Follow Naijacrux on twitter .follow us on Twitter www.twitter.com/naijacruxonline, or @naijacruxonline or search for naijacruxonline on twitter!!Like us on facebook .Like us at www.facebook.com/Naijacruxforum.Click Here To Last longer In Bed[Stay amused>>>Don’t be a one minute Foul]>>> Love need Tips-See how Here


Author Topic: Google security team Adds HSTS Support to Google.com Search Engine  (Read 1176 times)

0 Members and 1 Guest are viewing this topic.

Offline mastercode

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 2924
  • Karma: +0/-0
Loading...

Google security team announced that they have finished implementing HSTS support for the company's main product, its vaunted search engine.
The move comes after months of testing to make sure the feature covered all the places where the search engine was featured, including APIs, not just the main website.

HSTS stands for HTTP Strict Transport Security and is a Web security protocol supported by all of today's browsers and Web servers.

HSTS protects HTTPS against several SSL attacks
The technology allows webmasters protect their service, and their users, against HTTPS downgrades, man-in-the-middle attacks, and cookie hijacking for HTTPS connections.

The protocol prevents users from going back to an HTTP connection when accessing Google over HTTPS, and forcibly redirects users to HTTPS connections as much as possible.

The technology is widely regarded as the best way to protect HTTPS connections against the most common attacks on SSL but has not been widely adopted.

95% of HTTPS websites still don't use HSTS
A study from Netcraft conducted last March showed that 95% of all servers running HTTPS either fail to set up HSTS or come with configuration errors. As such, Google's team has spent a great amount of time testing.

"Ordinarily, implementing HSTS is a relatively basic process," Google's Jay Brown, Sr. Technical Program Manager explained Friday. "However, due to Google's particular complexities, we needed to do some extra prep work that most other domains wouldn't have needed to do. For example, we had to address mixed content, bad HREFs, redirects to HTTP, and other issues like updating legacy services which could cause problems for users as they try to access our core domain."

During HSTS tests, Brown says that the team managed to break Google's famous Santa Tracker last December. The problem was fixed, but this only comes to show the wide spectrum of products the engineers had to ensure were working properly after HSTS deployment.




 

 

Microsoft Update Bing for Search with major features

Started by bellanaija

Replies: 0
Views: 9741
Last post August 08, 2018, 02:46:06 AM
by bellanaija
Mozilla Firefox Adds a New Sidebar for Viewing Synced Tabs

Started by internet police

Replies: 0
Views: 1196
Last post February 08, 2016, 10:08:52 AM
by internet police
Google's parent company 'Alphabet' Becomes Most Valuable Company in the World

Started by mastercode

Replies: 0
Views: 1491
Last post February 02, 2016, 01:55:21 PM
by mastercode
Google to unveil enhanced Android desktop mode for Android 15

Started by gurusforum

Replies: 0
Views: 5681
Last post April 08, 2024, 09:01:25 AM
by gurusforum
Google Maps Updated With WiFi Only Mode and Offline Maps to SD Cards Features

Started by yungcrux

Replies: 0
Views: 1700
Last post August 10, 2016, 07:07:46 AM
by yungcrux