SlideShare a Scribd company logo
#SMX #24A3 @patrickstox
The Good, the Bad, and the Terrifying
Better Safe Than Sorry With HTTPS
#SMX #24A3 @patrickstox
You Know You Should Have Switched Right?
#SMX #24A3 @patrickstox
THE INFORMATION
#SMX #24A3 @patrickstox
HTTPS Everywhere
https://www.youtube.com/watch?v=cBhZ6S0PFCY
HTTPS as a Ranking Signal
https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html
HTTPS by Default
https://webmasters.googleblog.com/2015/12/indexing-https-pages-by-default.html
#SMX #24A3 @patrickstox
Then There’s This Guy
#SMX #24A3 @patrickstox
Securing Your Website With HTTPS
https://support.google.com/webmasters/answer/6073543
Google Wrote A Guide To Help
#SMX #24A3 @patrickstox
HTTP to HTTPS: An SEO’s guide to securing a website
http://searchengineland.com/http-https-seos-guide-securing-website-246940
I Also Wrote A Guide To Help
#SMX #24A3 @patrickstox
https://plus.google.com/+JohnMueller/posts/PY1xCWbeDVC
John Mueller Wrote An FAQ
#SMX #24A3 @patrickstox
John Mueller Liked My Guide
#SMX #24A3 @patrickstox
Why Aren’t People Adopting?
#SMX #24A3 @patrickstox
Top Ranking Sites Are Adopting
@methode is Google Webmaster Trends Analyst Gary Illyes
Dr. Pete Meyers of Moz ran a test and showed over 30% of first
page results were secure in June 2016.
https://moz.com/blog/https-tops-30-how-google-is-winning-the-long-war
#SMX #24A3 @patrickstox
THE GOOD
#SMX #24A3 @patrickstox
Authentication
This is who I’m supposed to be talking to
Data Integrity
Who is messing with my stuff
Encryption
Who is listening
What Does TLS Offer?
#SMX #24A3 @patrickstox
When going from HTTPS > HTTP, referral data is dropped. HTTPS
> HTTPS, HTTP > HTTP, and HTTP > HTTPS DO pass the value.
This accounts for a lot of what people call “Dark Traffic” and “Dark
Social”. Switching to HTTPS fixes some of these attribution errors.
Without this referral data, the traffic looks like it’s direct traffic.
Referral Data
HTTP HTTPS
HTTP Yes Yes
HTTPS No Yes
#SMX #24A3 @patrickstox
Read any of the guides out there. They make it sound so easy
because it can be.
Moving To HTTPS Is A Website Migration
#SMX #24A3 @patrickstox
Let’s Encrypt
https://letsencrypt.org/
Hosts are offering them
CDNs are offering them
Free Certificates
#SMX #24A3 @patrickstox
What’s the one thing everyone knows about AMP?
It’s FAST right, but why?
AMP
#SMX #24A3 @patrickstox
Single Connection. Only one connection to the server is used to
load a website, and that connection remains open as long as the
website is open. This reduces the number of round trips needed to
set up multiple TCP connections.
Multiplexing. Multiple requests are allowed at the same time, on
the same connection. Previously, with HTTP/1.1, each transfer
would have to wait for other transfers to complete.
Server Push. Additional resources can be sent to a client for future
use.
HTTP/2 – So Much Goodness
#SMX #24A3 @patrickstox
Prioritization. Requests are assigned dependency levels that the
server can use to deliver higher priority resources faster.
Binary. Makes HTTP/2 easier for a server to parse, more compact
and less error-prone. No additional time is wasted translating
information from text to binary, which is the computer’s native
language.
Header Compression. HTTP/2 uses HPACK compressions, which
reduces overhead. Many headers were sent with the same values in
every request in HTTP/1.1. CloudFlare saw a 30% reduction in size.
HTTP/2 – Even More Goodness
#SMX #24A3 @patrickstox
http://searchengineland.com/everyone-moving-http2-236716
HTTP/2 – Read About It
#SMX #24A3 @patrickstox
• For every 100ms decrease in homepage load speed, Mobify's customer base saw a
1.11% lift in session based conversion, amounting to an average annual revenue
increase of $376,789
• For every 100ms decrease in checkout page load speed, Mobify's customers saw a
1.55% life in session based conversion, amounting to an average annual revenue
increase of $526,147
• Shoppers browse more on faster mobile websites
• An increase of one pageview per user results in a 5.17% lift in user based conversion, i.e.
for each additional page viewed per user, Mobify saw their average customer's annual
revenue increase by: $398,484
Mobify’s Mobile Test
#SMX #24A3 @patrickstox
THE BAD
#SMX #24A3 @patrickstox
What if you’re a website who makes money by sending people from
your website to another website? Affiliates, Directories, Niche
Magazines.
You need that referral data to prove your value!
Referral Data – Didn’t We Say This Was Good?
#SMX #24A3 @patrickstox
Hard Mode
Load balancers, CDNs, legacy infrastructure, legacy software,
multiple CMS systems, routing, APIs
Moving to HTTPS, a new CMS, bringing in outside domains, new
taxonomy, new content, killing old content, redirects, redirects,
and more redirects
Moving To HTTPS Is A Website Migration
#SMX #24A3 @patrickstox
There’s a difference between getting it done and getting it done
correctly.
There’s some hard choices that people aren’t willing to make like
changing providers, upgrading systems, or just killing off things.
Is It Harder For Bigger Companies?
#SMX #24A3 @patrickstox
Making The Switch To HTTPS Can Go Wrong, Ask Buffer
#SMX #24A3 @patrickstox
https://www.wired.com/2016/05/wired-first-
big-https-rollout-snag
https://www.wired.com/2016/08/wired-https-
progress/
Wired’s Transition To HTTPS
#SMX #24A3 @patrickstox
https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
Chrome
#SMX #24A3 @patrickstox
They looked at accessibility via HTTP and HTTPS, redirects, and
status codes.
• 1 in 10 websites had what they considered a flawless HTTPS setup.
• 60% of the websites tested have no HTTPS whatsoever (increasing to over 65% when
taking into account websites with errors in SSL setup).
• Almost 1 in 4 domains were missing a canonical HTTPS version.
• Almost 1 in 4 domains were using 302 (temporary) redirects instead of 301
(permanent) redirects.
• Even Google can’t be bothered to use permanent redirects and uses temporary
redirects (HTTP status code 302) instead.
LinksSpy Analyzed 10,000 Top Domains
#SMX #24A3 @patrickstox
THE TERRIFYING
#SMX #24A3 @patrickstox
Do you want to be de-indexed by Bing and Baidu?
TLS SNI
#SMX #24A3 @patrickstox
Injection
Happens all the time with hotel chains, airlines
and ISPs.
AT&T Injecting Ads
http://webpolicy.org/2015/08/25/att-hotspots-now-with-
advertising-injection/
Comcast blocking VPN Traffic
https://blog.wjd.io/comcast-blocks-vpn-traffic
Comcast again Injecting Ads ------------
#SMX #24A3 @patrickstox
Headline
#SMX #24A3 @patrickstox
Think what could happen when a country controls the data.
i.e. The Great Firewall
Injection Is Scary Enough, Censorship Is Terrifying
#SMX #24A3 @patrickstox
Did you know GitHub was DDoS attacked. The attackers hijacked
HTTP connections and rewrote the Baidu tracking code with
malicious JS that attacked two GitHub projects that focused on
Chinese anti-censorship.
http://www.infoworld.com/article/2903533/security/github-still-recovering-from-massive-
ddos-attacks.html
Or How About Attacks?
#SMX #24A3 @patrickstox
Many Apps Send Data Over HTTP
They ask for so many permissions and then they do something like
this. It’s one of the most terrifying things I’ve seen in my life.
#SMX #24A3 @patrickstox
But more than likely your data was already stolen in one of the
many data breaches:
https://haveibeenpwned.com/
Sending Your Data Openly is Scary
#SMX #24A3 @patrickstox
Router
Modem
ISP
What else is between the person and the server or CDN?
Just Because Your Site Shows Secure, Not Everything Is
#SMX #24A3 @patrickstox
https://www.troyhunt.com/understanding-http-strict-transport/
The guy takes a Wifi Pineapple with him and shows how websites not
using HSTS, i.e. the first request is still HTTP, can be hijacked if
they’re connected to your wifi.
Troy Hunt Is My Hero
#SMX #24A3 @patrickstox
THE IMPROVEMENTS
#SMX #24A3 @patrickstox
https://istlsfastyet.com/
TLS Improvements By Server
#SMX #24A3 @patrickstox
https://istlsfastyet.com/
TLS Improvements By CDN
#SMX #24A3 @patrickstox
High Performance Browser Networking by Ilya Grigorik
http://chimera.labs.oreilly.com/books/1230000000545
OpenSSL Cookbook & Bulletproof SSL and TLS by Ivan Ristic
https://www.feistyduck.com/books/openssl-cookbook/
https://www.feistyduck.com/books/bulletproof-ssl-and-tls/
https://wiki.mozilla.org/Security/Server_Side_TLS
Performance Resources
#SMX #24A3 @patrickstox
https://www.ssllabs.com/ssltest/
They also have a best practice guide:
https://github.com/ssllabs/research/wiki/SSL-and-TLS-Deployment-Best-Practices
Test Your Server
#SMX #24A3 @patrickstox
LEARN MORE: UPCOMING @SMX EVENTS
THANK YOU!
SEE YOU AT THE NEXT #SMX

More Related Content

PPTX
Everyone Screws Up HTTPS
PPTX
SMX Advanced 2018 Solving Complex SEO Problems by Patrick Stox
PPTX
Everything That Can Go Wrong Will Go Wrong - Tech SEO Boost 2017 - Patrick Stox
PPTX
NLP Sitemap SMX 2016 Patrick Stox Latest In Advanced Technical SEO
PPTX
Enterprise SEO Chaos - SMX Advanced 2016
PPTX
Google's Top 3 Ranking Factors - Content, Links, and RankBrain - Raleigh SEO ...
PPTX
Troubleshooting Technical SEO Problems - Patrick Stox - Raleigh SEO Meetup
PPTX
SMX Advanced 2018 SEO for Javascript Frameworks by Patrick Stox
Everyone Screws Up HTTPS
SMX Advanced 2018 Solving Complex SEO Problems by Patrick Stox
Everything That Can Go Wrong Will Go Wrong - Tech SEO Boost 2017 - Patrick Stox
NLP Sitemap SMX 2016 Patrick Stox Latest In Advanced Technical SEO
Enterprise SEO Chaos - SMX Advanced 2016
Google's Top 3 Ranking Factors - Content, Links, and RankBrain - Raleigh SEO ...
Troubleshooting Technical SEO Problems - Patrick Stox - Raleigh SEO Meetup
SMX Advanced 2018 SEO for Javascript Frameworks by Patrick Stox

What's hot (20)

PPTX
AMP for Enterprises - SMX West - Patrick Stox
PPTX
Mobile First Indexing - SMX Advanced 2017 - Patrick Stox
PPT
A Technical Look at Content - PUBCON SFIMA 2017 - Patrick Stox
PPTX
Google Tag Manager Can Do What
PPTX
React JS and Search Engines - Patrick Stox at Triangle ReactJS Meetup
PPTX
A Crash Course in Technical SEO from Patrick Stox - Beer & SEO Meetup May 2019
PPTX
Data Visualization for SEO
PPTX
Troubleshooting SEO for JS Frameworks - Patrick Stox - DTD 2018
PPTX
Page Experience Update TMC June 2021 Patrick Stox
PPTX
Raleigh SEO Meetup April 2018 - Dan Hinckley
PPTX
What's Next for Page Experience - SMX Next 2021 - Patrick Stox
PPTX
Website Migrations at SMX Munich 2019 - Patrick Stox
PPT
Pubcon Vegas 2017 You're Going To Screw Up International SEO - Patrick Stox
PPTX
Things Google Tries To Correct For You - SMX Advanced 2019 Insights Sessions ...
PPTX
Google's Search Signals For Page Experience - SMX Advanced 2021 Patrick Stox
PPTX
Where to focus your SEO efforts to have the most impact Digital Summit Atlant...
PPTX
Nofollow UGC Sponsored SEOFromHome Patrick Stox Ahrefs
PPTX
JavaScript SEO Ungagged 2019 Patrick Stox
PPTX
Proactive Measures for Good Site Health - Brighton SEO 2014
PPTX
What's in my SEO Toolbox: Linkbuilding Edition - SMX Milan 2014
AMP for Enterprises - SMX West - Patrick Stox
Mobile First Indexing - SMX Advanced 2017 - Patrick Stox
A Technical Look at Content - PUBCON SFIMA 2017 - Patrick Stox
Google Tag Manager Can Do What
React JS and Search Engines - Patrick Stox at Triangle ReactJS Meetup
A Crash Course in Technical SEO from Patrick Stox - Beer & SEO Meetup May 2019
Data Visualization for SEO
Troubleshooting SEO for JS Frameworks - Patrick Stox - DTD 2018
Page Experience Update TMC June 2021 Patrick Stox
Raleigh SEO Meetup April 2018 - Dan Hinckley
What's Next for Page Experience - SMX Next 2021 - Patrick Stox
Website Migrations at SMX Munich 2019 - Patrick Stox
Pubcon Vegas 2017 You're Going To Screw Up International SEO - Patrick Stox
Things Google Tries To Correct For You - SMX Advanced 2019 Insights Sessions ...
Google's Search Signals For Page Experience - SMX Advanced 2021 Patrick Stox
Where to focus your SEO efforts to have the most impact Digital Summit Atlant...
Nofollow UGC Sponsored SEOFromHome Patrick Stox Ahrefs
JavaScript SEO Ungagged 2019 Patrick Stox
Proactive Measures for Good Site Health - Brighton SEO 2014
What's in my SEO Toolbox: Linkbuilding Edition - SMX Milan 2014
Ad

Similar to Better Safe Than Sorry with HTTPS - SMX East 2016 - Patrick Stox (20)

PPTX
Google are pushing HTTPS hard. Why? And​,​ when should you act? by Mark Thoma...
PDF
SPDY and What to Consider for HTTP/2.0
PPTX
BrightonSEO Sep 2015 - HTTPS | Mark Thomas
PPTX
Accelerated Mobile - Beyond AMP
PDF
OMB M 15-13, Policy to Require Secure Connections across Federal Websites and...
PPTX
SPDY - or maybe HTTP2.0
PPTX
PUM 23-01-2020 BUAS
PDF
Technical SEO for MODX CMS (MODXpo 2017)
PDF
Better Than Best Effort at Bloomberg from ThousandEyes Connect
PPTX
5 SEO trends that won’t quit in 2017!
PDF
BSides Lisbon 2017: David Sopas's 'GTFO Mr. User'
PPTX
Honing headers for highly hardened highspeed hypertext
PPTX
Honing headers for highly hardened highspeed hypertext
PDF
[Search University] How to make it to SERPS in times of Social Search: Impact...
PDF
AMP Accelerated Mobile Pages - The Next Generation SMX London 2017 Dawn Anderson
PPTX
Внедрение протокола SPDY в социальной сети LinkedIn, Omer Shapira (LinkedIn)
PDF
Http/2 - What's it all about?
PPT
2011 03 sem-standard-warsaw trends in 2011
PPTX
SEO for Bloggers
PPTX
Site Speed for Google's Mobile First Index - SMX London 2017
Google are pushing HTTPS hard. Why? And​,​ when should you act? by Mark Thoma...
SPDY and What to Consider for HTTP/2.0
BrightonSEO Sep 2015 - HTTPS | Mark Thomas
Accelerated Mobile - Beyond AMP
OMB M 15-13, Policy to Require Secure Connections across Federal Websites and...
SPDY - or maybe HTTP2.0
PUM 23-01-2020 BUAS
Technical SEO for MODX CMS (MODXpo 2017)
Better Than Best Effort at Bloomberg from ThousandEyes Connect
5 SEO trends that won’t quit in 2017!
BSides Lisbon 2017: David Sopas's 'GTFO Mr. User'
Honing headers for highly hardened highspeed hypertext
Honing headers for highly hardened highspeed hypertext
[Search University] How to make it to SERPS in times of Social Search: Impact...
AMP Accelerated Mobile Pages - The Next Generation SMX London 2017 Dawn Anderson
Внедрение протокола SPDY в социальной сети LinkedIn, Omer Shapira (LinkedIn)
Http/2 - What's it all about?
2011 03 sem-standard-warsaw trends in 2011
SEO for Bloggers
Site Speed for Google's Mobile First Index - SMX London 2017
Ad

More from patrickstox (8)

PPTX
A crash course into SEO and what moves the needle with scalable processes
PPTX
Raleigh seo-most-valuable-seo-presentation-patrick-stox
PPTX
Nofollow UGC Sponsored SEO From Home Patrick Stox Ahrefs
PPTX
Nofollow UGC Sponsored SMX West 2020 Patrick Stox
PPTX
How to find other affiliates most successful content patrick stox
PPTX
Data Visualization for SEO
PPT
International SEO: The Weird Technical Parts - Pubcon Vegas 2019 Patrick Stox
PPTX
Link Reclamation Strategies
A crash course into SEO and what moves the needle with scalable processes
Raleigh seo-most-valuable-seo-presentation-patrick-stox
Nofollow UGC Sponsored SEO From Home Patrick Stox Ahrefs
Nofollow UGC Sponsored SMX West 2020 Patrick Stox
How to find other affiliates most successful content patrick stox
Data Visualization for SEO
International SEO: The Weird Technical Parts - Pubcon Vegas 2019 Patrick Stox
Link Reclamation Strategies

Recently uploaded (20)

PPTX
PRINCIPLES OF MANAGEMENT and functions (1).pptx
PDF
Ramjilal Ramsaroop || Trending Branding
PDF
UNIT 1 -3 Factors Influencing RURAL CONSUMER BEHAVIOUR.pdf
PDF
Mastering the Art of the Prompt - Brantley Smith, HomePro Marketing
PDF
Fly Emirates SEO case study by Rakesh pathak.pdf
PDF
AFCAT Syllabus 2026 Guide by Best Defence Academy in Lucknow.pdf
PDF
Mastering Content Strategy in 2025 ss.pdf
PDF
How the Minnesota Vikings Used Community to Drive 170% Growth and Acquire 34K...
PDF
UNIT 1 -4 Profile of Rural Consumers (1).pdf
PDF
How a Travel Company Can Implement Content Marketing
PDF
AI & Automation: The Future of Marketing or the End of Creativity - Matthew W...
PDF
Coleção Nature .
PPTX
Your score increases as you pick a category, fill out a long description and ...
PPTX
Sumit Saxena IIM J Project Market segmentation.pptx
PPTX
The evolution of the internet - its impacts on consumers
PDF
Hidden gems in Microsoft ads with Navah Hopkins
PDF
NeuroRank™: The Future of AI-First SEO..
PPTX
Mastering eCommerce SEO: Strategies to Boost Traffic and Maximize Conversions
PPTX
Fixing-AI-Hallucinations-The-NeuroRanktm-Approach.pptx
PDF
E_Book_Customer_Relation_Management_0.pdf
PRINCIPLES OF MANAGEMENT and functions (1).pptx
Ramjilal Ramsaroop || Trending Branding
UNIT 1 -3 Factors Influencing RURAL CONSUMER BEHAVIOUR.pdf
Mastering the Art of the Prompt - Brantley Smith, HomePro Marketing
Fly Emirates SEO case study by Rakesh pathak.pdf
AFCAT Syllabus 2026 Guide by Best Defence Academy in Lucknow.pdf
Mastering Content Strategy in 2025 ss.pdf
How the Minnesota Vikings Used Community to Drive 170% Growth and Acquire 34K...
UNIT 1 -4 Profile of Rural Consumers (1).pdf
How a Travel Company Can Implement Content Marketing
AI & Automation: The Future of Marketing or the End of Creativity - Matthew W...
Coleção Nature .
Your score increases as you pick a category, fill out a long description and ...
Sumit Saxena IIM J Project Market segmentation.pptx
The evolution of the internet - its impacts on consumers
Hidden gems in Microsoft ads with Navah Hopkins
NeuroRank™: The Future of AI-First SEO..
Mastering eCommerce SEO: Strategies to Boost Traffic and Maximize Conversions
Fixing-AI-Hallucinations-The-NeuroRanktm-Approach.pptx
E_Book_Customer_Relation_Management_0.pdf

Better Safe Than Sorry with HTTPS - SMX East 2016 - Patrick Stox