{"id":4102,"date":"2017-05-17T10:46:51","date_gmt":"2017-05-17T14:46:51","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=4102"},"modified":"2018-09-27T07:15:18","modified_gmt":"2018-09-27T11:15:18","slug":"http-website-1999","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/http-website-1999\/","title":{"rendered":"So you want to make an HTTP Website? Enjoy 1999."},"content":{"rendered":"<h2>Plain-text sites are stuck with a technology from 20 years ago.<\/h2>\n<p>Before you go building a brand new HTTP website, think long and hard about 1999&#8230; In 1999:<\/p>\n<ul>\n<li>The global population hit 6 billion (we are well over 7 billion today),<\/li>\n<li>Intel introduced the Pentium III processor,<\/li>\n<li>Fight Club and The Matrix were released in theaters,<\/li>\n<li>and HTTP 1.1 was new.<\/li>\n<\/ul>\n<p><span id=\"newline\"><\/span><br \/>\nThat\u2019s right \u2013 HTTP 1.1 is from 1999 (actually, the first RFC is from 1997). So when you access a site over HTTP today you are using a technology that is 18 years old. Do you still work on a computer with a 400mhz processer and 128mb of RAM? No? So why serve your webpage from an equally outdated technology.<\/p>\n<p>When HTTP\/2 was finalized in 2015 it was the first upgrade to the HTTP protocol in more than a decade. It brought loads of improvements \u2013 <a href=\"https:\/\/http2.github.io\/faq\/#why-is-http2-multiplexed\" rel=\"nofollow\">multiplexing<\/a>, server push, header compression, and ditched the need to set up multiple TCP connections. Sounds great, right? So you should make sure your website is using HTTP\/2 since it\u2019s a huge upgrade to HTTP 1.1.<\/p>\n<p>There is just one \u2018catch\u2019 \u2013 all browsers require you support HTTPS in order to use it.<\/p>\n<p>That\u2019s a good thing. Absolutely every site \u2013 new and existing \u2013 needs to be using HTTPS. Now, we know migrating an existing site can take time (we hope you have started working on that, or at least have a detailed plan). But news sites have no excuse. This is your chance to build everything from the ground up to be the best that it can be.<\/p>\n<p>Here is why you want to use HTTPS:<\/p>\n<h2>More Than Just Encryption<\/h2>\n<p>We often hear people say that they don\u2019t need HTTPS because users don\u2019t need to login or the content of the site \u201cisn\u2019t sensitive.\u201d<\/p>\n<p>The problem is that this ignores the multiple benefits that HTTPS provides. It isn\u2019t just about encryption (which is hugely important) \u2013 you also get integrity and authentication.<\/p>\n<p>Integrity means that the data you send from your server is the same data your visitors will receive \u2013 with nothing added or removed along the way by networking tampering from an ISP, government, or other pesky person (more on this at the end).<\/p>\n<p>Authentication ensures that you \u2013 and your users \u2013are actually connected to your server. Over HTTP, anyone could be responding to requests to access your server. That is pretty shocking when you think about it.<\/p>\n<p>HTTPS prevents man-in-the-middle attacks and network re-routing \u2013 so no other server can pose as you. This is a risk no matter who you are. Network attackers don\u2019t have to target you \u2013 they can just start redirecting any and all sites. You want your users to know who they are really talking to.<\/p>\n<h2>Security AND Speed<\/h2>\n<p>Your site will be faster on HTTPS. Thanks to those improvements we mentioned in HTTP\/2 you actually get <a href=\"https:\/\/www.httpvshttps.com\/\" rel=\"nofollow\"><strong>better performance<\/strong><\/a> by giving your <a href=\"https:\/\/istlsfastyet.com\/\" rel=\"nofollow\">users a secure connection<\/a>.<\/p>\n<p>It isn\u2019t a small difference either. On real world sites using lots of images and multiple origins, HTTP\/2 can shave seconds off a load time.<\/p>\n<p>So if you (or your bosses) think your site is fine without security, is it also fine being slow?<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4106\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-vs-https.png\" alt=\"HTTP website\" width=\"611\" height=\"215\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-vs-https.png 611w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-vs-https-300x106.png 300w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/p>\n<h2>HTTP\/2 &amp; HTTPS Are the Future<\/h2>\n<p>HTTPS has essentially been declared the future of the internet. That\u2019s because HTTP\/2, the first new version of the HTTP protocol since 1999, <a href=\"https:\/\/www.thesslstore.com\/blog\/not-secure-2017-time-get-ssl-https\/\">will only work with HTTPS<\/a>. All major browsers decided this was the best choice for the future of the web.<\/p>\n<p>Without HTTP\/2 you are stuck on that old, tired HTTP 1.1. Do you really want your new website to rely on technology from <em>the last millennium?<\/em><\/p>\n<p>It isn\u2019t just HTTP\/2 that is being \u2018gated\u2019 by browsers. <a href=\"https:\/\/www.thesslstore.com\/blog\/firefox-55-https-for-geolocation\/\">Mozilla<\/a> and <a href=\"https:\/\/www.chromium.org\/Home\/chromium-security\/deprecating-powerful-features-on-insecure-origins\" rel=\"nofollow\">Google<\/a> are restricting their browsers most powerful features to HTTPS. Browsers are becoming the home of modern applications \u2013 and they are making websites take some responsibility when using features that expose sensitive user data or access. That\u2019s why geolocation, device orientation, AppCache, and notifications are amongst features that require HTTPS.<\/p>\n<p>Eventually, <a href=\"https:\/\/blog.mozilla.org\/security\/2015\/04\/30\/deprecating-non-secure-http\/\" rel=\"nofollow\">Mozilla wants to \u2018sunset\u2019 HTTP<\/a> \u201cafter which all new features will be available only to secure websites.\u201d<\/p>\n<p>&nbsp;<\/p>\n<h2>HTTP is Not Secure<\/h2>\n<p>\u2026And your browser is not afraid to say it. Google Chrome has been leading the charge here. At the beginning of this year Chrome added a \u201cNot Secure\u201d warning to some HTTP pages. Since then that warning has expanded \u2013 <a href=\"https:\/\/www.thesslstore.com\/blog\/chrome-http-warning-spreading\/\">later this year it will appear on all HTTP pages<\/a> when browsing in Incognito Mode. Firefox <a href=\"https:\/\/www.thesslstore.com\/blog\/firefox-52-adds-insecure-password-warning\/\">has a similar warning for pages that accept logins over HTTP<\/a>.<\/p>\n<p>This warning will continue to expand \u2013 <a href=\"https:\/\/security.googleblog.com\/2017\/04\/next-steps-toward-more-connection.html\" rel=\"nofollow\">just last month Chrome engineers wrote<\/a> \u201cwe plan to show the \u2018Not secure\u2019 warning for all HTTP pages.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4105\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-website.png\" alt=\"HTTP website\" width=\"603\" height=\"110\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-website.png 603w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/http-website-300x55.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/p>\n<h2>Protect Your Users &amp; Your Site<\/h2>\n<p>Unfortunately the ISPs who we pay for our Internet access are more interested in <a href=\"https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2016\/08\/03\/comcast-wants-to-sell-your-web-history\/?utm_term=.ef46d8da6a73\" rel=\"nofollow\">squeezing extra profit<\/a> from our data than protecting it. Give these providers <a href=\"https:\/\/arstechnica.com\/tech-policy\/2014\/09\/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality\/\" rel=\"nofollow\">a way to tamper with your website and they will<\/a>.<\/p>\n<p>Our government does not seem to care much either. Earlier this year the US Congress <a href=\"http:\/\/www.npr.org\/2017\/03\/28\/521831393\/congress-overturns-internet-privacy-regulation\" rel=\"nofollow\">went out of its way to *undo* an FCC privacy policy<\/a> that would have limited ISPs abilities to sell your data. Some governments <a href=\"https:\/\/citizenlab.ca\/2015\/04\/chinas-great-cannon\/\" rel=\"nofollow\">have gone so far as to use HTTP sites as a weapon<\/a>.<\/p>\n<p>Its unfortunate, but clear: If you don\u2019t provide privacy to your users, nobody else will.<\/p>\n<p>User don\u2019t want to worry if the history of every page they visit is being cataloged, stored, and sold; and you don\u2019t want to worry about what could be happening once data leaves your server.<\/p>\n<p>Using HTTP means compromising your users privacy, opening your site up to network tampering (which can hurt performance and interfere with how your site is displayed), and dealing with the security risks of man-in-the-middle attacks. What a headache. Just use HTTPS!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Plain-text sites are stuck with a technology from 20 years ago. Before you go building a brand new HTTP website, think long and hard about 1999&#8230; In 1999: The global&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4107,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[169,170,467],"class_list":["post-4102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-http","tag-https","tag-ssltls","post-with-tags"],"views":8843,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/05\/iStock-636480120.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=4102"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/4107"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=4102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=4102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=4102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}