HSTS On Google.com

Google Bringing HSTS To Google.com

Google announced bringing  HTTP Strict Transport Security (abbreviated as HSTS) to www.google.com. HSTS is a web security policy mechanism which allows a web server to enforce the use of HTTPS in a compliant User Agent (UA), such as a web browser. It lets a website tell web browsers that it should only be communicated with using HTTPS instead of using HTTP.

Although Google moved on HTTPS long before many well-known top sites such as Twitter, Facebook or Wikipedia, it is the last bringing HSTS to google.com among them. Besides, as announced on Google Blog, HSTS is brought for the moment only to www.google.com.

Below are Google's as well as some top sites dates of HTTPS migration.

Google      18/10/2011

Twitter       13/02/2012

Facebook  01/08/2013

Wikipedia  12/06/2015

Soon after Google's HSTS announcement, Youtube followed the same path and shared bringing HSTS to Youtube.

Youtube HSTS

A website server needs to return Strict-Transport-Security HTTP header in order to enable HSTS when the site is accessed over HTTPS. However no Strict-Transport-Security HTTP Header is returned from www.google.com when HTTP header of www.google.com is fetched although this header is returned from other top sites which are cited above.


A second way of checking this information is through Chrome.The Google Chrome browser offers a quick way to check a domain's HSTS status via chrome://net-internals/#hsts. Querying domain www.google.com on chrome://net-internals/#hsts gives the result below.

chrome hsts google.com

STRICT  as dynamic_upgrade_mode means that the browser has been instructed to enable HSTS by an HTTP response header.

Third way of verifying the information given by google about bringing HSTS to google.com is checking Chrome's HSTS preload list which is a list of sites that are hardcoded into Chrome as being HTTPS only. Most major browsers (Chrome, Firefox, Opera, Safari, IE 11 and Edge) also have HSTS preload lists based on the Chrome list.

A sample from this list is below.

Have comments, questions or feedback about this article? Please do share them with us here.

If you like this article

Follow Me on Twitter

Follow Searchdatalogy on Twitter

Related Tags: HTTPS  

Comments

About Us

Our objective is bringing all our experience and expertise together to deliver solid technology solutions that can take your search traffic acquisition to the next level. Our main goal is to assist you in building and maintaining your search marketing analytics platforms. Our will is to leverage your marketing and IT teams search knowledge while bridging the gap between two.

Legal Terms Privacy

Recent Posts

1 Million #SEO Tweets 9 months, 2 weeks ago
SEO, Six Blind Men & An Elephant 10 months, 2 weeks ago
SEO Hero 2017 11 months, 2 weeks ago
3 Ways For Free HTTPS 1 year, 1 month ago
Crawl Dictionary 1 year, 1 month ago
Bing Strikes 1 year, 2 months ago
HTTPS On Top Sites 1 year, 2 months ago
SEO Web Server Log Files 1 year, 3 months ago
SEO, Web Server Logs And Science 1 year, 3 months ago
HTTP2 On Top Sites 1 year, 3 months ago

Recent Tweets