To give you a little back story, in 2014, Google announced a call for HTTPS to be used by every website on the web. Google has three main reasons for this that all come back to the desire to create a more secure internet, but before we get to those three reasons, you may be wondering what HTTPS and SSL are.
What is HTTPS?
HTTPS is the acronym for Hypertext Transfer Protocol Secure. It is a protocol used for secure communications over a computer network, like the internet. Communication over HTTPS are encrypted between the client and the server so eavesdroppers don’t listen in, no one tampers with the data, and your website data isn’t forged.
What is SSL?
SSL is the acronym for Secure Socket Layer and is often used interchangeably with the term TLS – Transport Layer Security. Both are cryptographic protocols that help encrypt communications over a computer network. Typically, if a website wanted to encrypt the transmission of its data between the server and the client, they would purchase an SSL certificate that contains an encryption key that is placed on the server.
Why should you care about HTTPS and SSL?
This gets back to the three reasons why Google is calling for all websites to switch to HTTPS. In order to access most websites, the URL usually begins with “HTTP.” This is the unsecured version of the protocol that transfers data between the web server and the browser on your computer or smartphone. Remember that fear you had of using your credit card online? Well, it’s not just credit cards that are of interest.
Google sees three reasons for securing your website with HTTPS and SSL. They are “Authentication,” “Data Integrity,” and “Encryption.” These three reasons speak to a number of issues that have come up when it comes to communications over the web.
Authentication addresses the issue of verifying the ownership of your website. Believe it or not, there are people out there that make replicas of websites and divert traffic to it in an effort to steal from you. Most people know that they need to check for the Green Lock in their browser before entering personal information into the website. You can go one step further and verify the SSL certificate to make sure it belongs to the website you’re on.
Data Integrity speaks to whether or not the data on the site has been tampered with while it’s in transit. If someone knows’s what they are doing and your website is not secure, they can tamper with the data transmitted from your server back to the client. The form submission that the client just sent could go to the hacker and not to you.
Encryption refers to the security of communications between the client and the server so that no one else can read them. This is a key point for commercial websites. While it’s extremely important to encrypt the communications on an e-commerce website, it’s equally important to encrypt the data submitted using forms.
What does an SSL Certificate Cost?
The cost for an SSL certificate will depend on your website’s hosting provider, who they buy the certificate through, and the type of certificate they buy. There are three types of certificates.
- Single Domain – This type of SSL certificate is only valid on one domain URL.
- Multi Domain – Also known as a Universal Communication Certificate (UCC) this secures multiple domain names and multiple hostnames within a domain name. You would set a primary domain and can add up to 99 additional Subject Alternative Names (SANs) in a single certificate. This is great for businesses with multiple subdomains and URLs for different service, product lines or geographic locations.
- Wildcard – This type of certificate is for securing all of the subdomains you may have for a single domain.
When selecting your SSL Certificate, please consult with your web host, marketing agency, and IT department to make sure you are selecting the right option for your entire business.
Why is 2017 the Year of HTTPS and SSL?
Back in 2014, Google said that if your website was HTTPS it would give that site additional ranking signal in search results. This is a good thing for businesses that have websites that are competing with other businesses for position on search engine results pages. Google also said they wouldn’t penalize the websites that are not secure. Well, at least not with their algorithm.
In September 2016, Google announced that in January 2017 they would begin displaying the security of the connection in the address bar of Chrome version 56 and up on pages that display a password and/or a credit card field. This is the beginning of a long-term plan to mark all HTTP pages non-secure.
Google has conducted a number of studies that concluded that visitors do not consider the absence of a “secure” icon a warning. But it should be. This is why Google is taking the extra step to warn users of its browser, which is used by more than 55% of internet users, that the site they are visiting and about to enter their sensitive information into is not secure.
In addition, as part of their long-term plan, Google will likely include pages with contact forms in the coming months. So, while they’re not susceptible to this warning just yet, they will be and you should do something about it now.
What’s the process of changing my site from HTTP to HTTPS?
At TheeDesign, we are prepared to help our clients make this transition as simple as possible with little to no interruption to your website. This means there are potential issues that can happen, which is why this is not a DIY project. Here are a few of the things we will need to do to get your website converted to HTTPS:
- Help you secure the right certificate for your website if you are hosted with us.
- Install the certificate on your website.
- Update the configuration of your website to point to HTTPS instead of HTTP.
- Redirect all incoming requests for your HTTP website to the location of the HTTPS site.
- Re-verify ownership of your website in Google Search Console and update the sitemap location.
- Update your web property’s configuration in Google Analytics.
- Test and confirm that the conversion was successful.
Keep in mind that while the domain of your website is not changing, the address to get there is. HTTP and HTTPS request your website from two different ports on the web server. Because of this, there is a risk that traffic to your website will drop briefly as Google works to re-index your site. This is also why making sure you redirects are working seamlessly is extremely important.
From here, there are a few things to consider. If you have any marketing tools or digital ads pointing to your website you will want to update the URLs they are pointing to. While redirects will be set up to send HTTP request to the HTTPS URL it’s still best practice to change them as redirects slow the request time and could decrease visitors and conversions.
What do I do next?
This isn’t a decision about if you should make the switch. You need to decide when you want to make the switch to HTTPS. In 2017, every new website project we take on will include HTTPS and SSL in the contract. We want every website we make going forward to be secure, especially WordPress websites. Matt Mullenweg of Automattic, the creator of the WordPress project, is heavily advocating that all WordPress websites to be hosted on HTTPS as more and more features in WordPress will require it.