Google.com Begins HTTP Strict Transport Security Migration (HSTS)

Aug 1, 2016 - 8:08 am 2 by
Filed Under Google

Green Tech Google 1900px

Google announced Friday they are going HSTS, HTTP Strict Transport Security, for Google.com. That means anyone who tries to go to HTTP will be forced to go to HTTPS, even more than just a 301 redirect.

HSTS prevents people from accidentally navigating to HTTP URLs by automatically converting insecure HTTP URLs into secure HTTPS URLs. Users might navigate to these HTTP URLs by manually typing a protocol-less or HTTP URL in the address bar, or by following HTTP links from other websites, Google said.

Google said they "turned on HSTS for www.google.com, but some work remains on our deployment checklist." I did check, I didn't see HSTS on for them yet but maybe they are rolling it out slowly.

A good way to check is to use SSL Labs test and it would say "HTTP Strict Transport Security (HSTS) with long duration deployed on this server." Here is a screen shot of this site:

click for full size

Of course, do not implement HSTS without HTTPS on your site, that is asking for it. Also, there may be some redirect confusion from GoogleBot tools with that, but do not worry.

Good luck Google going HSTS!

Forum discussion at Google+.

 

Popular Categories

The Pulse of the search community

Search Video Recaps

 
- YouTube
Video Details More Videos Subscribe to Videos

Most Recent Articles

Search Forum Recap

Daily Search Forum Recap: April 29, 2025

Apr 29, 2025 - 10:00 am
Other Search Engines

ChatGPT Search Gains Shopping Search Features (Not Ads) & More

Apr 29, 2025 - 7:51 am
Google Search Engine Optimization

Google: Changing Lastmod Date In Sitemap Isn't An SEO Hack

Apr 29, 2025 - 7:41 am
Bing Search

Bing Tests New AI Answer Summary

Apr 29, 2025 - 7:31 am
Google Ads

Google Tests New Shopping Ads Design

Apr 29, 2025 - 7:21 am
Bing Search

Bing Search Without Microsoft Name By Logo

Apr 29, 2025 - 7:11 am
Previous Story: Yahoo Search Tests New User Interface