Site not secure? Google confirms it will punish you with lower search rank

happygeek 3 Tallied Votes 716 Views Share

An interesting appeared yesterday in the official Google Online Security and Webmaster Central blogs which confirms that in an effort to "make the Internet safer" it has been testing a system which looks at "whether sites use secure, encrypted connections as a signal in our search ranking algorithms." This follows calls for HTTPS everywhere at the recent Google I/O a few months back.

Google says is has seen positive results, and is now actually using HTTPS as a ranking signal albeit a "very lightweight" one which only impacts <1% of queries. Nonetheless, the intention is now clear that this will be the way forward and the signal will most likely be given more weight once website owners have had fair chance to make the move from HTTP to HTTPS.

Keep an eye open for official announcements from Google in the coming weeks, including best practice advise such as using 2048-bit key certificates and relative URLs for resources that reside on the same secure domain (using protocol relative URLs for all other domains.)

Mark Sparshott, a director at security vendor Proofpoint, says "I welcome Google's move to use HTTPS as ranking signal and downgrade those sites that are not encrypting connections to their visitors but caution that the minimal scope and weighting Google are applying may not be enough of a deterrent for poor security best practice yet."

Dani AI

Generated

A short, practical update and checklist that fills gaps in the thread (cost, hosted builders, and migration steps).

Major practical barriers that people worried about in 2014 — buying a paid certificate and paying for a dedicated IP — are mostly gone. Free, automated certificate authorities and server-name routing make HTTPS issuance and renewal trivial for most sites. (letsencrypt.org)

Hosted builders mentioned earlier in this thread (Wix, Squarespace, Weebly) now provision and renew HTTPS automatically for published sites and handle the common redirects for non-technical users; that makes them a safe option if managing certificate rotation is unwanted work. Confirm the custom domain is connected and the platform’s SSL option shows as active after publishing. (support.wix.com)

Short, high-impact migration checklist (apply to any host):

  • Ensure a valid certificate is active (use host-managed certs or a CA like Let’s Encrypt).
  • Put in site-wide 301 redirects from http:// to https://.
  • Update canonical tags, internal links and any hard-coded asset URLs to HTTPS.
  • Submit the HTTPS sitemap(s) and verify the HTTPS property in Search Console.
  • Scan and fix mixed-content (blocked resources) before forcing HTTPS.
  • Update analytics and third‑party integrations to the HTTPS URLs.
    Keep redirects live while search engines re-index (Google recommends keeping them in place during the transition). (developers.google.com)

Troubleshooting and verification: use the browser console to find mixed-content errors, run a TLS configuration check (Qualys SSL Labs) and an audit with Lighthouse/web.dev to catch security and page‑experience issues. Hosted platforms automate many steps, but a quick post‑publish audit avoids surprises. For the concerns raised by and the question from : the ecosystem now makes HTTPS low-cost and low-friction; the remaining work is primarily testing and updating links. (dhosting.pl)

rogerandre 0 Newbie Poster

As a non web designer and on top of that, not having the will to deal with web designers; was using the likes of Wix premium a safe desicion? I'm also thinking of Weebly and Squarespace here.

PixelatedKarma 65 Junior Poster in Training Featured Poster

Ahhh Davey you beat me to it! I think this is really great news overall for the internet, its users, and most importantly user privacy.

Unfortunately I do fear that this will be the beginning of the end of websites built "just because" - ie. fan sites, hobby sites, etc. Not many of these people are going to want to pony up an additional $100+ a year for an SSL certificate plus the money for a dedicated IP to work with that SSL cert.

On the bright side it may help boost web site design and development companies sales because the average user probably won't want to spend the time buying an SSL certificate or making a self signed certificate.

- all those Companies will be able to help you get an https site and walk you through the process if not do it themselves for you.

Dani 5,664 The Queen of DaniWeb Administrator Featured Poster

There's a discussion about this in our SEO forums and I seem to be the only one who is against the whole idea.

http://www.daniweb.com/internet-marketing/search-engine-optimization/threads/483040/google-is-now-ranking-websites-with-https-higher-in-its-search-results

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.