Skip to main content

Why Your Website Needs HTTPS, Even If It's a Brochure Site

Free certificates, a small Google ranking boost, HTTP/2 and ad-injecting hotspots: why every site should move to HTTPS in 2016, not just stores.

The CompleteStatus Team 5 min read

Why Your Website Needs HTTPS, Even If It's a Brochure Site

Want this checked continuously?

CompleteStatus grades your headers, SSL and email security 24/7 — free, commercial use allowed.

Monitor your site free

For most of the web's history, HTTPS was something you bought for the checkout page. Encryption cost money, was said to slow things down, and was for banks, stores and login forms. The blog, the brochure pages and the marketing site rode along on plain HTTP.

That thinking no longer holds. In the last eighteen months most of the old calculation has flipped: certificates are free, the performance argument has reversed, Google gives encrypted sites a small boost in search, and unencrypted pages are being tampered with in transit. If your site is still HTTP-only in 2016, here's the case for changing that, even if you don't sell anything.

HTTPS is about integrity, not just secrecy

The classic objection: "we don't handle anything sensitive, so there's nothing to encrypt." This misunderstands what TLS does. Encryption is only one of its three guarantees:

  • Confidentiality — nobody between the visitor and your server can read the traffic.
  • Integrity — nobody between the visitor and your server can modify the traffic.
  • Authentication — the visitor is actually talking to your server, not an impostor.

The second one gets overlooked. On plain HTTP, every network between your server and the visitor's browser (coffee-shop Wi-Fi, the hotel network, the mobile carrier, the ISP) can rewrite your pages in flight, and some do. Ad-injecting hotel and airport hotspots are well documented, and some ISPs have been caught inserting tracking headers, "data usage" banners or their own ads into customers' pages. Your visitors then see a version of your site you never published, with your name on it. HTTPS makes that kind of tampering detectable and, in practice, impossible.

"Nothing sensitive" is also usually wrong on inspection. Which pages a person reads on a medical practice's site, a law firm's site, a job board: that's sensitive by any reasonable definition, and on HTTP it's visible to every network in the path.

Google is already rewarding HTTPS

In August 2014, Google announced that HTTPS is a ranking signal in search. They described it as a lightweight signal affecting a small fraction of queries, but said they might strengthen it over time to encourage everyone to move to HTTPS.

Google rarely announces ranking signals at all, so it's reasonable to read this as a statement of direction. Sites that migrate now get the benefit early and avoid scrambling later. Do the migration properly, with 301 redirects from every HTTP URL to its HTTPS twin and updated canonical tags, and rankings carry over.

The referrer black hole is skewing your analytics

There's a quieter cost of staying on HTTP that most site owners have never connected to their analytics: when a visitor clicks from an HTTPS page to an HTTP page, the browser strips the referrer.

More of the web is encrypted every month. Google search has defaulted to HTTPS for years, and big publishers and social platforms are migrating. Every visitor arriving at your HTTP site from an HTTPS page shows up in analytics as "direct traffic". The newsletter mention, the link from a popular blog and the search click all land in the same anonymous bucket. If your "direct" traffic looks suspiciously large, this is probably part of the reason.

Move to HTTPS and the referrer flows again (HTTPS→HTTPS preserves it). You get your attribution data back for free.

Certificates are now free

The strongest argument against HTTPS everywhere was cost and hassle: $50–$200 per year per certificate, a clunky purchase flow, manual installation. That argument went away in December, when Let's Encrypt entered public beta. It's a free, automated certificate authority backed by Mozilla, the EFF, Akamai, Cisco and others.

The certificates are free, domain-validated and trusted by all major browsers. Issuance is automated through a command-line client: no CSR-pasting, no emails to an approval address, no invoice. It's still in beta and there are rough edges, but it has already issued hundreds of thousands of certificates. "Certificates are expensive" is no longer a reason.

HTTP/2 is HTTPS-only in practice

HTTP/2, standardized last May, is the first major revision of HTTP since the nineties: multiplexed requests over a single connection, header compression, and real gains on page load. Current versions of every major browser support it.

The detail that matters here is that browsers only speak HTTP/2 over TLS. The spec allows unencrypted HTTP/2, but Chrome and Firefox don't implement it. No HTTPS, no HTTP/2.

That turns the old "encryption is slow" objection around. A TLS handshake does add a little latency, but HTTPS is what gets you a protocol that can make the whole site faster than HTTP/1.1. On modern hardware the crypto overhead itself is negligible.

Browsers are heading toward marking HTTP as insecure

Today, browsers show a padlock for HTTPS and nothing for HTTP. Both the Chrome and Firefox security teams have said publicly that they intend to change this over time, treating plain HTTP as the exception and eventually warning users about it.

No shipping browser labels HTTP pages as insecure yet, and there's no firm timeline. But the direction is clear, and site owners who wait for the warnings will be migrating in a hurry alongside everyone else who waited.

Making the move, and keeping it working

A sane migration checklist: get a certificate (free, see above), install it, fix mixed content (every image, script and stylesheet must load over HTTPS too), 301-redirect all HTTP URLs to HTTPS, and enable HSTS once you're confident.

Then comes the part people forget: a certificate is not a one-time task. Certificates expire (Let's Encrypt's after 90 days, by design), and an expired certificate is worse than no HTTPS at all, because browsers greet your visitors with a full-page security warning. Renewal automation tends to fail quietly, and nobody notices until customers do.

Alongside uptime checks, CompleteStatus monitors your SSL certificates from the outside (validity, chain and expiry) and warns you well before the expiration date, not the morning after.

Create a free account and point a monitor at your newly encrypted site.

Written with AI assistance and reviewed by the CompleteStatus team.