40 likes | 62 Views
I have said it time and again, but I will never stop saying it because it is true: security is a crucial aspect of SEO that can make or break a brand’s reputation.
E N D
C Y B E R S E C U R I T Y : Introducing HSTS A N Y T H I N G S E O
6 0 % O FS M A L L B U S I N E S S E ST H A T S U F F E RF R O MC Y B E R A T T A C K S Ihavesaidittimeandagain, butIwillneverstopsayingit becauseitistrue: securityisacrucialaspectofSEOthat canmakeorbreakabrand’sreputation. Nobodyisentirely safefromthethreatsofcybercrime. Brandandbusinesses shouldtakecybersecurityseriouslybecausecyberattacks causeseriousdamage. Ihavementionedbeforethat60% ofsmallbusinessesthatsufferfromcyberattacksgooutof businesswithinsixmonths. OneofthesecuritymeasuresSEOprofessionalsuseis HTTPS. However, thereisa securitylayerthatcanprotect yoursiteandyoursearchengineoptimisation. Itiscalled HTTPStrictTransportSecurity (HSTS) available. According toMozilla, HSTS “letsawebsitetellbrowsersthatitshould onlybeaccessedusingHTTPSinsteadofusingHTTP.” This articleaimstodefinewhatHSTSisanddiscusshowitcan protectyoursiteandimproveyourSEO.
“aresponseheaderthat informsthebrowser SearchEngineLanddefinesHSTSas “aresponseheaderthatinformsthebrowseritcanonlyconnecttoa certainwebsiteusingHTTPS”. HTTPSisasecureversionofHTTP. HTTPSencryptsthesessionwithasecure socketlayerorSSLcertificate. Itprotectsagainsthackersthataimstostealsensitiveinformationfromusers. Unfortunately, HTTPSleavesthesiteopentoSSLstrippingwhichhappenswhenahackerchangesthe connectionfromanencryptedconnectiontoanolderversion, likeifasiterelieson301redirectsforswitching fromHTTPtoHTTPS. However, byapplyingHSTS, itforcesasitetoloadoverHTTPSanddisregardsanycallsto tryanHTTPconnection. Thiswillallowthebrowsertoloadthesecureversionimmediatelyandeliminatethe windowforhackerstostealsensitiveinformation. SinceitwillallowthebrowsertoloadtheHTTPSversionimmediatelyandtodisregardanycallstotrythe HTTPversion, itwon’thaveaninitialHTTPattemptthatcausesamilliseconddelayintheloadtime. TheHSTS tellsthebrowsertoonlyusetheHTTPSversionwhichmakestheredirectinstant – andeverymillisecond countsinSEO. SwitchingtoHSTSisamustforaddedsecurityandfasterloadtimes.
H T T P S : / / A N Y T H I N G S E O . W O R D P R E S S . C O M / 2 0 1 8 / 0 9 / 0 3 / C Y B E R S E C U R I T Y - I N T R O D U C I N G - H S T S / Source A N Y T H I N G S E O