23 ms·
Don't Take Security Advice from SEO Experts or Psychics
- jaclaz 9y ago>Don't Take Security Advice from SEO Experts or Psychics Maybe the "Security" is redundant?
- JoshMnem 9y agoSEO is a shady field in general, but not all of it is shady. It can make or break a company and is well worth understanding. There is a lot of bad information out there (like the HTTPS advice above), so it's difficult to find accurate information.
- nerdponx 9y agoMade me think of http://n-gate.com/software/2017/07/12/0/ http://n-gate.com/software/2017/07/12/0/
- cjsuk 9y agoUgh it's like anti vaxxers of the technology sector.
- chickenfries 9y agoBig Encryption LIES
- deleted 9y ago[deleted]
- Finnucane 9y agoKinda dig the Lynx-friendly layout, though.
- krotton 9y agoWoah, sounds like Internet's Gollum with just one more personality.
- justusw 9y agoI've noticed that a lot of the hostility towards HTTPS comes from those who do really shady things online. Like pop-under advertisers that are unhappy that they have to update their own infrastructure, otherwise their unsafe mixed content won't be loaded by a browser. So no, not HTTPS is a threat, but company's unwillingness to innovate. So Chrome's and Firefox's public shaming of unsafe websites is really doing everyone a service. The best thing I've ever done to serving HTTPS was to use Caddy with Let's Encrypt. Seriously. It was incredibly easy to set up. And I've never used Caddy before. https://caddyserver.com/docs/automatic-https https://caddyserver.com/docs/automatic-https describes how to have TLS available right from the first request served.
- jrimbault 9y agoI hope the packages for Apache in mainstream distros will include good defaults settings, I remember somehow hunting for the rules to redirect to https.
- Spivak 9y agoThe other hostility being that HTTPS bundles encryption with identity verification. The fact that we've bundled the practical ability to encrypt your site with a 3rd party gatekeepers is really off-putting to people. A self-signed cert could be supported and effectively trust on first use like SSH and have the same trust model as a DV cert.
- snowwrestler 9y agoI don't know how you use SSH, but I don't permit or establish anonymous SSH connections the way I do anonymous HTTPS connections. SSH is "trust on first use" because the trust is typically established ahead of time by provisioning a username/password or a public/private key pair. Along the same lines, I can use self-signed certs to encrypt the HTTPS connection to my own server, and feel confident because I can validate that it is really my cert and my server. The same is not true of connecting to, say, twitter.com.
- iancarroll 9y ago
- yamann 9y ago> SEO > Expert You have to pick one
- seane 9y ago1. I agree with this criticism of Neil Patel, and the things written about why SSL matters. 2. Neil Patel does not speak for all SEOs :) ...I've read several comments from other SEOs who strongly disagree with what he said. 3. JFC, people, stop linking to his site. Links are currency--it does not matter to him, big picture, if the link is framed by a sentence that says "this person is an idiot." Links only help increase his authority and ability to reach new people.
- overcast 9y agoThe redirection of https to http on neilpatel.com is amazing. That's something I've never seen in my life.
- heinrich5991 9y agoReally? Another popular example is https://store.steampowered.com/ https://store.steampowered.com/.
- StavrosK 9y agoJesus christ...
- ceejayoz 9y agoHoly crap, I've never noticed that. They 2FA me on every login and then do that?!
- overcast 9y agoI've always used the app :/ that's disappointing.
- mschuster91 9y agoLol they're HTTPS on the login form but plain HTTP immediately after... what a joke? That invites people to do cred fishing on bigger LAN parties or conferences...
- 9y ago
- GlennS 9y agoWhat does this mean for intranet sites? Will those need to be HTTPS from October as well?
- sasas 9y agoIf you want to avoid a warning, then yes. That said, is it such a bad thing for enterprises to ramp up the use of HTTPS in their internal networks? This can help prevent some MITM attacks from attackers to breach the perimeter. Enterprises have the luxury of installing their own certificates on managed workstations.
- zerkten 9y agoIt seems that if you plugged into an ethernet port at many companies you'd be able to grab a lot of valuable information due to the lack of HTTPS. The move to SaaS products by departments inadvertently protects the company data in this case while IT teams still rail cloud usage.
- somedumbguy22 9y agoIf other enterprises are similar to the one where I work, the warning will not come up in October. Like all software, we're a few versions back on Chrome. It'll take some time to get up to Chrome 58 :)
- TheAceOfHearts 9y agoIt doesn't seem like an unreasonable requirement. Multiple people might be on the same company network, but they might not all have the same capabilities. By using HTTPS you reduce the risk of credentials being leaked.
- SnacksOnAPlane 9y agoAs long as neverssl.com still exists so I have some way to pop up the login page from captive wifi portals, I'm fine with everyone else going SSL. However, I basically agree that if you're just hosting a blog with no user interaction, there's really no need for it. The threats (for example, somebody hijacks the request and returns different content) are minimal.
- jchw 9y agoYour users might care when malware is injected into your page.
- lol768 9y ago> so I have some way to pop up the login page from captive wifi portals, I'm fine with everyone else going SSL Isn't this the fault of those deploying the captive portal for not implementing RFC7710 and advertising a secure login URL?
- Spivak 9y agoYes, but we have to work around crappy software all the time. I've used portals that only trigger on google.com
- qb45 9y agoFirst time I hear of RFC7710, all I see is HTTP hijacking. Does anybody support it, in particular OS vendors? I suppose some new UI or a new API for browsers would be required.
- dsfyu404ed 9y ago> The threats (for example, somebody hijacks the request and returns different content) are minimal. I wouldn't call injecting malware/adware/advertising minimal.
- organsnyder 9y agoI use example.com for this purpose. I'm guessing that they'll keep listening on port 80 for quite some time.
- danesparza 9y agoWithout certificate pinning, I'm not sure that SSL everywhere is really going to help. Larger ISPs or corporate networks will just get pushed more into the arms of companies like Bluecoat that provide proxies to effectively man-in-the-middle SSL traffic.
- groundCode 9y agoI'm always happy to read Troy's writing and heed his advice. I'm not sure about the whole "Perhaps Neil Patel is hoping that people will be too distracted looking at him in his pyjamas to notice" thing though. I do feel one can offer counter arguments without resorting to that kind of insult and teasing. Especially when you are right.
- zb3 9y agoNote that unless you're using a wildcard certificate, all your subdomains are public when you use HTTPS thanks to Certificate Transparency.
- willstrafach 9y agoWildcard certificate would not help, that only refers to validity, not destination host.
- ceejayoz 9y agoWildcards do help. If you've got super-secret-subdomain.example.com, a wildcard for *.example.com doesn't expose its existence. A non-wildcard certificate does. There's a bit of security-via-obscurity going on here, but sometimes the need for such a thing is out of one's control.
- willstrafach 9y agoI do not understand what you are trying to say. The destination would still be under SNI. Exposing existence is a separate matter, the only thing I can think of is that you're referring to those TLS certificates with multiple domains (almost just as bad as a wildcard certificate). Now that TLS certificates are free, each subdomain can indeed have its own certificate, thereby not causing any exposure.
- pixl97 9y agoI think you are missing what is going on. Lets say you have super secret domain xsrihghufgyssw.foo.com, it is published in your DNS and it is publically reachable, but no one ever knows to look up that domain to reach the website. It is almost impossible for someone to randomly stumble upon or guess that domain name. With certificate transparency there is a log of that certificate being registered so if some group like DDOS for hire wanted to take your services out, they could use all those names as targets.
- jjude 9y agoWhatever Troy says is true. But for bloggers, please know this. The RSS 2.0 spec specifies that the feed url must be http url (and not https). So if you want your feed url should validate (which is a requirement for certain aggregators like AllTop), then it has to be http. I wrote my experience of moving my blog to https about it here: https://jjude.com/cost-of-https/ https://jjude.com/cost-of-https/
- cratermoon 9y agoThat's incorrect. Prior to 2.0 yes, but since 2.0 https is allowed. see https://validator.w3.org/feed/docs/rss2.html https://validator.w3.org/feed/docs/rss2.html in the Comments section.
- jwilk 9y agoRSS is a terrible format. You should use Atom feeds.
- RileyJames 9y agoWell a big thank you to Michael James Field in the comments section. I forced http -> https in cloudfront over the weekend and my traffic from google has been down 20% and falling since. I didn't realise google treated different protocols as different sites. Thank you.
- shanecleveland 9y agoAbsolutely. Not sure how its handled by cloudfront, but make sure you 301 redirect from http to https. And if you monitor your traffic in Google's Search Console tool (why wouldn't you?), you have to set up the https version as a completely separate site. Data for the http site is not reflected in the data for the https site, and vice versa.
- pbhjpbhj 9y agoSo if you add HTTPS to your site you lose continuity of stats and have to amalgamate statistics across "2" sites from then on? .. there's a really good reason for Google to do this, right?
- shanecleveland 9y agoTechnically you can serve different content on http and https (same as with www and non-www). Search Console also allows a way to group together sites to view data/stats together.
- pbhjpbhj 9y agoHave you ever heard of anyone serving different content on http vs https pages with the same URL?
- shanecleveland 9y agoI certainly have not considered a reason for doing that myself. I'm just saying that is the case and it is important to be aware of it to ensure you get credit for backlinks to your site and avoid duplicate content penalties.
- mijoharas 9y agoHas anyone else noticed the "Right to be forgotten message" in google (in europe) upon searching the guys name?
- pbhjpbhj 9y agoI always think "what did they do" as if they're a criminal when I see this. But, realistically they're probably as likely to be a victim!?!
- mijoharas 9y agoGiven that this guy seems to delete comments that show he's wrong, my first instinct was to assume that he was trying to silence detractors. That may be unfair on my part though. On a more general point, does anyone know how to find what pages that are delisted are? I seem to remember some newspaper publishing the pages of theirs that had been delisted.
- jwilk 9y agoDoesn't it happen for all names?
- wnevets 9y agoDoesn't google care about TLS for rankings? Why would any SEO advise against what google wants?
- AJ007 9y agoStep 1 - Make outrageous claim Step 2 - Receive lots of inbound links from people upset with your outrageous claim Step 3 - Cash in on your increased audience (or become elected President)
- Taniwha 9y agoI kind of suspect that someone who has 909442 likes and 909143 people following him knows how to game the system .... And sadly while he may know little about security he may know how to pretend that people like him, which I guess is some form of SEO
- CaptSpify 9y agoSEO isn't about doing the right thing, it's about looking like you are doing the right thing
- rmason 9y agoFYI Neil Patel is the co-founder of both CrazyEgg and Kissmetrics. He blogs, has a popular podcast and gives away some pretty valuable marketing information for free. I follow him and have never thought that he was primarily an SEO expert. He speaks about startup marketing and SEO is certainly a big part of that. He does preach that unless you have the capital, blogging and SEO are one of your few alternatives for marketing in the beginning of your startups life. He may very well be wrong on SSL but surprised he doesn't have other fans on here. I personally have learned a lot from the guy. https://thestartupchat.com/ https://thestartupchat.com/ http://neilpatel.com/blog/ http://neilpatel.com/blog/
- ssharp 9y agoI dropped him off my regular rounds quite some time ago and am generally wary of clicking his site when it comes up in organic searches. I find his site incredibly annoying and very rarely is the information so unique that it couldn't be found elsewhere.
- bhartzer 9y agoI stopped following Neil when one of his posts (written by one of his writers) plagiarized someone else's post and he was publicly called out on it. Neil has been around for a long time... I remember him from the old SEO conference days (PubCon), and at that time he was putting out good material. He's turned into a content marketing organization, the majority of content written by people who he hires to write in his name.
- rmason 9y agoThere are a lot of people advising startups on marketing that have never run a startup. Neil Patel has done it twice, once bootstrapping and the second time raising venture capital. Actually he's done it more times and has talked about his failures and what he's learned. I do agree he needs to change web designers, the advice is golden so you don't need the gaudy design elements.
- dasil003 9y agoIn a way that's even more damning, because he's not just an SEO or marketing guy, he's actually built a couple true tech startups. Presumably he wasn't involved in the security, but it's still extremely alarming that someone with that background would spread such blatant disinformation. Some of his misunderstandings are initially forgivable, but then to delete comments pointing out his mistakes, not issue any correction, and continue blasting out patently false information to a large following is the sort of willful ignorance that deserves to be called out very publicly, hopefully with severe damage to his reputation (although I'm not holding my breath). If he's silencing feedback from actual security experts then what is he whitewashing in other domains?
- dzink 9y agoThere is a reason those guys actively denounce SSL. They use snip.ly and other tools that hijack the clicks from their social media references with an overlay to promote their products. The users see the WSJ or NYT article they clicked on with a free ad for the person who shared it underneath (possibly data too). Those overlays don't work over SSL pages.
- puranjay 9y agoFor what it's worth, my largely ignored website ranked for 3x as many terms in Google Webmaster after I switched to SSL
- bacheson1293 9y agoNeil appears to be deleting any negative comments
- Sleeep 9y agoI think he deleted his Facebook post. I got "the page you requested can't be displayed right now..." message when I clicked the link.
- sadlyNess 9y agoSidenote: Which parses better: buzzfeed-esque, buzzfeedesque or buzzfedian?
- NKCSS 9y agoYou should check the tweet threads https://twitter.com/troyhunt/status/895800744787546114 https://twitter.com/troyhunt/status/895800744787546114 https://twitter.com/troyhunt/status/895758193896202240 https://twitter.com/troyhunt/status/895758193896202240 https://twitter.com/troyhunt/status/895757970729979904 https://twitter.com/troyhunt/status/895757970729979904