{"id":3397,"date":"2017-01-20T15:17:21","date_gmt":"2017-01-20T20:17:21","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3397"},"modified":"2018-10-02T05:49:42","modified_gmt":"2018-10-02T09:49:42","slug":"not-secure-2017-time-get-ssl-https","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/not-secure-2017-time-get-ssl-https\/","title":{"rendered":"It\u2019s 2017, Which Means It\u2019s Time to Get SSL"},"content":{"rendered":"<h2>The browsers are done asking politely\u2014time to migrate to HTTPS.<\/h2>\n<p>For all the websites out there that are still using HTTP, we want to talk about the importance of providing secure connections to your website by migrating to HTTPS before Google Chrome gives you an ugly surprise by slapping a &#8220;not secure&#8221; label next to your URL in its address bar.<\/p>\n<p>You likely have heard about HTTPS, which is the secure version of HTTP (the internet communication protocol that is used to \u201ctalk\u201d to websites). You may even know why it\u2019s important, but think that it does not apply to your site. We are here to tell you that in 2017, HTTPS is going to be a requirement for every website on the internet. No exceptions.<\/p>\n<p>If you have not been keeping up with developments in web standards, you may have missed the initiative that has been emerging over the last few years: the web community is making SSL encryption a baseline security requirement, and it realistically won\u2019t be possible to stay on HTTP much longer.<\/p>\n<p>We have put together a thorough and up-to-date argument about the benefits of acquiring SSL (and serving your site over HTTPS) and how key internet players (the likes of Google, Mozilla, Microsoft, Apple) have put it at the core of the web.<\/p>\n<p>If you think adopting HTTPS is still only about adding secure connections to your site, you need to read this:<\/p>\n<h2>Why HTTPS?<\/h2>\n<p>First, the basics: HTTPS encrypts your visitor\u2019s data and provides integrity, so that the no one can modify or read what\u2019s being sent and received or perform a man-in-the-middle attack. It helps protect you from attackers big and small \u2013 from governments to coffee shop hackers.<\/p>\n<p>Security is the core purpose of HTTPS. So, while we are excited to tell you about the other benefits (better performance, better SEO) we don\u2019t want you to forget about this one.<\/p>\n<p>If you are handling any personal information at all \u2013 passwords, addresses, financial data, etc. \u2013 using encryption ensures that the data is securely traveling to your servers without the risk of tampering or theft. You MUST start using encryption if you are collecting this type of data or it\u2019s only a matter of time before your users\u2019 safety will be jeopardized. Any business or organization that has a reputation to maintain (or build) needs to be serving its site over HTTPS to secure its connections and protect communication\u2014a data breach could be devastating to your brand. Per the National cyber security Alliance, 60% of small businesses that suffer a hack or breach end up going under within six months of the incident.<\/p>\n<h2>Secure by Default<\/h2>\n<p>But HTTPS is not just about protecting personal data. Every byte that travels to and from your server deserves equal protection. We have entered the \u201csecure by default\u201d era \u2013 where security is becoming a core piece of a system\u2019s design instead of an afterthought.<\/p>\n<p>With <a href=\"https:\/\/www.washingtonpost.com\/news\/wonk\/wp\/2013\/06\/12\/heres-everything-we-know-about-prism-to-date\/?utm_term=.aa440192e5d7\" rel=\"nofollow\">evidence of wide-spread internet surveillance<\/a>, governments <a href=\"https:\/\/deibert.citizenlab.ca\/2016\/08\/disarming-a-cyber-mercenary-patching-apple-zero-days\/\" rel=\"nofollow\">paying millions of dollars to hack political activists<\/a>, and <a href=\"https:\/\/www.thesslstore.com\/blog\/dnc-hacking-scandal-happened-typo\/\">phishing campaigns hitting everyone<\/a>, it\u2019s no wonder that our industry has realized that security is a necessity and not an option.<\/p>\n<p>Encryption has gained a ton of traction and adoption since Edward Snowden leaked documents showing just how much of our plaintext internet activity was being monitored and recorded. Major <a href=\"https:\/\/cdt.org\/blog\/its-time-to-move-to-https\/\" rel=\"nofollow\">civil liberties advocates<\/a> and <a href=\"https:\/\/www.eff.org\/encrypt-the-web\" rel=\"nofollow\">privacy groups<\/a> have adopted the call to encrypt the web to protect us from this threat.<\/p>\n<p>[su_pullquote]\u201c[W]e plan to label all HTTP pages as non-secure.\u201d[\/su_pullquote]<\/p>\n<p>But encryption isn\u2019t just for protecting yourself from the big bad guys. Comparably benign threats \u2013 like ad injection &#8211; can also be stopped by HTTPS. It\u2019s unfortunate, but <a href=\"https:\/\/dailysocial.id\/post\/the-unethical-advertising-behaviors-of-mobile-telcos\" rel=\"nofollow\">service providers<\/a> have <a href=\"http:\/\/arstechnica.com\/tech-policy\/2014\/09\/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality\/\" rel=\"nofollow\">shown they will modify your webpage<\/a> and abuse your <a href=\"https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2016\/08\/03\/comcast-wants-to-sell-your-web-history\/?utm_term=.d88bd11221c7\" rel=\"nofollow\">privacy if it\u2019s not protected<\/a>. By providing authenticated connections, HTTPS prevents that sort of network-level tampering on your site. This ensures you can give a consistent experience to your users and that the bytes you are sending are the only ones your visitors receive.<\/p>\n<p>Finally, when someone connects to your site, it is their data that is being put onto the internet. You should give them the option to keep that data secure by providing encryption. This is particularly relevant in situations where a user may want to keep his or her browser history private. Without HTTPS, it\u2019s easy to track what pages someone was viewing on your site. With HTTPS, some degree of anonymity can be maintained while browsing.<\/p>\n<h2>The Internet of Tomorrow Will Be Encrypted<\/h2>\n<p>Now, internet giants like Google, Facebook, Mozilla, and the IETF are planning on making sure the future of the internet is using HTTPS. Meaning that soon, unsecure HTTP will become a thing of the past.<\/p>\n<p>Perhaps the largest reason for this, at least long-term, is that all the major browsers \u2013 Chrome, Firefox, Edge, and Safari \u2013 have decided that HTTP\/2 will only be available to sites that use HTTPS. This major upgrade to the HTTP protocol (the first in nearly two decades) brings huge performance improvements (<a href=\"https:\/\/www.thesslstore.com\/blog\/introduction-to-http2-hypertext-transfer-protocol\/\">here is a brief introduction to HTTP\/2<\/a>). For the internet, this jump from HTTP\/1.1 to HTTP\/2 is going to be like upgrading from horse-drawn carriages to motorized cars.<\/p>\n<p>While it will likely take years, the entire internet will slowly migrate to HTTP\/2. When that does happen, the death of unsecure HTTP will be official. Migrating to HTTPS isn\u2019t a question of \u201cif,\u201d it\u2019s a question of \u201cwhen.\u201d<\/p>\n<p>We think we have a pretty good case for why 2017 should be the year you adopt HTTPS:<\/p>\n<h2>Insecure Sites Will Be At a Disadvantage<\/h2>\n<p>So far we have talked about how encryption protects you, and why the internet community is moving towards an HTTPS-only future. But what we haven\u2019t mentioned is that sites that remain on insecure HTTP will be at a competitive disadvantage.<\/p>\n<p>In order to effectively motivate the millions of websites out there to migrate, there are both incentives for adopting HTTPS, and penalties for failing to.<\/p>\n<p>The biggest penalty will be coming from Google and Mozilla, who\u2019s Chrome and Firefox browsers- which make up <a href=\"https:\/\/analytics.wikimedia.org\/dashboards\/browsers\/#all-sites-by-os\" rel=\"nofollow\">50% of the browser market<\/a> \u2013 will be warning users when they visit HTTP sites.<\/p>\n<p><strong>This behavior is already starting<\/strong>.<\/p>\n<p>Both upcoming releases of Chrome (v56) and Firefox (v51) \u2013 which are due out the last week of January \u2013 will display a warning for any HTTP page that contains a password field or credit card form. Chrome\u2019s warning will be more severe \u2013 on the left-hand side of the address bar it will read \u201cNot Secure.\u201d Firefox will show a <a href=\"https:\/\/blog.mozilla.org\/security\/2017\/01\/20\/communicating-the-dangers-of-non-secure-http\/\" rel=\"nofollow\">broken padlock icon<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3398\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/HTTPS2017.png\" alt=\"HTTPS, Not Secure, SSL\" width=\"591\" height=\"108\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/HTTPS2017.png 591w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/HTTPS2017-300x55.png 300w\" sizes=\"auto, (max-width: 591px) 100vw, 591px\" \/><\/p>\n<p>This warning will slowly spread until all HTTP pages display the same &#8220;not secure&#8221; warning. Google developer Emily Schechter <a href=\"https:\/\/security.googleblog.com\/2016\/09\/moving-towards-more-secure-web.html\" rel=\"nofollow\">recently published a blog post<\/a>, saying \u201cwe plan to label all HTTP pages as non-secure.\u201d<\/p>\n<p>As a website owner, you need to seriously consider what the effects of your users seeing that their browser has called your site \u201cNot Secure\u201d will be. We don\u2019t like to cause undue fear, but this is serious and will negatively affect conversation rates, bounce rates, and your users\u2019 confidence.<\/p>\n<p>In addition, Google <a href=\"https:\/\/www.thesslstore.com\/new-to-ssl\/boost-seo-with-ssl.aspx\">has been applying a SEO rankings boost to pages using HTTPS<\/a> since 2014. Some data has shown as much as 5% jump just from this ranking signal.<\/p>\n<p>On to the benefits of SSL\u2026<\/p>\n<h2>HTTPS is faster than ever<\/h2>\n<p>TLS is the protocol that powers HTTPS. The next version, TLS 1.3, will be finalized and supported by consumer libraries like OpenSSL this year.<\/p>\n<p>It\u2019s the first major upgrade to TLS in nearly a decade, and it brings with it a lot of improvements and optimizations. TLS 1.3 will implement new \u201czero round-trip\u201d handshakes, which will make connections faster. In fact, <a href=\"https:\/\/www.httpvshttps.com\/\" rel=\"noffolow\">HTTPS can already be faster than HTTP<\/a>, and TLS 1.3 will only broaden its lead.<\/p>\n<p>The TLS 1.3 designers have also done their own version of spring cleaning \u2013 ridding the new version of aging encryption methods which added more complexity than true security benefits. This means simpler configurations and less blank-staring at huge lists of settings.<\/p>\n<h2>HTTPS is easier than ever<\/h2>\n<p>Five years ago, developers would have probably winced when asked to set up HTTPS. But today it is a totally different story. HTTPS has gone from an essential yet sidelined technology, to one of the most important aspects of your website.<\/p>\n<p>Internet giants like Google and Mozilla aren\u2019t just mandating HTTPS with a memo. They are building suites of tools and new browser behaviors to make it easier than ever to get your site migrated to HTTPS.<\/p>\n<p>Google started by <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-security-indicators\/\">simplifying its security UI<\/a> to make it easier for average users to understand. Then <a href=\"https:\/\/developers.google.com\/web\/updates\/2015\/12\/security-panel\" rel=\"nofollow\">it built a brand new \u201cSecurity\u201d section<\/a> in Chrome\u2019s Developer Tools to make troubleshooting HTTPS painless. Then it worked on open standards like <a href=\"https:\/\/scotthelme.co.uk\/content-security-policy-an-introduction\/\" rel=\"nofollow\">Content Security Policy<\/a> to provide more security.<\/p>\n<p>Mozilla <a href=\"https:\/\/mozilla.github.io\/server-side-tls\/ssl-config-generator\/\" rel=\"nofollow\">built a tool that automatically generates secure SSL\/TLS settings<\/a> for your webserver. Facebook <a href=\"https:\/\/www.thesslstore.com\/blog\/facebook-certificate-transparency\/\">built a free tool to monitor Certificate Transparency logs<\/a> to make sure you know when and where certificates are being deployed for your domains.<\/p>\n<p>After you have your certificate installed, free tools like <a href=\"https:\/\/www.ssllabs.com\/\" rel=\"nofollow\">SSL Labs<\/a> can test your server to make sure everything is working properly.<\/p>\n<h2>There are more benefits than ever<\/h2>\n<p>There are so many reasons to migrate to HTTPS that it is honestly hard to cover them in one post. Since we have already talked for a while, we are going to give you a rapid-fire bullet-point list. Every single one of these links to a great resource where you can learn more (and to convince your colleagues that migrating is a great idea):<\/p>\n<ul>\n<li>HTTP\/2, the literal future of all web communication, <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/blog\/introduction-to-http2-hypertext-transfer-protocol\/\">requires that you use HTTPS<\/a><span style=\"color: #000000;\">.<\/span><\/span><\/li>\n<li>Google gives you an <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/new-to-ssl\/boost-seo-with-ssl.aspx\">SEO rankings boost for using HTTPS<\/a><\/span>.<\/li>\n<li><span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.httpvshttps.com\/\" rel=\"nofollow\">Your site can be faster with HTTPS<\/a><\/span> than HTTP. <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.troyhunt.com\/i-wanna-go-fast-https-massive-speed-advantage\/\" rel=\"nofollow\">Seriously<\/a><\/span>.<\/li>\n<li>Google Chrome will slowly turn up the heat on HTTP, <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/blog\/chrome-start-warning-users-http-2017\/\">eventually marking it \u201cNot Secure.\u201d<\/a><\/span><\/li>\n<li>Browser features that expose more sensitive user information \u2013 <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/blog\/browser-community-pushing-towards-https\/\">including location data, webcam access, and persistent storage \u2013 require HTTPS<\/a><\/span>.<\/li>\n<li>Cutting-edge technologies like AMP, <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Service_Worker_API\/Using_Service_Workers#Setting_up_to_play_with_service_workers\" rel=\"nofollow\">Service Workers<\/a><\/span>, and <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/developers.google.com\/web\/progressive-web-apps\/#dive-deeper\" rel=\"nofollow\">Progressive Web Apps<\/a><\/span> require HTTPS.<\/li>\n<li><span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/blog\/reminder-apple-app-store-ats\/\">All iOS apps will require HTTPS connections<\/a><\/span> to backend servers.<\/li>\n<li>Of course, let\u2019s not forget the core benefit of HTTPS: <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/new-to-ssl\/how-does-ssl-work.aspx\">encrypted data and an authenticated connection<\/a><\/span>.<\/li>\n<li><span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/scotthelme.co.uk\/still-think-you-dont-need-https\/\" rel=\"nofollow\">Many<\/a><\/span> other <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/konklone.com\/post\/were-deprecating-http-and-its-going-to-be-okay\" rel=\"nofollow\">security<\/a><\/span> and <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/twitter.com\/SwiftOnSecurity\/status\/704331207178190850\" rel=\"nofollow\">web<\/a><\/span> experts <span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/snyk.io\/blog\/10-reasons-to-use-https\/\" rel=\"nofollow\">agree<\/a><\/span>: <strong>HTTPS is the right choice<\/strong>.<\/li>\n<\/ul>\n<p>A lot of these developments, while important, are not exactly headline material. It\u2019s easy to miss that an existing feature you use, or a new feature you like, is going to be HTTPS only.<\/p>\n<p>But now it\u2019s time to see the bigger picture. All these small changes are adding up to a very big change: <strong>the end of HTTP<\/strong>. In 2017 we are going to see a massive number of sites adopt HTTPS, and the list of benefits will continue to grow. We don\u2019t want to see anyone get left behind, so put an HTTPS migration on your development roadmap today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The browsers are done asking politely\u2014time to migrate to HTTPS. For all the websites out there that are still using HTTP, we want to talk about the importance of providing&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3399,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[155,170,356,208,357,136,214],"class_list":["post-3397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-google-chrome","tag-https","tag-migrating-to-https","tag-not-secure","tag-seo-rankings-boost","tag-ssl","tag-tls-1-3","post-with-tags"],"views":16193,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/iStock-616889756.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3397"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3397\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3399"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}