Page 1 of 2 12 LastLast
Results 1 to 20 of 31
  1. #1
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    5,098
    Thanks
    433
    Thanked 2,333 Times in 1,555 Posts

    Default Google to use HTTPS as a ranking signal

    Just saw this, thought it may be of interest:

    ...over the past few months we’ve been running tests taking into account whether sites use secure, encrypted connections as a signal in our search ranking algorithms. We've seen positive results, so we're starting to use HTTPS as a ranking signal. For now it's only a very lightweight signal — affecting fewer than 1% of global queries, and carrying less weight than other signals such as high-quality content — while we give webmasters time to switch to HTTPS. But over time, we may decide to strengthen it, because we’d like to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web.


    http://googlewebmastercentral.blogsp...c6e2-199211861
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding - see the spreadsheet here.

  2. #2
    chaumi is offline Private Member
    Join Date
    October 2013
    Location
    East Midlands
    Posts
    1,640
    Thanks
    570
    Thanked 840 Times in 617 Posts

    Default

    Anyone know how you actually 'switch to https'?

  3. #3
    DanHorvat's Avatar
    DanHorvat is offline Private Member
    Join Date
    November 2008
    Location
    Actual location may vary.
    Posts
    1,994
    Blog Entries
    3
    Thanks
    1,417
    Thanked 1,319 Times in 783 Posts

    Default

    By purchasing an SSL/TLS certificate for your site. I got it on my dedicated server but not on individual sites. Https would look strange in the URL if the site isn't dealing with confidential info and payments.

    The basic AlphaSSL certificate is $20/year.
    Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.

  4. The Following User Says Thank You to DanHorvat For This Useful Post:

    -Shay- (7 August 2014)

  5. #4
    sportsfreak is offline Public Member
    Join Date
    February 2014
    Posts
    131
    Thanks
    32
    Thanked 36 Times in 29 Posts

    Default

    https://konklone.com/post/switch-to-https-now-for-free

    I will (at least not yet) go through the trouble.

  6. #5
    chaumi is offline Private Member
    Join Date
    October 2013
    Location
    East Midlands
    Posts
    1,640
    Thanks
    570
    Thanked 840 Times in 617 Posts

    Default

    Seems a strange decision overall, which is why I guess they say affects only small percentage of sites at present.

    You normally see https when it's a financial transaction page, yes? Which makes sense.

    But why would G apply that to an affiliate page about 'how to find the best blue monkeys?'

    Is it that a https page has less vulnerability to hackers etc in general?

  7. #6
    Scampi's Avatar
    Scampi is offline Private Member
    Join Date
    August 2013
    Posts
    855
    Thanks
    371
    Thanked 304 Times in 180 Posts

    Default

    1% of billions of queries is still a very big number. They are probably banking and finance related queries at the moment, thanks for the head-up though.

  8. #7
    DanHorvat's Avatar
    DanHorvat is offline Private Member
    Join Date
    November 2008
    Location
    Actual location may vary.
    Posts
    1,994
    Blog Entries
    3
    Thanks
    1,417
    Thanked 1,319 Times in 783 Posts

    Default

    Https exists to prevent eavesdropping on the information being transmitted, so it makes no sense at all to use it if there's no sensitive information.

    If you have user registration, https will add an extra layer of security for your visitors (their passwords are less likely to get stolen), but Google's intent to use https as a ranking signal is, in general, idiotic.

    The positive comments regarding this change are even more shocking. Everyone seems to be on the bandwagon, in a crusade to make the web more secure by transmitting the blue monkey information over https.

    Https is FAR from being important in terms of security for an average website. There are tons of things which you should do first, but Google can't recognize those. This is easy. Got an "s" next to "http"? Cool, you're secure, here's an extra point.

    "Https everywhere. You can help."

    Again:
    Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.

  9. The Following 2 Users Say Thank You to DanHorvat For This Useful Post:

    chaumi (7 August 2014)

  10. #8
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,921
    Thanks
    4,524
    Thanked 9,282 Times in 5,970 Posts

    Default

    Https exists to prevent eavesdropping on the information being transmitted, so it makes no sense at all to use it if there's no sensitive information.
    I agree, although, I might actually state it a little stronger.

    Using https when there is no logical NEED is just plain stupid. There is ZERO reason to encrypt traffic that is nothing more then informational.

    Rick
    Universal4

  11. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    -Shay- (7 August 2014), sweetbet (7 August 2014)

  12. #9
    sweetbet's Avatar
    sweetbet is offline Public Member
    Join Date
    November 2012
    Posts
    2,824
    Blog Entries
    5
    Thanks
    898
    Thanked 1,574 Times in 1,086 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Using https when there is no logical NEED is just plain stupid. There is ZERO reason to encrypt traffic that is nothing more then informational.
    Exactly right !! I wonder if sites like wikipedia.org will switch to https

  13. #10
    TravG's Avatar
    TravG is offline Private Member
    Join Date
    September 2008
    Posts
    2,069
    Thanks
    34
    Thanked 179 Times in 131 Posts

    Default

    I would think that G will modify this to only pertain to website with sensitive information. I can see it as being somewhat of a penalty rather than a boost if your page contains sensitive info and doesn't have an https I could see your ranking go down, which actually makes perfect sense.

    For what we do I agree there is absolutely no need for it and I am sure Google knows that and I would hope it wouldn't affect any website that doesn't contain sensitive info. I have a feeling a clarification will come out regarding that. I hope at least!
    Live Casino USA - the best USA live online casinos. Play USA online slots and other casino games like USA online blackjack. Play See USAlegalcasinos.com to find the best USA online casino. Want to play USA online poker? Find the best poker sites at 4DeucesPoker.com.

  14. #11
    DanHorvat's Avatar
    DanHorvat is offline Private Member
    Join Date
    November 2008
    Location
    Actual location may vary.
    Posts
    1,994
    Blog Entries
    3
    Thanks
    1,417
    Thanked 1,319 Times in 783 Posts

    Default

    Using SPF/DKIM to authenticate emails would be a MUCH bigger signal that the site is trustworthy.

    You can have https but still send millions of spam mails. You can't spam with SPF/DKIM.

    Google allows webmasters to hide their identity and to cloak emails, but if they're doing so over a secure connection then it's fine.
    Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.

  15. The Following User Says Thank You to DanHorvat For This Useful Post:

    -Shay- (8 August 2014)

  16. #12
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,921
    Thanks
    4,524
    Thanked 9,282 Times in 5,970 Posts

    Default

    /begin off topic
    I see an awful LOT of spam from subnets that use spf and dkim, sure it would be nice if it was the holy grail we all wanted, but it isn't.

    Yes I do spf checks, but I have the mail server set to mark them since a LOT of affiliate programs and other well know non gaming sites still don't use spf records.

    DKIM doesn't stop spammers in any way, it just adds more to the header and allows me to determine the true source of the domain sending the spam.

    Having the actual email address that is sending the email be listed as the actual sender and return, as well as ZERO replayt of any mail that failed this rule, would have reduced spam 8 or 10 years ago. (send a million emails in 1 day and get back 250,000 responses in 2 days would make any isp take notice no matter what their size is....no one could send spam without also being mail bombed...thus all the largest spam operators would have been controlled)

    /end off topic

    Rick
    Universal4

  17. The Following User Says Thank You to universal4 For This Useful Post:

    -Shay- (8 August 2014)

  18. #13
    slotplayer is offline Private Member
    Join Date
    September 2006
    Posts
    1,044
    Thanks
    198
    Thanked 322 Times in 252 Posts

    Default

    Do browsers still throw the security error message for mixed content? Could this be a problem if you're on a secure site but say the affiliate program's free slots are not?

    One of my e-commerce sites uses paypal as the processor. A feature of PayPal is you can have custom checkout pages with your logo and a color scheme to match your site. However as with most sites that use paypal if your site is not on a secure server, when paypal goes to grab the logo jpeg it would trigger the unsecure content message potentionally scaring off customers.

    The way I got around it back in 2004, was e-junkie had free service called SSLpic that allowed you to upload your logo to their secure server. SSLpic would then email you a link to your logo jpeg. You entered this link in the paypal setup instead of a link (to your logo) from your site.

    As Dan said, hosting a secure site is not nearly as expensive as it was 10+ years go.
    Last edited by slotplayer; 8 August 2014 at 2:50 pm.

  19. The Following User Says Thank You to slotplayer For This Useful Post:

    -Shay- (8 August 2014)

  20. #14
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,921
    Thanks
    4,524
    Thanked 9,282 Times in 5,970 Posts

    Default

    The best way to mix secure and non secure pages on a site is to move secure pages into their own folder (set of sub-folders) and then secure those folders.

    One possibility is the error is thrown when grabbing the jpeg is from the certificate not matching the domain the url call is on. If that is the source of the error, whether the call is made from a secure page or not will NOT change the error.

    As far as mixed content, I think people are accustomed to seeing that error when leaving standard pages and going to a page where you need to authenticate or login using a secure page.

    In your particular situation, you could solve the secure/non-secure mixed content error by securing any pages that have anything at all to do with the cart or payments. (again I would recommend moving any appropriate pages into a folder and securing that folder)

    Rick
    Universal4

  21. #15
    slotplayer is offline Private Member
    Join Date
    September 2006
    Posts
    1,044
    Thanks
    198
    Thanked 322 Times in 252 Posts

    Default

    Quote Originally Posted by universal4 View Post
    The best way to mix secure and non secure pages on a site is to move secure pages into their own folder (set of sub-folders) and then secure those folders.

    One possibility is the error is thrown when grabbing the jpeg is from the certificate not matching the domain the url call is on. If that is the source of the error, whether the call is made from a secure page or not will NOT change the error.

    As far as mixed content, I think people are accustomed to seeing that error when leaving standard pages and going to a page where you need to authenticate or login using a secure page.

    In your particular situation, you could solve the secure/non-secure mixed content error by securing any pages that have anything at all to do with the cart or payments. (again I would recommend moving any appropriate pages into a folder and securing that folder)

    Rick
    Universal4
    sorry, I don't understand, is there a way to secure folders without getting an (https) secure domain?

    this is what I'm talking about.

    May 25, 2014 ... Starting with Firefox 23, Firefox blocks active mixed content by default. This
    follows a practice adopted by Internet Explorer (since version 9)

    https://developer.mozilla.org/en-US/..._mixed_content

    My ecommerce site is not on a secure domain as I store no critical data. When a shopper clicks 'add to cart' on my site they leave my site and end up on the paypal shopping cart which is on secure domain.

    However, if I want my store logo to appear on the paypal shopping cart checkout page, the logo needs to be stored on a secure domain or the "do you want to display mixed content" message is displayed. Unfortunately paypal does not allow the logo to be uploaded to their (secure) servers, you can only hot link to it. (oddly they do allow a logo to be uploaded for the packing slip).

    I haven't tried it in years so maybe its changed but the mixed content message would appear for every item they added to the cart and every time they clicked view cart. Even if the visitor said no to displaying the mixed content, all that would happen in my case is my logo would not be displayed.

    Maybe you're right, users are just used to seeing it now so it may not matter but in my experience shoppers could be scared off by a message that has the word unsecure in it.

    As far as the gaming industry goes I'm thinking that if a free slot is hosted on a secure domain and we link to it from an unsecure domain perhaps via an iframe the visitor would get the mixed content message for every game they tried. If they clicked no to the message the game would not load.

  22. #16
    DanHorvat's Avatar
    DanHorvat is offline Private Member
    Join Date
    November 2008
    Location
    Actual location may vary.
    Posts
    1,994
    Blog Entries
    3
    Thanks
    1,417
    Thanked 1,319 Times in 783 Posts

    Default

    Sure I can spam you with SPF/DKIM but you'll know it's me.
    Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.

  23. #17
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,921
    Thanks
    4,524
    Thanked 9,282 Times in 5,970 Posts

    Default

    Right Dan, in my opinion it doesn't really do enough to slow down or limit spam. And since most spammers that have dkim records spam from thousands of ip's that have nothing to do with the domain, blocking techniques based upon dkim is kinda toothless, but does give an avenue to report them.

    I have found though, that most hosts will just use the excuse, well they didn't send the actual mail from these ip's and they ignore the report. It is not how it is supposed to be, but that is a fact I have run into very often.

    Now for mail servers that do a dkim check, and force the mail so that the sender matches dkim records, yes that does help, but it doesn't stop the spam, just gives an avenue to verify the spammer.

    /back to https

    Well there is https on the server (which encrypts the traffic) and then there is purchasing an SSL Certificate. A certificate is not needed in order to have https, but you would only every put an SSL on https pages.

    An SSL Certificate is issued by authorized Certificate Authorities, and shows the visitor that the domain went through a verification process to verify the domain in the specific server it is on.

    In your case slotplayer, I do not recall if adding the https site to the trusted zone of the browser avoids seeing this error, maybe Dan or someone else knows the answer to that. This means users would still see that message, until such time as the browser knows the site is trusted.

    If the mixed content message is the only error you are trying to overcome, having that page secure would likely drop the message, but you would likely need any and all artwork shown on that page to also b in a secure folder.

    Rick
    Universal4

    After re-reading your post explaining the error, and how you got around it previously, it seems to me that you could create a folder and secure it with https, and then place any artwork called from that folder.

    This would create a different error without the SSL Certificate. The server could assign a self-signed certificate, but if the cert is on a domain that is not in the list of "recognized" certificate authorities, the error would be that the cert is not recognized or self signed (and in Firefox it asks if the user understand the risks, and gives the choice to continue knowing the risks, or to add the exception, or to leave). If the exception is added the user would never see the error again.

    With the costs of SSL now (such as the one Dan recommended) it might be worth considering.

    The main thing is to get a cert from a RECOGNIZED Authority, so that most common browsers see it as authorized.

  24. #18
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,921
    Thanks
    4,524
    Thanked 9,282 Times in 5,970 Posts

    Default

    I did not see Alpha listed as a trusted authority for Firefox, but after viewing their site and hitting a cart or two we did not get any errors.

    http://www.alphassl.com/

    Nosing around the site it looks to be $49 a year, but maybe Dan has a special he can recommend. GoDaddy starts $69 a year so he made a great recommendation. Thawte starts at $39 for 1 year (lower for longer terms)

    Rick
    Universal4

  25. #19
    TheGooner's Avatar
    TheGooner is offline Private Member
    Join Date
    March 2007
    Location
    New Zealand
    Posts
    4,563
    Thanks
    2,092
    Thanked 4,533 Times in 2,175 Posts

    Default

    Stupid signal to be measuring ... Google are getting weird.
    Next it will be the Number of "G"s in the domain name.

  26. The Following User Says Thank You to TheGooner For This Useful Post:

    -Shay- (9 August 2014)

  27. #20
    slotplayer is offline Private Member
    Join Date
    September 2006
    Posts
    1,044
    Thanks
    198
    Thanked 322 Times in 252 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Right Dan, in my opinion it doesn't really do enough to slow down or limit spam. And since most spammers that have dkim records spam from thousands of ip's that have nothing to do with the domain, blocking techniques based upon dkim is kinda toothless, but does give an avenue to report them.

    I have found though, that most hosts will just use the excuse, well they didn't send the actual mail from these ip's and they ignore the report. It is not how it is supposed to be, but that is a fact I have run into very often.

    Now for mail servers that do a dkim check, and force the mail so that the sender matches dkim records, yes that does help, but it doesn't stop the spam, just gives an avenue to verify the spammer.

    /back to https

    Well there is https on the server (which encrypts the traffic) and then there is purchasing an SSL Certificate. A certificate is not needed in order to have https, but you would only every put an SSL on https pages.

    An SSL Certificate is issued by authorized Certificate Authorities, and shows the visitor that the domain went through a verification process to verify the domain in the specific server it is on.

    In your case slotplayer, I do not recall if adding the https site to the trusted zone of the browser avoids seeing this error, maybe Dan or someone else knows the answer to that. This means users would still see that message, until such time as the browser knows the site is trusted.

    If the mixed content message is the only error you are trying to overcome, having that page secure would likely drop the message, but you would likely need any and all artwork shown on that page to also b in a secure folder.

    Rick
    Universal4

    After re-reading your post explaining the error, and how you got around it previously, it seems to me that you could create a folder and secure it with https, and then place any artwork called from that folder.

    This would create a different error without the SSL Certificate. The server could assign a self-signed certificate, but if the cert is on a domain that is not in the list of "recognized" certificate authorities, the error would be that the cert is not recognized or self signed (and in Firefox it asks if the user understand the risks, and gives the choice to continue knowing the risks, or to add the exception, or to leave). If the exception is added the user would never see the error again.

    With the costs of SSL now (such as the one Dan recommended) it might be worth considering.

    The main thing is to get a cert from a RECOGNIZED Authority, so that most common browsers see it as authorized.
    thanks,

    I didn't know that. For some reason I just thought getting an https meant getting the certificate. Was that how it was years ago? I'll have go read up on it.

    I know I added Revenue Giants to the IE trusted zone to avoid getting some kind of message.

    Rick,

    I was surfing a little but I could not find any info that said you could have https without a basic certificate?

    Well there is https on the server (which encrypts the traffic) and then there is purchasing an SSL Certificate. A certificate is not needed in order to have https, but you would only every put an SSL on https pages.
    What am I not understanding?


    I agree, I'm not sure what Google is thinking.
    Last edited by slotplayer; 9 August 2014 at 5:38 pm.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •