlier quoted context omitted.

Adding http2 is easier then reducing the number of requests. And infact reducing the number of requests using things like spritemaps, bundling js and css is actually an antipattern with http2.

> And infact reducing the number of requests using things like spritemaps, bundling js and css is actually an antipattern with http2. Those are just ways to lose some of the impact of bloat without addressing the bloat itself. If you address bloat directly it will benefit all users.

If you migrate to HTTP2 or move to a host that already supports it then cutting down on "round trips" is an obsolete concern altogether.

Re: Https hurts users far away from the server

#82
post #73
post #66

Earlier quoted context omitted.

Domain validation only requires an HTTP response. They can easily MitM that specific response to fake a certificate for your domain.

Yes. This. In particular, the company operating the data center your server is in can reliably do this, and so can the backbone provider they use, and probably the server's local government. The DNS provider that controls your domain can mitm the ca process too (though with a higher chance of detection). The argument for making domain validation yellow (and not red) is that domain validation protects against attacks…

It's hard to say if you're implying this is any different with other validation levels like OV and EV. The validation methods that CAs may use for OV/EV are the same ones they may use for DV. The only difference is that they also validate the organization's information of the certificate requester. In other words, someone with the ability to MitM traffic between the CA and the target's domain could still obtain an OV/EV certificate for that domain, they'd just have to verify they are who they claim they are on top of that (and they don't have to be the domain owner - there's nothing that says "only the legal entity owning the domain may acquire a certificate for that domain").

Re: Https hurts users far away from the server

#83
post #77
post #45

Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments (in the US, or the location of the cloudflare proxy) you probably should look elsewhere. It's probably controversial, but I'd love to see a yellow security icon in browsers when sites are using well known https relays that can see plaintext (or are doing other obviou…

> Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments ... you probably should look elsewhere. This analysis seems flawed. If you care about mass surveillance, you want their top-tier security and legal teams working for you.

Their security and legal teams don't work for you, they work for the company. The company can be drafted to work for the government. Just because you pay them, does not mean they actually work for you.

Re: Https hurts users far away from the server

#84
post #64

Earlier quoted context omitted.

Hi - I know some tools report a slow site in this case, but these reports are not accurate - don't believe them! Google is not that stupid ! :D I am currently working as a dev in an SEO-Agency (in Austria), and we never believed this hypothesis - so we tested this once with a bunch of our sites: When moving sites with a German speaking audience to a VPS in America, your rankings at google.de/google.at will decrease (…

Report tool I use is Google's official webmaster tool (420ms an average time in "crawl stats"). And here is the article on budget https://webmasters.googleblog.com/2017/01/what-crawl-budget-...

Hi, alvil - 420ms does not sound that bad.

Checking some of my sites I see:

- values ranging vom 320 - 410 for a bunch of German speaking sites hosted in Europe

- and values of 221 and 240 for my two English speaking sites hosted in America (via firebase - on googles own infrastructure)

So if you are concerned with your crawl budget, I think you better focus on things like:

- On-site duplicate content

- Soft error pages

- and Low quality and spam content

Plus you could also get some high quality backlinks.

And please be aware that the crawl frequency does not directly influence your rankings. So, as long as your do not really have a big problem regarding your crawl budget, you may spend your time wiser if you focus on other metrics.

PS: You may already know the tools, but others could be interested:

If you want to optimize you sites performance in respect to SEO use the following tools:

https://developers.google.com/speed/pagespeed/insights/?hl=d...

The most important aspect is "Reduce server response time" - you have to pass this!

https://www.webpagetest.org/

Choose a server near you and aim for a Speed-Index of maximum 3000 - I personally target 1000, but depending on your influence regarding the website's frontend you will not be able to achieve this.

Re: Https hurts users far away from the server

#85
post #77
post #45

Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments (in the US, or the location of the cloudflare proxy) you probably should look elsewhere. It's probably controversial, but I'd love to see a yellow security icon in browsers when sites are using well known https relays that can see plaintext (or are doing other obviou…

> Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments ... you probably should look elsewhere. This analysis seems flawed. If you care about mass surveillance, you want their top-tier security and legal teams working for you.

That really seems like wishing.

In an ideal world you'd want Youtube's (Google's) legal teams working for you, protecting you against DMCA abuses and alike... but they don't. Not unless you're a top-tier YouTuber and even then it's laughable dice roll as to whether they feel the bad press is worth their time to do anything.

And I don't believe from a bottom-line perspective the shareholders believe it's worth their time to do anything more than provide a platform (no matter how problematic) and market it.

Will Cloudflare do everything they can to keep your content accessible? Sure. Anything above and beyond that? lol. Good luck with that...

Re: Https hurts users far away from the server

#86
post #77

Earlier quoted context omitted.

> Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments ... you probably should look elsewhere. This analysis seems flawed. If you care about mass surveillance, you want their top-tier security and legal teams working for you.

Their security and legal teams don't work for you, they work for the company. The company can be drafted to work for the government. Just because you pay them, does not mean they actually work for you.

Or even that their interests and yours are even remotely aligned.

They sell you a widget/service. That's where your relationship ends.

Re: Https hurts users far away from the server

#87
post #53
post #7

Earlier quoted context omitted.

Keeping it extremely high level: Among other reasons, not encrypting traffic gives an opportunity for bad actors to replace content in transit to your end users when your end users are on compromised connections, such as rogue "free" wifi networks in airports or coffee shops, or even legitimate networks which have in some way been compromised, e.g. the ISPs of the world who decide to inject other content e.g. their o…

Has google disclosed all investments in CA providers? don't know the answer myself here.. there are good technical reasons, I agree.. but it is a logical fact that if google search was always 100%, there would be no need for adwords and site ads...

Google is a platinum sponsor for Let's Encrypt, which is slowly taking away market share from almost all commercial CAs[1]. They've also removed special treatment for EV certificates on mobile browsers (and are regularly thinking out loud about doing the same for their desktop browser), taking away most of the incentive for using a commercial CA (and not a free DV CA like Let's Encrypt). There's probably also a good chance that they'll offer something like Amazon's ACM (free certificates for various AWS services) as part of their Google Cloud offerings with their newly-acquired roots[2].

I think we can safely say that this would be a very weird way to go about earning a few bucks through CA investments.

[1]: https://w3techs.com/technologies/history_overview/ssl_certif...

[2]: http://pki.goog/

Re: Https hurts users far away from the server

#88

Earlier quoted context omitted.

Hi - I know some tools report a slow site in this case, but these reports are not accurate - don't believe them! Google is not that stupid ! :D I am currently working as a dev in an SEO-Agency (in Austria), and we never believed this hypothesis - so we tested this once with a bunch of our sites: When moving sites with a German speaking audience to a VPS in America, your rankings at google.de/google.at will decrease (…

That sounds like a really interesting experiment. Kudos for taking a scientific approach to SEO. A bit off-topic, but out of curiosity, have you run any other interesting experiments like this? I would love to read a blog post about them.

Hi, thanks!

We regularly test different things, but few are as extensive as this "server location test".

This one was quite easy to do - and to revert - even when doing it for a lot of sites: just duplicate your sites on another continent and change your dns-settings.

Sadly we do not blog about this stuff. As our customers are not particularly fond of sharing their data - and blog posts without precise data are not useful at all...

Additionally, most of our assumptions and hypotheses were wrong. So most of our blogsposts would sound like:

"We thought google would work like this, but sadly we were wrong"

SEOs might like these posts - but potential customers probably not so much :D

Re: Https hurts users far away from the server

#89
post #45

Presumably, cloudflare is up to its ears in NSL's, illegal wiretaps, etc. If you care at all about mass surveillance, censorship, oppressive governments (in the US, or the location of the cloudflare proxy) you probably should look elsewhere. It's probably controversial, but I'd love to see a yellow security icon in browsers when sites are using well known https relays that can see plaintext (or are doing other obviou…

Cloudflare is unquestionably a source of pure, unencrypted traffic for the govt.

Does anyone remember a few years ago when Google found out through leaks that the govt was wiretapping it's private traffic between datacentres?

What makes you so naive to think that the govt isn't sniffing every single page on cloudflare?

Re: Https hurts users far away from the server

#90
post #64

Earlier quoted context omitted.

Report tool I use is Google's official webmaster tool (420ms an average time in "crawl stats"). And here is the article on budget https://webmasters.googleblog.com/2017/01/what-crawl-budget-...

Hi, alvil - 420ms does not sound that bad. Checking some of my sites I see: - values ranging vom 320 - 410 for a bunch of German speaking sites hosted in Europe - and values of 221 and 240 for my two English speaking sites hosted in America (via firebase - on googles own infrastructure) So if you are concerned with your crawl budget, I think you better focus on things like: - On-site duplicate content - Soft error pa…

thanks for your suggestions KabuseCha :)
Post reply on HN