Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

BrightonSEO Sep 2015 - HTTPS | Mark Thomas

This presentation is going to focus on HTTPS, the challenges people are facing when migrating and why you should be planning your migration.

  • Login to see the comments

BrightonSEO Sep 2015 - HTTPS | Mark Thomas

  1. 1. HTTPS Google are pushing HTTPS hard. Why? And, when should you act? Mark Thomas | @SearchMath
  2. 2. Why push HTTPS?
  3. 3. June 26th 2014
  4. 4. “Individually, the meta data you can gather from unencrypted sites can seem benign, when you put it all together it uncovers a lot about my intent and can actually compromise privacy.” Ilya Grigorik
  5. 5. August 2014 “Making the internet safer more broadly”
  6. 6. Maile Ohye SMX Advanced 2015 HTTPS benefits: • Authenticates the site • Grants data integrity for the client • Gives encryption which is good for the user “For new and particularly powerful web platform features, browser vendors prefer to make the feature available only to secure origins by default.” Sounds interesting!!!!
  7. 7. August 2014 “Making the internet safer more broadly” “Over time, we may decide to strengthen it.” “It’s only a very lightweight signal”
  8. 8. Where are we?
  9. 9. HTTPS & Mobile updates had a lot to live up to
  10. 10. Growing trend towards HTTPS 5% 6% 7% 8% 9% 10% Jan March April May June July August % Alexa Top 100K Websites on HTTPS (2015), DeepCrawl 0% 20% 40% 60% 80% 100% Jan March April May June July August % Alexa Top 100K Websites HTTPS/HTTP, DeepCrawl HTTPS HTTP Opportunity
  11. 11.
  12. 12.
  13. 13. Why are people experiencing so many problems?
  14. 14. • Speed - HTTPS runs slower than HTTP • All resources (JS, CSS, images) need to be on HTTPS. • Internal links, Sitemaps, canonical tags, robots.txt file and analytics tracking codes need to be updated to refer to HTTPS version. • 302 redirects not a clear enough signal that the site has moved to HTTPS. Google specifically state that 301 redirects should be used. • Avoid redirect chains – avoid latency • HSTS not enabled in addition to HTTPS • Might incur issues with third-party resources (e.g. ad networks) • Analytics and backlink data could be affected. • Social shares also need to be migrated/managed to retain social proof (only Facebook, Google +1 and LinkedIn shares transfer automatically, although this can still take weeks/months).
  15. 15. Verify all site variants in Search Console!
  16. 16. Managing HTTPS migration
  17. 17. When should you migrate? New Websites: Definitely build on HTTPS Existing Websites: Migrate to HTTPS when you’re next planning a domain migration Or, Build the infrastructure to support HTTPS during a site redevelopment for a later URL migration
  18. 18. Google’s position +12 Months
  19. 19. Dealbreaker
  20. 20. A more conciliatory tone
  21. 21. “Maybe it makes sense to wait half a year or so until all of the ad networks I rely on to keep the site running are ready to handle HTTPS properly.” August 28th 2015
  22. 22. elegant-weapon-for-a-more-civilized-marketer
  23. 23. Where next?
  24. 24. HTTP/2 > HTTP/1.1
  25. 25.
  26. 26. What is HTTP/2? HTTP/2 (originally named HTTP/2.0) is the second major version of the HTTP network protocol used by the World Wide Web. It is based on SPDY. HTTP 1 was designed for webpages with few external assets. Browsers typically downloaded assets sequentially, but this wasn’t a problem on lighter pages. Now most webpages have 50+ resources, which is difficult for HTTP 1 to handle. HTTP/2 downloads many resources at the same time, prioritizes them and supports compressed HTTP headers.
  27. 27. The proposed changes do not require any changes to how existing web applications work, but new applications can take advantage of new features for increased speed. HTTP/2 allows the server to "push" content, that is, to respond with data for more queries than the client requested. HTTP/2 enables a more efficient use of network resources and a reduced perception of latency by introducing header field compression and allowing multiple concurrent exchanges on the same connection. It also introduces unsolicited push of representations from servers to clients. This specification is an alternative to, but does not obsolete, the HTTP/1.1 message syntax. HTTP's existing semantics remain unchanged. Googlebot did not (as of June 2nd 2015) support HTTP/2
  28. 28.
  29. 29. HTTP/2 +20% to 30% Quicker HTTP/1.1
  30. 30. Popular sites using HTTP/2
  31. 31. And finally, the punch line…
  32. 32. HTTP/2 and HTTPS “Although the standard itself does not require usage of encryption, most client implementations (Firefox, Chrome) have stated that they will only support HTTP/2 over TLS, which makes encryption de facto mandatory.”
  33. 33. Thank you Slides available: @SearchMATH