Hsts on google.com

Is really Google.com on HSTS ?

Google announced bringing  HTTP Strict Transport Security (abbreviated as HSTS) to www.google.com. HSTS is a web security policy mechanism which allows a web server to enforce the use of HTTPS in a compliant User Agent (UA), such as a web browser. It lets a website tell web browsers that it should only be communicated with using HTTPS instead of using HTTP.

Although Google moved on HTTPS long before many well-known top sites such as Twitter, Facebook or Wikipedia, it is the last bringing HSTS to google.com among them. Besides, as announced on Google Blog, HSTS is brought for the moment only to www.google.com.

Below are Google's as well as some top sites dates of HTTPS migration.

Google      18/10/2011

Twitter       13/02/2012

Facebook  01/08/2013

Wikipedia  12/06/2015

Soon after Google's HSTS announcement, Youtube followed the same path and shared bringing HSTS to Youtube.

Youtube HSTS

A website server needs to return Strict-Transport-Security HTTP header in order to enable HSTS when the site is accessed over HTTPS. However no Strict-Transport-Security HTTP Header is returned from www.google.com when HTTP header of www.google.com is fetched although this header is returned from other top sites which are cited above.


A second way of checking this information is through Chrome.The Google Chrome browser offers a quick way to check a domain's HSTS status via chrome://net-internals/#hsts. Querying domain www.google.com on chrome://net-internals/#hsts gives the result below.

chrome hsts google.com

STRICT  as dynamic_upgrade_mode means that the browser has been instructed to enable HSTS by an HTTP response header.

Third way of verifying the information given by google about bringing HSTS to google.com is checking Chrome's HSTS preload list which is a list of sites that are hardcoded into Chrome as being HTTPS only. Most major browsers (Chrome, Firefox, Opera, Safari, IE 11 and Edge) also have HSTS preload lists based on the Chrome list.

A sample from this list is below.

Thanks for taking time to read this post. I offer consulting, architecture and hands-on development services in web/digital to clients in Europe & North America. If you'd like to discuss how my offerings can help your business please contact me via LinkedIn

Have comments, questions or feedback about this article? Please do share them with us here.

If you like this article

Follow Me on Twitter

Follow Searchdatalogy on Twitter

Related Tags: HTTPS  

Comments

Legal Terms Privacy

Data SEO

Gael Gegourel: Data Engineer SEO

Hamlet Batista: CEO Ranksense

Walid Gabteni: Consultant SEO

Vincent Terrasi: Data Scientist SEO

Remi Bacha: Data Scientist SEO

Recent Posts

87 million domains pagerank 1 year, 8 months ago
SEO data forecasting 1 year, 9 months ago
SEO data analysis 1 year, 9 months ago
BrightonSEO conference 1 year, 10 months ago
HTTP2 on top sites 2 years, 1 month ago
Desktop & mobile performances 2 years, 5 months ago
Alexa top 1 million sites 2 years, 6 months ago
1 million #SEO tweets 3 years, 6 months ago
SEO, six blind men & an elephant 3 years, 7 months ago
Technical SEO log analysis 3 years, 8 months ago
3 ways for free https 3 years, 9 months ago
Crawl dictionary 3 years, 10 months ago
Https on top sites 3 years, 11 months ago
SEO web server log files 3 years, 11 months ago
Hsts on google.com 4 years ago

Recent Tweets