Google to default to SSL version for logged in users
googleblog.blogspot.com
googleblog.blogspot.com
https://www.google.com/adsense/support/bin/answer.py?hl=en...
To utilize the NoSSLSearch option for your network, please configure the DNS entry for www.google.com to be a CNAME for nosslsearch.google.com. We will not serve SSL search results for requests that we receive on this hostname. If we receive a search request over port 443, the certificate handshake will complete successfully, but we will then redirect the user to a non-SSL search experience along with an initial message explaining so.
http://www.google.com/support/websearch/bin/answer.py?hl=en&...
Seems like this will mean hugely asymmetrical information about search queries -- Google will still see all Google queries, but nobody else will.
This might also prevent even toolbars from seeing this stuff (remember when Google and Bing went tete-a-tete over that issue?).
It depends. For Gecko, that's a configuration option (defaulting to "send cross-site" at the moment, but subject to change in general).
And as others have pointed out, sites using AdSense can't very well "implement SSL".
Perhaps this provides an incentive for sites to start serving HTTPS-Only, or at least showing Google only the SSL version (e.g. showing rel='canonical' with the HTTPS link). On the other hand, Google is still disincentivizing use of SSL through AdSense, which I believe is still HTTP-Only.
Even with the AdSense disincentive, it could still help. Knowing your referrer keywords is much more important to businesses than AdSense, and it's a very good thing for a site that wants my money to be served by HTTPS-Only, since you can MITM a site easier if there are any HTTP-Only pages on said site.
Sites relying heavily on AdSense, OTOH, would be more likely to be ad-supported rather than product sales-supported, and thus would have less need to be fully secured, since you're less likely to enter sensitive information there (excepting, of course, people who stubbornly reuse the same password everywhere).
I'd like to see this lead to a push of vendors who both sell a product and use AdSense to demand Google support SSL for AdSense, since they would need both referrer data and AdSense to survive. Once Google cracks and adds SSL support to AdWords, smaller sites will be more inclined to offer there content as HTTPS-Only.
It's a step in the right direction, at least.
It isn't even an americanism, its a straight-up misspelling.
Every time I have to type it I die a little inside.
http://en.wikipedia.org/wiki/HTTP_referrer#Origin_of_the_ter...
I rarely spell it "properly" on the first attempt. My brain just auto-corrects it as I type. I try to think of it as an inside joke or something, but - as you can see from my previous comment - it doesn't stop me from being snarky about it.
I know, you get far more entertainment for your buck complaining, but even so, who cares?
Side note: many things commonly refered to as "americanisms" cannot be accurately described as such. See color/colour. Pedants beware.
I quite agree. Unfortunately, there aren't any people that spell the word with three Rs, only HTTP parsers, and I draw the line at bending my conception of language to the will of inanimate agents, as inevitable as this may turn out to be.
>but even so, who cares?
Let's make a deal, I'll stop being irrationally emotional about spelling when everyone else stops being irrationally emotional about brace placement. Cool? ;)
I wonder if Google Analytics will still list the queries. (They mention that Google Webmasters' Tools will give the top 1000 queries, but not individual results.)
To help you better identify the signed in user organic
search visits, we created the token “(not provided)”
within Organic Search Traffic Keyword reporting. You
will continue to see referrals without any change; only
the queries for signed in user visits will be affected.
Note that “cpc” paid search data is not affected.
This will make it much more difficult to measure organic search marketing efforts, but for Google, this should encourage more investment in paid marketing campaigns to measure keyword effectiveness.I've always disabled cross-site referers because it's none of anyone's business how I got to their site. This seems to be the way the winds are blowing now.
So unless gAnalytics is going to be deliberately ignoring incoming referer headers in particular circumstances from now on, things should remain the same if your page uses SSL.
I willing to believe however that they actually are going to be deliberately ignoring/discarding the data even when it's available. That would certainly make the EU happy.
The browser decides when to send a referrer, not Google. You can, for instance, tell your browser never to send them, or to send a specific one.
https://secure.wikimedia.org/wikipedia/en/wiki/HTTP_referrer
In HTML5 you can apparently request that a referrer not be sent, but that's a request, not a command.
I presume they're working around it for ads and (telling webmasters the user is coming from Google) by sending the user through a HTTP page before they reach the result (like DuckDuckGo does, but for the opposite reason).
This is why I use https for gmail and http for search. But I guess I have to use browser based filtering now.
If so, why not use one of the opt out plugins, rather than search over http?
What's interesting to me is they have a double standard: if you pay for placement, you'll get keyword data. If it's organic placement, you won't get keyword data.
I have no opinion, just thought it was interesting.
It will also stop other search engines like Bing from utilizing keyword referral data in their search algorithms.
Of course you can manually change the search bar settings in most browsers to use encrypted.google.com.
If your concern is that you should be forced to the HTTPS site, even if you mistype or bookmark the wrong version, etc., then you could try the EFF's HTTPS-Everywhere extension (Firefox only. I'm told Chrome's extension framework is fundamentally incompatible right now).[2] If you've noticed a lot of comments have linked to, for example, Wikipedia using a "secure.wikimedia.org/wikipedia" type URL, this extension is very likely how they got that way.
Out of the box, there is no ruleset preconfigured in HTTPS-Everywhere for HN, but the top comment[3] on the HN SSL announcement/discovery post gives a rule for it to configure it to always force HN to SSL.
[1] - https://news.ycombinator.com/item?id=3126309
[1] - https://addons.mozilla.org/en-US/firefox/addon/https-finder/
I actually have HTTPS Everywhere, but it didn't find it for the reasons you mention.
If anyone at HN is reading, the certificate doesn't work if you visit via news.ycombinator.org (vs .com). It would probably be better to just make that a redirect to .com, rather than what appears to be an alias.
May be they are pushing Adwords channel by saying: "look you can arrange your campaigns in keyword level."
It's interesting to see this decision while they are improving Google Analytics very much lately. Maybe they will monetize by subscription model.
Now if they would please allow adsense ads on ssl served pages elsewhere it would actually make some sense.
Is that true? Most encryption schemes include compression (since compression removes redundancy, and redundancy is where cryptanalysts attack).
"Servers that are heavy on serving a fairly small set of static pages that can easily be cached in memory suffer from a much higher overhead... SSL handshaking is the major cost of HTTPS."
http://stackoverflow.com/questions/149274/http-vs-https-perf...
Currently my web site highlights keywords that user was searching for on Google. It will be impossible anymore for users who logged in to Google.
Is it possible to opt out from SSL search on Google?
Search keywords in these results are highlighted.
If your goal is to hide your intent from web sites you visit - you can just turn off URL Referrer in your browser.
Search result pages and destination pages serve completely different purposes, and you can't apply the same UI to both. If you ran a restaurant, you might decide to laminate the menus, but I hope you wouldn't laminate the entrees, too.
Highlighting "salmon" menu entries on web site could make sense for the user who is searching for "salmon", wouldn't it?
But let's be more specific: I run a job board (PostJobFree) and recruiters frequently find resumes on Goolge in queries like this:
http://www.google.com/search?q=intitle%3Aresume+sharepoint+C...
If you open first result - you can see how these keywords are highlighted. I'm pretty sure that this highlighting is a convenient feature for recruiters who want to quickly scan resume.
Curious: have you tested/surveyed user preference to having that feature or not?
Besides - there is no point testing it now, considering that Google slowly takes away that option.