{"id":2980,"date":"2016-08-26T13:55:18","date_gmt":"2016-08-26T13:55:18","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=2980"},"modified":"2018-10-01T07:50:36","modified_gmt":"2018-10-01T11:50:36","slug":"wired-transition-to-https","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/wired-transition-to-https\/","title":{"rendered":"Wired.com Documents Its Transition to HTTPS"},"content":{"rendered":"<h2>The transition to HTTPS is a lot more complicated than it sounds.<\/h2>\n<p>Wired.com is in the process of switching its entire site from HTTP to HTTPS. For a site of its scale \u2013 with thousands of pages, and loads of existing infrastructure \u2013 making an engineering change is always a challenge.<\/p>\n<p>From the beginning, Wired pledged to be transparent about the switch, giving insight about what it\u2019s like for a major website to implement HTTPS for the first time. In <a href=\"https:\/\/www.wired.com\/2016\/08\/wired-https-progress\/\" rel=\"nofollow\">its most recent update<\/a>, Wired\u2019s application architect Zack Tollman discussed obstacles in implementing the secure protocol.<\/p>\n<p>The HTTPS protocol brings a variety of benefits to end users, including encryption, authentication, and integrity. Combined, those features ensure that you are connecting to website\u2019s true server and seeing the content exactly as intended. Without HTTPS, it is trivially easy for the content of a website to be modified by others, including malicious actors.<\/p>\n<p>Google released an <a href=\"https:\/\/transparencyreport.google.com\/https\/top-sites?hl=en\">HTTPS Transparency Report<\/a> earlier this year, which included some great statistics on HTTPS usage amongst the world\u2019s most-visited websites. A troubling trend is that many popular news sites have yet to adopt the secure protocol. As Neiman Lab <a href=\"http:\/\/www.niemanlab.org\/2016\/04\/wireds-making-the-long-and-slow-switch-to-https-and-it-wants-to-help-other-news-sites-do-the-same\/\" rel=\"nofollow\">wrote<\/a>, \u201cwhen it comes to security best practices, most publishers are better at writing about them than actually implementing them.\u201d<\/p>\n<p>The New York Times and DailyMail.co.uk are amongst worldwide leaders in news that do not have any support for HTTPS on their sites. The Guardian (which originally published Edward Snowden\u2019s evidence of the NSA\u2019s global spying programs) added HTTPS <a href=\"https:\/\/twitter.com\/konklone\/status\/749784665498775554\" rel=\"nofollow\">only a few months ago<\/a>.<\/p>\n<p>Many news organizations have acknowledged this and are working on rectifying this lack of secure access. To have a properly secure connection all the resources on your webpage need to be available over HTTPS. For large sites that use third-party services and ad networks this can be challenging, as those providers may not have HTTPS support themselves.<\/p>\n<p>Ensuring every asset on a page is available over HTTPS is no small feat. It\u2019s common for larger sites like Wired to have more than a dozen third-party services providing tools like metrics, video players, advertising, etc. On top of that you have to consider every individual page that may have embedded content that was relevant to a particular article. If just one asset is not available over HTTPS, then that specific page is not secure. That is a big challenge when you <a href=\"http:\/\/www.wired.com\/2015\/10\/cyphon-wired-archive-migration\/\" rel=\"nofollow\">have 23 years of content<\/a>.<\/p>\n<p>Wired isn\u2019t moving to HTTPS purely for the security benefits. The site is also hoping that moving to HTTPS can help it combat ad-blocking, which is <a href=\"https:\/\/pagefair.com\/blog\/2015\/ad-blocking-report\/\" rel=\"nofollow\">growing 50% year-over-year<\/a>. Reuters estimates that <a href=\"https:\/\/espresso.economist.com\/00c17237d011cca999f55a43db2ce040\" rel=\"nofollow\">more than 20% of U.S. internet users<\/a> use ad-blocking software, and Wired\u2019s own estimates show that proportion is even higher with their tech-savvy audience.<\/p>\n<p>Privacy concerns are frequently cited as a reason for blocking ads. Wired believes that if they can eliminate those concerns by supporting HTTPS, they can slow their audience\u2019s adoption of ad-blocking. <a href=\"http:\/\/digiday.com\/publishers\/latest-attack-ad-blocking-wired-addresses-security-concerns\/\" rel=\"nofollow\">In a May interview<\/a>, Wired\u2019s VP publisher Ken Kelleher told Digiday, \u201cthe ultimate goal is to alleviate one of the big three concerns people have expressed to us outright.\u201d<\/p>\n<p>Wired\u2019s HTTPS pilot <a href=\"https:\/\/www.wired.com\/2016\/04\/wired-launching-https-security-upgrade\/\" rel=\"nofollow\">began in April<\/a>, when they moved their Security vertical over. They intended to move the entire site to HTTPS by the end of May. But now, five months later, less than half of Wired\u2019s verticals are using HTTPS.<\/p>\n<p>There are two persistent issues that have been holding Wired back from a full-site switch: SEO rankings and mixed content.<\/p>\n<p>A temporary drop in SEO is normal and expected, because Google treats HTTP and HTTPS as separate addresses and the associated rankings need to be migrated. But once that happens, everything should return to normal. Wired has had some lingering issues with SEO and they are \u201cstill trying to figure out why.\u201d<\/p>\n<p>The other issue is mixed content problems, which occur when some of the assets on a page are loaded over HTTP (the challenge we were describing above). Tollman <a href=\"https:\/\/www.wired.com\/2016\/05\/wired-first-big-https-rollout-snag\/\" rel=\"nofollow\">said<\/a> \u201cmany of these issues are from ad assets.\u201d Ad networks have typically been one of the biggest components preventing a transition to HTTPS.<\/p>\n<p>Wired\u2019s progress has further cemented the importance of piloting changes before flipping your entire site over to HTTPS.\u00a0 It is so easy to turn HTTPS on with most servers, that it belies what a major change it is. We always recommend having a detailed plan to ensure that you do not suffer any negative consequences as a result of switching to HTTPS. Google has an <a href=\"https:\/\/support.google.com\/webmasters\/answer\/6073543?hl=en\">excellent set of documentation about best-practices<\/a> for moving from HTTP to HTTPS, including tips on how to avoid SEO problems.<\/p>\n<p>Alexa.com ranks Wired as the 887<sup>th<\/sup> most-visited site in the world. \u00a0This week, they moved their Design vertical to HTTPS, and they hope to have the entire site on HTTPS \u201cby the end of the summer.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The transition to HTTPS is a lot more complicated than it sounds. Wired.com is in the process of switching its entire site from HTTP to HTTPS. For a site of&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2983,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[190,170,191,189],"class_list":["post-2980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-http-to-https","tag-https","tag-transition-to-https","tag-wired-com","post-with-tags"],"views":6544,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/08\/Depositphotos_64347497_m-2015.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=2980"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2980\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/2983"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=2980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=2980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=2980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}