Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Google Prioritises Encrypted Websites
News & Analysis

Google Prioritises Encrypted Websites

ISBuzz TeamBy ISBuzz TeamAugust 18, 2014Updated:May 2, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
google_ranking
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Google has announced that it will lower the search ranking of websites that don’t use encryption in order to promote better online security practices.

This is an eminently sound move. If anything, the presence (or otherwise) of encryption on a website should have a higher weighting in the ranking algorithm than the “lightweight” signal accorded. However, adjustments can be saved until later when certain outstanding issues of public-key cryptography are closer to being resolved. These issues include:

–  Checking of certificate status, which is essential for determining whose encryption is to be trusted. The methods are on an evolutionary path from well-intended but cumbersome CRLs through OCSP, OCSP Stapling and towards OCSP Must-Staple;

–  Web browsers becoming better at clearly indicating to lay users/end-users precisely whose website is being visited, and precisely whose certificate is used to secure the website;

–  Certificate pricing to not drive budget-constrained SMEs into the arms of dodgy certificate authorities (CAs);

–  Attacks against the PKI — i.e. against CAs and Root CAs: spoofing, theft, denial-of-service and other threats; and

–  Proactively beefing up and bolting down OpenSSL.

With issues such as these resolved, and if other search engines join Google in rewarding the use of encryption, the decades-old vision of an open and loosely-coupled public key infrastructure (PKI) may yet be realised.

Some people might object that it is not Google’s business to play “Internet cop” and that simple informational sites should not be compelled to unnecessarily employ HTTPS and encryption.

On the first point, the argument about Google playing “Internet policeman” can take off in a number of directions. For instance, in ranking websites, Google takes into account whether the site’s owner has been penalised as a scammer. Should that be Google’s business? Not only that, the ranking algorithm takes into account no fewer than 200 such “signals” as “grammar & spelling”, page age, domain age, and “site & page quality”. If an accusation is to be made in terms of “Internet policing”, then it probably ought to have been made from the beginning with respect to the number of signals listed above.

Google values the details of how many signals are used for a ranking and how much each signal influences rankings. In that respect, we do not know the weighting of the “encryption” signal within the ranking algorithm. However, the company did say in its blog posting:

“For now it’s only a very lightweight signal—affecting fewer than 1% of global queries, and carrying less weight than other signals such as high-quality content—while we give webmasters time to switch to HTTPS. But over time, we may decide to strengthen it, because we’d like to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web.

“In the coming weeks, we’ll publish detailed best practices (we’ll add a link to it from here) to make TLS adoption easier, and to avoid common mistakes.”
(Ref: http://googleonlinesecurity.blogspot.in/2014/08/https-as-ranking-signal_6.html, and .)

On the second point of objection above, while acknowledging the plight of those running small and/or plain informational (i.e. non-transactional) web sites, it should be noted that HTTPS can help protect websites from some forms of malware and code-insertion attacks. The Electronic Frontier Foundation (EFF) has for long espoused an “HTTPS-Everywhere” mentality, and in support of this it makes browser plug-ins that help to enforce that approach.

Furthermore, pricing and performance objections are largely historical. SSL certificates from reputable organisations can be had for US$10/year and less. While it is true that blue-chip CAs can charge as much as US$500/year, at the other end of the scale are organisations offering TLS/SSL certificates for free. As far back as 2010, Google reported: “On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10 KB of memory per connection and less than 2% of network overhead.” Researchers confirm that most of the overhead is not in the cryptographic stages, but in the “handshaking”, cipher-agreement stages.

This is not necessarily the opinion of Sestus, which develops authentication software with no dependence on Google or SSL technologies. It is a professional opinion. If it would cost me GB£50/year to raise my informational website in the web search rankings, I would consider it money well spent — particularly as the measure would be adding to my site’s security, in any case.

By Toyin Adelakun, VP, Sestus

sestus_logoSestus is an online security company offering a suite of ground-breaking security products used to satisfy multi-factor authentication requirements (FFIEC, CJIS, PCA, HIPAA). Sestus’ products are used by both regulated and non-regulated companies who wish to improve their online security.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}