# Why Websites Should Use HTTPS for Privacy and Security

DevFeed: [Why Websites Should Use HTTPS for Privacy and Security](<https://devfeed.tech/articles/if-your-site-isn-t-using-https-you-are-doing-it-wrong-24967.md>)

Original publisher: [Read original article](<https://codeahoy.com/2017/01/18/if-your-site-isnt-using-https-you-are-doing-it-wrong/>)

Author: umer

Published: 2017-01-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Code Ahoy - Articles](<https://devfeed.tech/sources/code-ahoy-articles.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Web](<https://devfeed.tech/topics/web.md>), [AWS Certificate Manager](<https://devfeed.tech/topics/aws-certificate-manager.md>), [Google](<https://devfeed.tech/topics/google.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Mozilla](<https://devfeed.tech/topics/mozilla.md>)

Tags: [aws-certificate-manager](<https://devfeed.tech/tags/aws-certificate-manager.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [google](<https://devfeed.tech/tags/google.md>), [http](<https://devfeed.tech/tags/http.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that websites should use HTTPS to reduce exposure of users' communications and protect privacy. It describes Google Chrome and Firefox warnings for some HTTP pages and notes that free HTTPS certificates are available through Let's Encrypt and AWS Certificate Manager.

## Source excerpt

We live in a day and age where we simply cannot take our right to privacy for granted. When we communicate over unprotected channels, we expose our messages to everyone who happens to be along the way: The WiFi hotspots, corporate IT providers, ISPs, cloud providers, can listen in to our communication. We leave a trail of digital footprints behind. When aggregated, it can reveal information about ourselves. Eavesdroppers and intruders can make inferences about our behaviors and intentions: ISPs can determine what types of news stories we are interested in, employers can monitor our activities even on personal devices at work, look at our searches, see our messages, all when we communicate over unprotected channels. Google has been urging site owners to switch to HTTPS for many years now. They started using HTTPS as a ranking indicator for their search results. To tighten the screws, Chrome, starting with version 56 that is coming soon, will start showing "not secure" alerts on sites that collect login or credit card information over HTTP. Firefox will also start displaying a red icon in the address bar as well as an in-context warning for pages that ask users to login over HTTP. While I don't know the real reason that compel Google to drive the HTTPS campaign, it's a great direction for the future of the web, a direction that we should all support. So how do you make your website secure? It's way easier to secure sites with HTTPS these days than it used to be. In the past, obtaining a digital certificate that is required for HTTPS required paperwork and hundreds of dollars. This is no longer the case. Let's Encrypt is a certificate authority that provides FREE certificates to anyone. It's backed by organizations such as Mozilla, Facebook and Google to name a few. Let's Encrypt makes it possible for anyone to have an HTTPS website for free. As an alternative, if you host your servers on the AWS, Certificate Manager provides free certificates and handle certificate re