What is HTTPS
Firstly, we’d better explain what HTTPS means. Have you ever looked in the address bar of your web browser and seen the http:// before the www, the HTTP stands for Hypertext Transfer Protocol, it is the protocol that allows the exchange of data over the internet and allows you to view a website. The addition of the “S” in the HTTP stands for “secure”, which means that the protocol now has a form of encryption.
HTTPS is a Google Ranking Factor
HTTPS has been used on websites that exchange sensitive information, such as shopper information for a long time. In August 2014 Google announced the HTTPS was a ranking signal, meaning that they would potentially rank a site with a secure certificate higher than an equivalent site without. There wasn’t an overnight change, but statistics show that about 32.5% of page 1 Google results now us the https: protocol. The excellent people over at Moz have a full blog post on this: https://moz.com/blog/https-tops-30-how-google-is-winning-the-long-war
You can also read Google’s own blog post that announced them using this as a ranking factor which is something they rarely do: https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html. As they rarely announce what they use in their algorithms as a ranking factors, we can assume that Google is trying to push all websites to use a secure certificate.
So why does Google want all websites to use HTTPS?
- HTTPS protects the integrity of your website, by preventing intruders form tampering with communications between your websites and your websites users, for example an Internet Service Provider or if you’re on WIFI in a hotel, they could inject malicious code or advertisements into web pages.
- HTTPS protects the privacy and security of your users – by preventing intruders from being able to listen to the communications between the user and the website. Every unprotected HTTP request can potentially reveal information about the users of your website. For example, software on the network could potentially intercept data that you are sending and receiving (such as credit cards or personal information).
- Some new web features need HTTPS to work – There are also many new web platform features such as geolocation, that will not work in browsers unless there is a secure connection.
You can read Google full page on why HTTPS matters here: https://developers.google.com/web/fundamentals/security/encrypt-in-transit/why-https
Changes in Google Chrome
To this end, Google announced on 8th September 2016 that it would make changes to its web browser Google Chrome, starting in January 2017 so that all sites that ask for passwords or credit cards details over a plain HTTP connection would be labeled as not-secure in the address bar. During the course of 2017 Google will be rolling out more changes to its web browser including labeling HTTP pages as not secure in Incognito mode, where users have higher expectations of privacy. Eventually Google plans to label all HTTP pages as non-secure and add a red triangle indicator next to the address bar. See Googles blog post on the matter: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
How does this effect my website?
So what should you be doing? If you have an online shop or have a login area you should be using a secure certificate. If you have a plain brochure site that doesn’t have a logging or shop area, you don’t need to do anything immediately, but plan to move to HTTPS.
Moving to HTTPS is a relatively simple process and doesn’t need to cost the earth. If your site is not on HTTPS and you think you should be, give us a call to talk about adding it to your website on 01904 720 999 or use our contact page.
