Feeds

Google to enforce SSL encryption on developer APIs

September 15: HTTPS or nothing

Internet Security Threat Report 2014

Google will soon require the use of SSL encryption with three of its developer-facing APIs.

Beginning September 15, Google will require all developers to use SSL connections for all requests through its Google Documents List, Google Spreadsheet, and Google Sites APIs. In other words, these APIs will only accept requests via HTTPS. If you make a request to an old HTTP address, such as http://docs.google.com/feeds/default/private/full, it will no longer work. You must use https://docs.google.com/feeds/default/private/full.

If you're using the latest version of the Google Data Client libraries, Google says, you needn't change anything. Those libraries already use SSL across the board. If you're not using those libraries, you must change all HTTP URLs in your code to HTTPS.

Google is not requiring SSL on all its APIs, but it "strongly recommends" that you use such encryption with all your Google API clients. The company has started with the Document List, Spreadsheet, and Sites API because most traffic to these APIs is already encrypted with SSL.

Mountain View has led the web in the gradual migration to SSL encryption: Gmail now defaults to SSL, it's an option with Google web search, and Google Docs – the company's online word processor – requires SSL. But other big names, including Facebook, have followed suit.

With most Google APIs, SSL is used with technical documentation, client libraries, and code samples already use SSL. This week, the company also announced that the Google Maps API is now offering SSL to all developers. Previously, it only offered SSL to "Premier" customers. ®

Security for virtualized datacentres

More from The Register

next story
Microsoft WINDOWS 10: Seven ATE Nine. Or Eight did really
Windows NEIN skipped, tech preview due out on Wednesday
Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
Forget touchscreen millennials, Microsoft goes for mouse crowd
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.