You probably know that whenever you shop online you should always look for the little padlock
on the address bar. This shows (along with the URL starting HTTPS:// rather than more usual HTTP://) that the web page you are browsing is secure, it is encrypted using an SSL Certificate to prevent anyone intercepting information on the page – including any details you may type in. Up until recently, secure webpages using HTTPS:// have been the domain on e-commerce and other sites handling sensitive data such as credit card details but over the past months, Google have upped the ante by recognising that secure pages deliver a better, more reliable experience to site visitors. See this Google Blog Post for more details. As a consequence they have started giving preferred ranking to secure sites. To date, the impact of HTTPS:// on rankings has been limited. High quality page content is still the most significant ranking factor but maybe it is time, particularly if you work in a very competitive field, to start thinking of adding encryption to your site – even if you don’t handle sensitive data.
What is SSL encryption?
SSL stands for ‘Secure Sockets Layer’ and is the world-standard security technology for creating an encrypted link between a server and a browser. Websites with SSL certificates ensure trust and respect from visitors, as SSL technology guarantees stringent security checks are in place to protect private information. In essence, SSL works in 2 ways:
- Encrypting data – which means that hackers cannot see what a browser sends to and receives from a web server.
- Authenticating your website – which means the SSL Certificate tells your browser “This website really is who it claims to be.” For example, when you visit PayPal.com, the SSL verifies the website you are at is actually PayPal, and not a hacker posing as PayPal.com.
How do I add encryption to my site?
First you need to buy an SSL certificate. You can buy an SSL Certificate from numerous websites but it is probably sensible to buy your SSL through your hosting provider. They should provide the easiest setup. AS with most things ‘web’ there is a huge range of cost options. Although there are SSLs offered at less than £10 per year, you should normally expect to pay around £50-100 pa for a standard SSL up to £300-400pa for more comprehensive security (most relevant to e-commerce sites handling payment card details or other sensitive data) Setup normally takes a day or two. Your ISP should be able to advise for your particular site
Will it make it harder for people to use my site?
Short answer – No! The only difference in the browsing experience will be the SSL padlock, and maybe a warm feeling of safety!
When do I need to do it?
If you have an e-commerce site, or another site that handles sensitive data, you should have an SSL already. If you haven’t, I recommend you address the issue of site security immediately. It really isn’t fair to play fast and loose with your customers’ private data! For everyone else, I think it is more a case of being aware and planning SSL/HTTPS:// into future developments. If Google follows up on it’s initial steps and increases the impact of site security on search rankings then implementing on your site may need to be pushed up the priority list.
What if I ignore SSL?
Assuming your site isn’t e-commerce etc., in the short term, not having SSL security is probably no big deal but there is no question that, as time goes on, there are ever more ‘nasties’ out on the internet and they won’t go away. I’m sorry to say that website security will increasingly be the de-facto necessity; Remember those halcyon days when everyone left their front door open and no-one bothered to lock their car! If you want to discuss the potential impact of SSL and HTTPS:// on your website, please get in touch