October 2017: time to switch to HTTPS
Over the past few weeks you may have received a message from Google urging you to implement the HTTPS protocol on your website or web application. But what is it, and why is it important to start using it today?
Google's notice
A security guarantee
HTTPS is a protocol that secures the data transferred when you use a website or web application. Data sent from the site to the browser is usually the site's own content; data traveling the other way, from the browser to the site, is what users enter, such as login, registration or checkout form details.
Knowing this data is encrypted, and therefore can't be used by third parties, becomes especially important for personal and sensitive data, such as account passwords or credit card details.
To find out whether a website or application uses this protocol, just look at the full address in your browser when you visit it:
The system relies on certificates issued by third-party authorities that enable this secure, encrypted exchange, and these certificates must be renewed every year.
Google's decision
In recent months Google has chosen to encourage adoption of this protocol with some soft measures, such as giving sites that use it a boost in search rankings.
Starting this October, a somewhat less gentle measure takes effect: users will see warnings when the site they're visiting doesn't use this protocol.
The warning will only appear when browsing with Google Chrome, not with Internet Explorer, Safari, Firefox and others. Keep in mind, though, that Google Chrome is used by 56% of internet users, and that this applies to every website in the world that doesn't yet use this protocol.
Your situation
If your site has login, registration or credit card payment forms, switching to HTTPS is strongly recommended. If it doesn't, switching is still advisable for the search ranking benefits.
Our solution
If you have a web application, the server hosting it needs to be updated to support this protocol, so it can both accept the certificate and renew it every year by communicating with the third-party authority that issues it. In this article, we explain how to do it with the Ruby on Rails framework.
For a static site, perhaps built with DatoCMS, switching to HTTPS is fairly simple: just move your deployment to a service that supports this protocol, such as Netlify. In that case you'll need the login details for your domain's DNS panel at hand.
Contact us
If you're a Cantiere client and we built your website or application less than a year ago, good news: this protocol is already enabled and you don't need to do anything at all. Otherwise, you can [contact us](https://www.cantierecreativo.net/contatto/) to assess the time and cost of the switch.