Web encryption technology is 20 years old. So why isn't every site using it?
Secure Sockets Layer (SSL) has been around for 20 years, and it's been widely used for financial transactions since the 1990s. But back then, the technology was too slow to be practical to use on every website. But as the technology has improved and computers have gotten faster, that's been changing. Sites like Facebook and Twitter began using SSL in the last few years, and media organizations like the New York Times are currently working to adopt it. Advocates hope that SSL will become ubiquitous in the next few years. People usually think of SSL as a way to protect people's privacy. When you browse a website that's not protected by SSL over a Wi-Fi network, the information you upload and download can be intercepted by other people near you. SSL prevents this by scrambling the data before it's sent across the network.
Security researchers at Google point out another huge benefit of using SSL across the web: it helps fight cyberattacks. Webpages protected with SSL aren't just hard to intercept, they're also hard to modify, which means users won't be exposed to the risks of third parties tampering with the websites they visit. Google has started to apply significant pressure on website owners to upgrade to SSL. In 2014, the company announced it would start penalizing websites that don't adopt it by docking their search results. The penalty is small for now, but Google says it may increase it in the coming years. That creates an added incentive for webmasters to get on board, improving security for both their users and the web as a whole.