EFF: Half of web traffic is now encrypted
Half of the web's traffic is now encrypted, according to a new report from the EFF released this week. The rights organization noted the milestone was attributable to a number of efforts, including recent moves from major tech companies to implement HTTPS on their own properties.
Context & Ripple Effects
The EFF's half-encrypted milestone is the payoff to a multi-year push the related coverage traces step by step: Google reported 75% of requests to its non-YouTube sites were already encrypted a year earlier, and committed in 2015 to encrypting the vast majority of ads on its platforms. The missing piece for everyone else was cost and friction, which the EFF attacked directly by putting its free certificate authority Let's Encrypt into public beta in late 2015.
What changed with this report is that encryption stopped being a differentiator for big platforms and became the web's median state — measured across all traffic, not just one company's properties.
First-order effects
- Sites still on plain HTTP now fall below the web's baseline, making the unencrypted connection itself a visible signal to visitors rather than an invisible default.
Second-order effects
- Free automated certificates from Let's Encrypt collapse the price argument against HTTPS, pressuring paid certificate authorities to compete on automation and validation features instead of the certificate itself.
Third-order effects
- With half of traffic encrypted and Google's own properties already at 75%, network intermediaries and advertisers progressively lose plaintext visibility into browsing, shifting the industry debate from whether to encrypt toward where measurement and filtering can legitimately happen above the encryption layer.
The trend: Web encryption is crossing from opt-in feature to assumed default, driven by platform self-interest and free certificate infrastructure rather than regulation.