Hsts on google.com

Is really Google.com on HSTS ?

Google announced bringing  HTTP Strict Transport Security (abbreviated as HSTS) to www.google.com. HSTS is a web security policy mechanism which allows a web server to enforce the use of HTTPS in a compliant User Agent (UA), such as a web browser. It lets a website tell web browsers that it should only be communicated with using HTTPS instead of using HTTP.

Although Google moved on HTTPS long before many well-known top sites such as Twitter, Facebook or Wikipedia, it is the last bringing HSTS to google.com among them. Besides, as announced on Google Blog, HSTS is brought for the moment only to www.google.com.

Below are Google's as well as some top sites dates of HTTPS migration.

Google      18/10/2011

Twitter       13/02/2012

Facebook  01/08/2013

Wikipedia  12/06/2015

Soon after Google's HSTS announcement, Youtube followed the same path and shared bringing HSTS to Youtube.

Youtube HSTS

A website server needs to return Strict-Transport-Security HTTP header in order to enable HSTS when the site is accessed over HTTPS. However no Strict-Transport-Security HTTP Header is returned from www.google.com when HTTP header of www.google.com is fetched although this header is returned from other top sites which are cited above.


A second way of checking this information is through Chrome.The Google Chrome browser offers a quick way to check a domain's HSTS status via chrome://net-internals/#hsts. Querying domain www.google.com on chrome://net-internals/#hsts gives the result below.

chrome hsts google.com

STRICT  as dynamic_upgrade_mode means that the browser has been instructed to enable HSTS by an HTTP response header.

Third way of verifying the information given by google about bringing HSTS to google.com is checking Chrome's HSTS preload list which is a list of sites that are hardcoded into Chrome as being HTTPS only. Most major browsers (Chrome, Firefox, Opera, Safari, IE 11 and Edge) also have HSTS preload lists based on the Chrome list.

A sample from this list is below.

Thanks for taking time to read this post. I offer consulting, architecture and hands-on development services in web/digital to clients in Europe & North America. If you'd like to discuss how my offerings can help your business please contact me via LinkedIn

Have comments, questions or feedback about this article? Please do share them with us here.

If you like this article

Follow Me on Twitter

Follow Searchdatalogy on Twitter

Related Tags: HTTPS  

Comments

About Us

My objective is bringing all my experience and expertise together to deliver solid technology solutions that can take your search traffic acquisition to the next level. My main goal is to assist you in building and maintaining your search marketing analytics platforms. My will is to leverage your marketing and IT teams search knowledge while bridging the gap between two.

Certificates

Botify: Botify Certified Consultant

IBM: Data Scientist, Data Engineering Certificates

Google: Google Analytics, Google Adwords, Mobile Sites, Digital Sales Certificated Professional

Coursera: Data Engineering on Google Cloud Platform Specialization

Legal Terms Privacy

Recent Posts

87 million domains pagerank 2 weeks, 4 days ago
SEO data forecasting 1 month, 3 weeks ago
SEO data analysis 1 month, 3 weeks ago
BrightonSEO conference 2 months, 2 weeks ago
HTTP2 on top sites 5 months, 1 week ago
Desktop & mobile performances 9 months, 3 weeks ago
Alexa top 1 million sites 10 months, 1 week ago
Web marketing festival 1 year, 5 months ago
Webcampday 1 year, 6 months ago
Queduweb 1 year, 7 months ago
SEOCamp'us 1 year, 9 months ago
1 million #SEO tweets 1 year, 10 months ago
SEO, six blind men & an elephant 1 year, 11 months ago
SEO hero 2017 2 years ago
Digitalzone 2 years ago

Recent Tweets