6 ms·
I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere. Some webmasters say they have "just a content si
by pierrefar 12y ago
I was involved in this launch and I want to address a very common misconception I'm seeing here and elsewhere.
Some webmasters say they have "just a content site", like a blog, and that doesn't need to be secured. That misses out two immediate benefits you get as a site owner:
1. Data integrity: only by serving securely can you guarantee that someone is not altering how your content is received by your users. How many times have you accessed a site on an open network or from a hotel and got unexpected ads? This is a very visible manifestation of the issue, but it can be much more subtle.
2. Authentication: How can users trust that the site is really the one it says it is? Imagine you're a content site that gives financial or medical advice. If I operated such a site, I'd really want to tell my readers that the advice they're reading is genuinely mine and not someone else pretending to be me.
On top of these, your users get obvious (and not-so-obvious) benefits. Myself and fellow Googler and HNer Ilya Grigorik did a talk at Google I/O a few weeks ago that talks about these and a lot more in great detail:
https://www.youtube.com/watch?v=cBhZ6S0PFCY https://www.youtube.com/watch?v=cBhZ6S0PFCY
- radmuzom 12y agoIn my country, the cost of a SSL certificate is around 60% of my hosting costs, per year. I run a low-traffic blog with comments disabled, so users do not "interact" with the site in any way - except consume the content. I don't see any benefit from this.
- grimmfang 12y agoI see the benefits but I have to agree. This is a very real barrier to entry, and not just financially. Making SSL a global standard is just one more thing new web developers have to appreciate.
- lazylizard 12y agohttps://www.startssl.com/?app=1 https://www.startssl.com/?app=1 and https://www.namecheap.com/campaigns/2014/reset-the-net.aspx https://www.namecheap.com/campaigns/2014/reset-the-net.aspx ???
- spain 12y agoStartSSL is pretty harmful as evidenced by the events after Heartbleed. The certificates are free but they charge you to revoke them, and after we found out about Heartbleed and realized a lot of those free certs were compromised a lot of people refused to pay up for their free keys and continue using the compromised ones. What's more is that StartSSL refused to do the right thing and revoke them, leading a lot of folks to even go as far as petitioning to remove StartSSL from Firefox's Certificate Authorities because any given site using their free certs could be compromised. [0] [0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744027 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744027
- ayrx 12y agoErm... Heartbleed has absolutely nothing to do with what version of OpenSSL you use to generate the cert.
- spain 12y agoYou're right, so I fixed my post. What I meant was that my particular cert wasn't compromised. Either way, the StartSSL/Heartbleed fiasco is a real thing and I've added a link to the original discussion I was citing.
- EwanToo 12y agoNo, but if your SSL certificate has been exposed by Heartbleed, it would be sensible to revoke that certificate to prevent potential spoofing attacks, wouldn't it? StartSSL charge you for revoking that exposed certificate, so your choices are you pay for the revocation, or wait until the certificate expires.
- dspillett 12y agoIn there defence this their treatment of revocation requests is made quite plain in their policies, and any heartbleed exposure was not their fault (their signing certs were not affected IIRC). Now if there had been a problem with their signing certificates then I would have expected them to revoke anything affected for free and offer replacements similarly at no cost. OK, they could have done that anyway (or perhaps offered a discount on the revoke charge) as an good will gesture, but they didn't, so what.
- mike-cardwell 12y agoGet a free cert instead?
- chmars 12y agoFree certificates tend to result in ugly warning messages in browsers … Cheap certificates are available, however, they are still not for free. And hosting more than one domain with SSL is a problem too with most hosting providers if you do not want to book additional hostings.
- antsar 12y ago> Free certificates tend to result in ugly warning messages in browsers StartSSL is free, and as long as you correctly bundle the intermediate cert (something you have to do with many, many other CA's anyway) your SSL will look no different than a $100+/year one from an A-list provider.
- mkal_tsr 12y agoI mean, I understand their argument against it, but I think this is one of those cases where the pros definitely out-weigh the cons, this is great.
- chmars 12y agoAnother advantage to we masters with money … why? SSL does not come cheap. Certificates have become cheap but you need your own IP, i.e., shared hosting is a problem and hosting becomes more expensive. Certificate sellers, hosters etc. on the other hand are certainly happy about these new business opportunities – although we all know that SSL is inherently broken. OK, probably still better than nothing! :)
- drdaeman 12y ago> but you need your own IP Not anymore, unless you need to support antiquities like IE7 on Windows XP or some ancient Java-based software. SNI works just fine in other cases.
- jahnu 12y agoHere's a list of browsers that support it... http://en.wikipedia.org/wiki/Server_Name_Indication#Browsers_with_support_for_TLS_server_name_indication.5B10.5D http://en.wikipedia.org/wiki/Server_Name_Indication#Browsers...
- nulltype 12y agoExcept with the most popular version of Python
- icebraining 12y agoWorks fine if you use requests, or any other HTTP library which hasn't been left to rot like the one in the 2.x stdlib.
- Wilya 12y agoOut of the box, requests on Python2.7 doesn't support SNI. It is documented, and all you have to do is install additional packages to enable it, but still, that's not automatic.
- dchest 12y ago
- hadoukenio 12y agoHey Pierre, Quick question. Is the type of certificate also a signal? i.e. self-signed vs plain vs EV?
- dspillett 12y agoI assume self-signed will be treat as having no certificate at all, if the reason for the difference in ranking is that a certificate implies the user will more definitely read what the server sends, as a self-signed certificate protected site is just as easy to MitM as one without a certificate at all.
- btian 12y agoSelf-signed is worse than not having one. Don't do that.
- dserodio 12y agoWhy? The crypto is just as strong with a self-signed cert as a "name brand" cert. The only downside is teaching users to ignore SSL errors, which is bad.
- pdkl95 12y agoPlease stop spreading this lie. It's been debunked many, many times. Just because something doesn't provide 100% security doesn't mean you should give up and use nothing. Once again, self-signed SSL raises the cost of an attack from "basically free" passive monitoring to a much more expensive[1] MitM attack. It's a travesty that apache doesn't simply auto-create a self-signed certificate if it doesn't have one so plain HTTP can be retired forever. Note: this is about transport security, and the UI presented should not suggest any kind of authentication has been achieved. In firefox, this means not showing the "locked padlock" and other changes usually associated with SSL. So please, stop undermining the security of the web. We could have been all-HTTPS a long time ago if this nonsense wasn't brought up each time. [1] and hard to use against everybody simultaneously
- rwhitman 12y agoSo Google's position is that SSL is such a high priority for content sites that they will officially incite a mad scramble for every content site on the planet from big media companies to hobby blogs to secure their page behind https to keep their ranking, but yet doesn't see anything wrong with the fact that every Blogger blog and even the Google Online Security Blog that it is announced on, is insecure. Nice.
- ChrisAntaki 12y ago"A journey of a thousand miles begins with a single step"
- blogspotblog 12y agoI am more than happy to migrate my site to https and I took a two days to watch your youtube video to ensure i do not miss anything But I got one very valid concern. Most websites running some kind of affiliate links and banners. Most of the affiliate links and banners is not on the https platform. This will cause mixed content error message by the browser. First, is using protocol relative urls solve this mixed content error issue? Second, can the non-https affiliate links and banners work correctly(tracking etc) on https website? I am sure this is the one big hurdle need to be addressed or else more than 50% of the websites in existence will have difficulty to migrate.