It's HTTPS day

Peter Bowen

Free Member
Jul 2, 2007
857
229
55
Isle of Wight
The latest version of Google Chrome (the world's most popular web browser) warns visitors to your website that it's insecure if you're not using HTTPS.

Here's how you check if it has been enabled for your site.

  1. Go to your website's home page.
  2. Copy the URL from the browser address bar.
  3. Paste it anywhere that will let you change it - Word will do.
  4. If the URL starts with HTTPS you’re in the clear, no further action required. Otherwise change the HTTP part of the address to HTTPS and paste it into the address bar of your web browser.
  5. Reload the page. If your site doesn't load right away, or if you see warnings then your site doesn't work on HTTPS.
You need to install a SSL certificate on your web server to make HTTPS work. A certificate costs anything from free to several hundred dollars a year. The installation process ranges in complexity from one-click-and-you're-done to gouge-your-eyes-out-in-frustration - depending on who hosts your site.

Late last year I had to install a couple of hundred certificates for the specialist lead generation sites my business runs for our clients. I was expecting three weeks of manual, error-prone work. It turns out that it was (mostly) a walk in the park thanks to a service called Let's Encrypt who offer free certificates with programatic install.
 
Yes, In current Situation, SSL is very important, You can understand by following points.

The Requirements by Google:

This service is essential because of Google with flag any site that doesn’t load with a secure HTTPS as well as it will negatively impact your search engine rankings. As we know that Google is the prime and primary search engine used worldwide, therefore, it is essential that your website complies with the Google standards. Our WordPress Security Professional will make sure that your site complies with all the terms and conditions put forward by Google. This will not only help you to be in the good books as per google standards but will also enhance your google search rankings.

Website security setup:
The procedure carried out by our WordPress Security professional is highly thorough and detailed. It covers all the aspects of security and makes sure your site loads with a secure and encrypted HTTPS. We will make sure to find all the loopholes in the security standards and eliminate them. We will build a robust security wall around your website to prevent it from any future online attacks.

For any support related SSL contact WDE

Like how you advertise your service for WordPress Security professional.

Do you mean you will install Free SSL using the web hosting provider's Let's Encrypt plugin available within cPanel like what we offer? The end user can install that within seconds themselves. Don't need to be a WordPress security professional to do that.

As for protect against attacks, you mean to have something like Imunify360 stop all the attacks automatically. That's why we offer that to our customer's too because that way they don't have to mess about manually installing resource heavy WordPress plugins like WordFence which use up the customer's resources rather than the provider's resources. When a provider uses things like Imunify360 the resources are not used by the customer like it would if a WordPress security plugin would when being used.

Hope that helps.
 
Upvote 0
Companies not offering or making it rather difficult to use free SSLs are simply protecting their own revenue streams rather than supporting/protecting internet use as a whole.

I've heard of 'issues' with the auto-renewal of LetsEncrypt certificates with some providers and their solution is to buy one of their 'discounted' 2 year SSL certificates!

Talk with your feet and move to someone who cares.
 
Upvote 0
As for protect against attacks, you mean to have something like Imunify360 stop all the attacks automatically. That's why we offer that to our customer's too because that way they don't have to mess about manually installing resource heavy WordPress plugins like WordFence which use up the customer's resources rather than the provider's resources. When a provider uses things like Imunify360 the resources are not used by the customer like it would if a WordPress security plugin would when being used.

All our sites use both wordfence and have Imunify360 on the server, are you saying as a host you think that the latter offers enough protection alone? On a daily basis wordfence blocks attack attempts and flooding on logins etc, correct me if I'm wrong but Imunify360 does not seem to offer that kind of protection.
 
Upvote 0
All our sites use both wordfence and have Imunify360 on the server, are you saying as a host you think that the latter offers enough protection alone? On a daily basis wordfence blocks attack attempts and flooding on logins etc, correct me if I'm wrong but Imunify360 does not seem to offer that kind of protection.

Quite similar to the rule of not using more than one virus/firewall security software on PC as they can conflict with each other. Sure, if you want to potentially have conflicting security software trying to block the same thing or block it but in a different way or you want to increase the chances of blocking something that Imunify360 might miss (unlikely, a lot of data is gathered from thousands of servers very often, so you would think such data would be much better than a plugin that is not updated automatically in real-time) then you may keep your current setup.

I would say if you don't experience any issues with Imunify360 alone then all is good. Only install custom security plugins if you think Imunify360 is not up to the job. I think it is up to the job. It seems to be working great for over a year or so now and is far more advanced than a WordPress plugin.

Using custom plugins will just use more of your accounts' resources and may make your website load slower because of it.

You may read more about Imunify360 on their website.
 
Upvote 0
But that does not really address the wordpress user specific logging and access issues with wordpress. For example the weakest point in an IT system is normally the people, if a user has their admin password compromised an a login from outside the UK comes into one of our wordpress sites wordfence will email me and it can be investigated. If someone tries to brute force a wordpress login, again it will be picked up by WF and action taken.

I use 360 and think its a good tool, and would love to be proved wrong on this as its less software to run, but I don't think its own it provides enough protection. I also have not seen a slowdown in our sites using it, so wonder if you have any stats on these.
 
Upvote 0
if a user has their admin password compromised an a login from outside the UK comes into one of our wordpress sites wordfence will email me and it can be investigated.

If the password is compromised and password is known then account could be accessed whether using Imunify360 or WordFence, right? Of course, if you want to only allow connection from a certain country then that is something custom. You could not do that with Imunify360, at least not yet. But the password should not be compromised in the first place. The root caused needs to be fixed rather than relying on WordFence. There could be false positives with both scenarios too.

But note that Imunify360 now also has Proactive Defense which pretty much does what WordFence does too. Imunify360 has a large database of bad activity updated in real-time. Does not get better than that really.

If someone tries to brute force a wordpress login, again it will be picked up by WF and action taken.

The same thing is done with Imunify360, not sure what you mean by that? If an attack is detected it is blocked by Imunify360 WAF.
 
Upvote 0
If the password is compromised and password is known then account could be accessed whether using Imunify360 or WordFence, right? Of course, if you want to only allow connection from a certain country then that is something custom. You could not do that with Imunify360, at least not yet. But the password should not be compromised in the first place. The root caused needs to be fixed rather than relying on WordFence. There could be false positives with both scenarios too.

But note that Imunify360 now also has Proactive Defense which pretty much does what WordFence does too. Imunify360 has a large database of bad activity updated in real-time. Does not get better than that really.

Yes I'm not denying it would still result in access and false positives, all I'm saying it that I do not know a way in 360 of being notified when unusual wordpress logins occur and it does happen from time to time and thankfully via WF we can jump on it before an issue happens. Will look at proactive defence and see if that covers enough of what we do to do away with WF
 
  • Like
Reactions: HostXNow
Upvote 0
Aside from some web browsers like Google Chrome and Firefox have marked a non-ssl(HTTP) site as insecure, which can be seen from the browsers left side of top navigation bar, an ssl cert has been marked as a ranking signal by Google since 2014, namely it now has a direct impact on the ranking of your sites in the SERP.
 
Upvote 0
Imunify360, Lets encrypt, HTTPS, VPN’s they all sound very impressive and protect us from the dark unknown bogey man.
But no one knows exactly who’s behind all these ‘nice’ organisations.

Next time you go on holiday give me your house keys and I’ll look after it..... cos I’m a ‘nice’ man.
 
Upvote 0

Latest Articles