Greets.
Actually, though I am not privy to Google's specific algorithms, they actually do seem to favor HTTPS over HTTP, not quite as dramatically as they currently favor mobile, but along the same lines.
This is from 2015:
https://webmasters.googleblog.com/2015/12/indexing-https-pages-by-default.html
#------------------------------------
Indexing HTTPS pages by default
Thursday, December 17, 2015
At Google, user security has always been a top priority. Over the years, we’ve worked hard to promote a more secure web and to provide a better browsing experience for users.
Gmail,
Google search, and YouTube have had secure connections for some time, and we also started giving a slight
ranking boost to HTTPS URLs in search results last year. Browsing the web should be a private experience between the user and the website, and must not be subject to
eavesdropping,
man-in-the-middle attacks, or data modification. This is why we’ve been strongly promoting
HTTPS everywhere.
As a natural continuation of this, today we'd like to announce that we're adjusting our indexing system to look for more HTTPS pages. Specifically, we’ll start crawling HTTPS equivalents of HTTP pages, even when the former are not linked to from any page. When two URLs from the same domain appear to have the same content but are served over different protocol schemes, we’ll typically choose to index the HTTPS URL if:
- It doesn’t contain insecure dependencies.
- It isn’t blocked from crawling by robots.txt.
- It doesn’t redirect users to or through an insecure HTTP page.
- It doesn’t have a rel="canonical" link to the HTTP page.
- It doesn’t contain a noindex robots meta tag.
- It doesn’t have on-host outlinks to HTTP URLs.
- The sitemaps lists the HTTPS URL, or doesn’t list the HTTP version of the URL
- The server has a valid TLS certificate.
Although our systems prefer the HTTPS version by default, you can also make this clearer for other search engines by redirecting your HTTP site to your HTTPS version and by implementing the
HSTS header on your server.
We’re excited about taking another step forward in making the web more secure. By showing users HTTPS pages in our search results, we’re hoping to decrease the risk for users to browse a website over an insecure connection and making themselves vulnerable to content injection attacks. As usual, if you have any questions or comments, please let us know in the comments section below or in our
webmaster help forums.
Posted by
Zineb Ait Bahajji, WTA, and the Google Security and Indexing teams
#------------------------------------
This is from 2014:
https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html
#------------------------------------
HTTPS as a ranking signal
Wednesday, August 06, 2014
HTTPS as a ranking signal
Wednesday, August 06, 2014
Webmaster level: all
Security is a top priority for Google. We invest a lot in making sure that our services use industry-leading security, like
strong HTTPS encryption by default. That means that people using Search, Gmail and Google Drive, for example, automatically have a secure connection to Google.
Beyond our own stuff, we’re also working to make the Internet safer more broadly. A big part of that is making sure that websites people access from Google are secure. For instance, we have created resources to help webmasters
prevent and fix security breaches on their sites.
We want to go even further. At
Google I/O a few months ago, we called for “
HTTPS everywhere” on the web.
We’ve also seen more and more webmasters adopting
HTTPS (also known as HTTP over
TLS, or Transport Layer Security), on their website, which is encouraging.
For these reasons, over the past few months we’ve been running tests taking into account whether sites use secure, encrypted connections as a signal in our search ranking algorithms. We've seen positive results, so we're starting to use HTTPS as a ranking signal. For now it's only a very lightweight signal — affecting fewer than 1% of global queries, and carrying less weight than other signals such as
high-quality content — while we give webmasters time to switch to HTTPS. But over time, we may decide to strengthen it, because we’d like to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web.
In the coming weeks, we’ll publish detailed best practices (it's in our
help center now) to make TLS adoption easier, and to avoid common mistakes. Here are some basic tips to get started:
- Decide the kind of certificate you need: single, multi-domain, or wildcard certificate
- Use 2048-bit key certificates
- Use relative URLs for resources that reside on the same secure domain
- Use protocol relative URLs for all other domains
- Check out our Site move article for more guidelines on how to change your website’s address
- Don’t block your HTTPS site from crawling using robots.txt
- Allow indexing of your pages by search engines where possible. Avoid the noindex robots meta tag.
If your website is already serving on HTTPS, you can test its security level and configuration with the
Qualys Lab tool. If you are concerned about TLS and your site’s performance, have a look at
Is TLS fast yet?. And of course, if you have any questions or concerns, please feel free to post in our
Webmaster Help Forums.
We hope to see more websites using HTTPS in the future. Let’s all make the web more secure!
Posted by
Zineb Ait Bahajji and
Gary Illyes, Webmaster Trends Analysts
#------------------------------------
Then, Google's recommendations with regard to moving URL's:
https://support.google.com/webmasters/answer/6033049?hl=en&ref_topic=6033084
#------------------------------------
Move a site with URL changes
Overview: Site moves with URL changes
Make sure Google can index your content under your new URLs
This article describes how to change the URLs of existing pages on your site with minimal impact on your Google Search results. Examples of this kind of site move include:
- URL changes from HTTP to HTTPS
- Domain name changes such as example.com to example.net or merging multiple domains or hostnames
- URL paths changes: example.com/page.php?id=1 > example.com/widget, or example.com/page.html > example.com/page.htm
If you are making site changes without visible URL changes,
start here instead.
FAQs for all site moves with URL changes
- Should I move everything together, or is it fine to move in sections?
Moving in sections is fine.
- How can I test how many pages were indexed?
Verify data for each property separately in Search Console. Use the Index Status report for a broad look, or the sitemaps indexed count on the Sitemaps report for sitemap URLs.
- How long will it take for Google to recognize my URL changes?
There are no fixed crawl frequencies; it depends on the size of your site, and the speed of crawling that's possible. The move takes place on a per-URL basis.
- Do I lose credit for links when I redirect to new URLs?
No, 301 or 302 redirects do not cause a loss in PageRank.
Migrating from HTTP–>HTTPS
- Review the best practices for HTTPS.
- Be sure to add the HTTPS property to Search Console. Search Console treats HTTP and HTTPS separately; data for these properties is not shared in Search Console. So if you have pages in both protocols, you must have a separate Search Console property for each one.
- Here are additional FAQs for migrating pages from HTTP to HTTPS:
HTTP–>HTTPS migration FAQs
Will this migration affect my ranking?
As with all migrations, you may experience some ranking fluctuation during a migration. However, you should also review the best practices information for HTTPS pages to avoid HTTPS-specific pitfalls.
HTTPS sites receive a small ranking boost, but don't expect a visible change. Google uses HTTPS as a positive ranking signal. This signal is one amongst many others, and currently carries less weight than high-quality site content; you should not expect a major SEO advantage for moving to HTTPS in the short term. In the longer term, Google may increase the strength of the HTTPS boost.
Is it OK to move just some pages to HTTPS?
Yes, no problem! Start with a part, test it, then move more, as you like.
If you are migrating from HTTP to HTTPS in pieces, and you want to avoid early indexing of the staged URLs, we recommend using rel=canonical rather than redirects. If you use redirects, you won't be able to test the redirected pages.
Which certificate do I need?
For Google Search, any modern certificate that's accepted by modern browsers is acceptable.
Will I see search keywords for my HTTPS site?
This won't change with HTTPS; you can still see search queries in Search Console.
We reference our HTTP sitemaps in robots.txt. Should we update the robots.txt to include our new HTTPS sitemaps?
We recommend separate robots.txt files for HTTP and HTTPS, pointing to separate sitemap files for HTTP and HTTPS. We also recommend listing a specific URL in only one sitemap file.
Which sitemap should map the section in the HTTPS trial?
You can create a separate sitemap just for the updated section of your site. This will enable you to track indexing of the trial section more precisely. Be sure not to duplicate these URLs in any other sitemaps, though.
What URLs should our sitemaps list if we have redirects (from HTTP to HTTPS or the reverse)?
List all HTTP URLs in your HTTP sitemap, and all HTTPS URLs in your HTTPS sitemap, regardless of redirects when the user visits the page. Having pages listed in your sitemap regardless of redirects will help search engines discover the new URLs faster.
Are there any other specific things we need to add to the robots.txt for the HTTPS version?
No.
Should we support HSTS?
HSTS increases security, but adds complexity to your rollback strategy. See HTTPS best practices for more information.
We use a single Google News sitemap for our entire site. What do we do if we're migrating our site piece by piece?
If you want to use a Google News sitemap for the new HTTPS section, you will have to contact the News team to let them know about the protocol change, and then in your HTTPS property in Search Console you can submit a new Google News sitemap as you migrate each section of your site to HTTPS.
Are there any specific recommendations for Google News Publisher Center with HTTPS migration?
Google News Publisher Center handles the HTTP->HTTPS moves transparently. In general you don't have to do anything from Google News perspective, unless you're also making use of News sitemaps. In that case, please contact the News team and let them know about the change. You can also let the team know about changing sections, for example in case you're moving to HTTPS, you can specify that you're moving http://example.com/section to https://example.com/section .
Move your site
- Review basic information about site moves. Know what to expect, and how it might affect your users and rankings. If moving from HTTP to HTTPS, review the best practices for HTTPS.
- Prepare the new site and test it thoroughly.
- Prepare a URL mapping from the current URLs to their corresponding new format.
- Start the site move by configuring the server to redirect from the old URLs to the new ones.
- Monitor the traffic on both the old and new URLs.
#------------------------------------
So, the simple answer for you is to go ahead and redirect your unencrypted traffic, by default, to encrypted traffic.