{"id":2874,"date":"2016-08-10T15:58:30","date_gmt":"2016-08-10T15:58:30","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=2874"},"modified":"2020-12-15T10:33:39","modified_gmt":"2020-12-15T15:33:39","slug":"browser-community-pushing-towards-https","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/browser-community-pushing-towards-https\/","title":{"rendered":"The Browser Community is Pushing You Towards HTTPS"},"content":{"rendered":"<h2>Their not-so-subtle encouragement to get secure.<\/h2>\n<p>It\u2019s no secret: Encryption is coming. HTTPS, the secure version of the HTTP protocol that is enabled by SSL, is the de facto standard when it comes to secure communication over the internet. But it may surprise you to know that only a small percentage of the internet is using SSL.<\/p>\n<p>For years, SSL has been widely-used, even mandated, in areas like online banking, e-commerce and user portals. But when we look at the entire web, tens of millions of sites &#8211; <a href=\"https:\/\/scotthelme.co.uk\/alexa-top-1-million-crawl-aug-2016\/\" rel=\"nofollow\">more than 80%<\/a> &#8211; still use HTTP \u2013 even though it can be dangerously insecure.<\/p>\n<p>But those days are coming to an end.<\/p>\n<p>There are a <a href=\"https:\/\/konklone.com\/post\/were-deprecating-http-and-its-going-to-be-okay\" rel=\"nofollow\">number of arguments<\/a> for encrypting the entire web, but many still think they don\u2019t need secure connections for their site because it\u2019s \u201cjust a blog,\u201d or because they don\u2019t have user log-ins. The reality is we are no longer in an era where you can get away with using HTTP on any site.<\/p>\n<p>That\u2019s not just because you <em>should <\/em>(and in many cases, need to) provide security to your visitors. It\u2019s because the web wants HTTPS to be expected, not an after-thought, and waiting to adopt HTTPS is going to put your website at a major competitive disadvantage.<\/p>\n<p>In the last two years major browsers \u2013 including Google Chrome and Mozilla Firefox\u2013 have encouraged the use of HTTPS. Let\u2019s take a look at three major ways the browsers are pushing you towards HTTPS:<\/p>\n<h2><strong>Guaranteed SEO Benefits<\/strong><\/h2>\n<p>In 2014 Google <a href=\"https:\/\/webmasters.googleblog.com\/2014\/08\/https-as-ranking-signal.html\">announced<\/a> that using HTTPS would become a search ranking signal.<\/p>\n<p>Usually, SEO involves jumping through all sorts of hoops, because no one but Google really understands what goes into the ranking algorithms.<\/p>\n<p>But in this case, it\u2019s crystal clear. All you have to do is install a certificate and configure your server correctly (serving all pages over HTTPS \u2013 which in the industry is known as Always-On SSL or HTTPS Everywhere). Some measurements have <a href=\"http:\/\/blog.searchmetrics.com\/us\/2015\/03\/03\/https-vs-http-website-ssl-tls-encryption-ranking-seo-secure-connection\/\" rel=\"nofollow\">seen up to a 5% increase<\/a> in search visibility from this simple switch.<\/p>\n<p>Companies spend hundreds of hours and thousands of dollars on SEO strategies \u2013 many of which never bear fruit. But SSL sure does \u2013 it\u2019s the closest thing to a guarantee you are going to get in SEO.<\/p>\n<p>Google has said that the effect of this signal may increase over time as HTTPS becomes more widely adopted.<\/p>\n<h2><strong>The Best Browser Features are Exclusive to HTTPS<\/strong><\/h2>\n<p>Web browsers have evolved substantially since the inception of the internet. What once just displayed a page of static text can now pinpoint your exact location, access your webcam, and even respond to voice commands.<\/p>\n<p>These cutting-edge features can pose a huge security and privacy risk when used over unsecured HTTP connections. Depending on where and who your users are, their location, audio, or video data can be dangerous in the wrong hands. Using leaky-HTTP almost guarantees that someone else will see the data sent and received by your users.<\/p>\n<p>As a great (spider-)man once said, \u201cwith great power comes great responsibility.\u201d That is why Google Chrome now restricts certain features to HTTPS only, in order to protect user\u2019s privacy and data. Google Chrome\u2019s security team has an <a href=\"https:\/\/sites.google.com\/a\/chromium.org\/dev\/Home\/chromium-security\/deprecating-powerful-features-on-insecure-origins\">entire proposal<\/a> where they define these <em>powerful features <\/em>\u2013 but here\u2019s the one sentence summary: These are features you don\u2019t want to miss out on.<\/p>\n<p>Some major ones \u2013 including geolocation and camera\/microphone access \u2013 are already HTTPS-exclusive. Having access to a device\u2019s orientation will flip to HTTPS-exclusive in the future, and any new powerful <a href=\"https:\/\/www.thesslstore.com\/blog\/chrome-feature-https-presentation-api\/\">features added to Chrome<\/a> will automatically be HTTPS-exclusive.<\/p>\n<p>Think about the competitive disadvantage you would find yourself at if you didn\u2019t have access to this ever-increasing suite of features. Something as simple as geolocation can be a game-changer for brick-and-mortar and online operations alike. Chances are, you use these advanced features on a daily basis without even realizing it \u2013 it\u2019s one of those things you don\u2019t miss until it\u2019s gone.<\/p>\n<p>Suffice to say, if you want to take full advantage of a user\u2019s browser, which is quickly becoming one of the most powerful apps on most desktops and phones \u2013 you need to encrypt.<\/p>\n<h2>The Unencrypted Web Is Going to Get Ugly.<\/h2>\n<p>HTTP provides no security to your users, plain and simple. Right now, that is an ugly fact that the browsers aren\u2019t telling us. It\u2019s just business as usual. But <a href=\"https:\/\/www.chromium.org\/Home\/chromium-security\/marking-http-as-non-secure\">Google<\/a> and <a href=\"https:\/\/blog.mozilla.org\/security\/2015\/04\/30\/deprecating-non-secure-http\/\">Mozilla<\/a> want to change that.<\/p>\n<p>They have proposed a plan that will make security an expectation, not a luxury.\u00a0 HTTP will no longer be happily accepted \u2013 instead browsers will clearly show that HTTP is unsecure by displaying a negative indicator wherever it\u2019s used.<\/p>\n<p>Today, in a browser, you usually see a harmless looking page icon when HTTP is used. In a multi-step process, Google\u2019s Chrome browser will make that icon increasingly severe.<\/p>\n<p>If you stick with HTTP, that nasty <em>red-x<\/em> will be living in your address bar, clearly telling every user on your site that their connection is not secure \u2013 imagine what that will do to your bounce rate.<\/p>\n<p>This will be a gradual plan, which probably won\u2019t be fully implemented until 2017 at the earliest.\u00a0But you probably shouldn&#8217;t wait until then. After all, it&#8217;s better to be proactive than reactive.<\/p>\n<h2>Let&#8217;s Wrap This Up<\/h2>\n<p>We\u2019ve covered three major ways the browser community is pushing your website towards encryption, and that is only the tip of the iceberg. Google recently started displaying warnings on emails sent from unsecured servers; and the entire community has decided that HTTP\/2 must be deployed with HTTPS encryption \u2013 the internet is making it clear that SSL is no longer optional.<\/p>\n<p>Even if you don\u2019t see encryption as important for your site you simply cannot afford not to encrypt anymore. HTTPS will make your site faster, give you access to the most powerful browser features, boost your search engine rankings, and it\u2019s is being built <a href=\"https:\/\/www.thesslstore.com\/blog\/introduction-to-http2-hypertext-transfer-protocol\/\">into the technologies that make up the backbone of the web<\/a>.<\/p>\n<p>Don\u2019t wait for the rest of the web to zoom past you. HTTPS adoption has been exploding recently \u2013 increasing nearly <a href=\"https:\/\/scotthelme.co.uk\/alexa-top-1-million-crawl-aug-2016\/\" rel=\"nofollow\">50% year over year<\/a>.\u00a0A time will come when you aren\u2019t just rewarded for using HTTPS, but will be actively penalized for staying with unsecure HTTP.<\/p>\n<p>Don\u2019t wait for that time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Their not-so-subtle encouragement to get secure. It\u2019s no secret: Encryption is coming. HTTPS, the secure version of the HTTP protocol that is enabled by SSL, is the de facto standard&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[171,169,170],"class_list":["post-2874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-browsers","tag-http","tag-https","post-with-tags"],"views":13407,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/08\/iStock_77923989_SMALL.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=2874"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2874\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/2875"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=2874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=2874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=2874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}