Google’s Deadline for SSL Certificates Is Approaching

Over the course of the last two years, rumors have swirled over Google’s position concerning forcing the move to HTTPS encryption.  Last year, Google began officially warning website owners that non HTTPS sites would incur consumer messaging that identified the site as non-secure.

n February 8th, Google made clear its intentions to formally mark websites lacking SSL Certificates (the certificate which once installed on the website results in an HTTPS secure URL string) as insecure.

Google has confirmed a date of “early July 2018” as the start date. They have also disclosed how they will alert web surfers of the non-HTTPS status, or not secure.

Sites that remain on the HTTP non-secure protocol will be flagged with a warning in the URL bar of the surfer’s browser.

The non-secure flag will be built into the release of Chrome 68, which will be ready for download in early July.  It is possible that the flag could stand out by use of the color red.  However, that remains an unconfirmed aspect. Officially, the image above represents Google’s current likely change.

Google followed up this by stating that the web’s transition to HTTPS, which is also identified as “making the web safer,” by disclosing numbers supporting HTTPS growth and scale.

” Over 68% of Chrome traffic on both Android and Windows is now protected
” Over 78% of Chrome traffic on both Chrome OS and Mac is now protected
” 81 of the top 100 sites on the web use HTTPS by default

HTTPS encryption growth shows that most site owners are taking Google’s warnings seriously.

However, it remains that a large group of site owners has been less than motivated to make the change.

This adaptive lag is likely a result of confusion over what HTTPS encryption is, the annual cost associated with HTTPS encryption maintenance, and general laziness.

Google does not provide SSL certificates, but luckily, we do.   If you need assistance with setting up your SSL feel free to contact us today!

READ MORE

Three Common WordPress Vulnerabilities

WordPress is now one of the biggest blogging platforms and it’s important to keep your website safe. Respire Digital takes the security of your sites very seriously and make every effort to keep our clients aware of any potential security issues. Here are three common WordPress vulnerabilities & how to fix them.

1. Plugin Vulnerabilities

Plugins often have glitches that make your website vulnerable to hackers. To help prevent this, keep on top of updating your plugins.

If you’re a client of ours, we have processes in place to take care of this for you. If there’s ever a plugin with a possible threat in the update we automatically revert it to the old version until the update is patched. To check to see if any of the plugins you are using have any potential threats, click here.

2. Default Admin User Account/Default Passwords

Is your login to the website the default username and password that came with WordPress when you installed it? I would change it as soon as possible.

We purposely change the username to be more complex & we use a 13+ character password that is unique for each of our clients’ websites. When we give our clients access to the website, we also recommend that they change their passwords to a secure password after their first sign-in. If you struggle with remembering passwords, try using a secure password bank such as LastPass.

3. Vulnerable Hosting Servers

Since the server where your WordPress website resides is a target for attackers, using low-quality hosting services can make your site more vulnerable to being compromised. While all hosts take precautions to secure their servers, not all hosting providers are as vigilant or implement the latest security measures to protect websites on the server-level.

Respire Digital frequently run scans of our servers to ensure that our client sites are safe. If there’s a possible threat we are immediately alerted by the scan & take action to ensure that the sites are not affected.

Do you have any questions regarding your website’s safety? Contact Us Today!

READ MORE