Skip to main content
Book 07 · SecurityPage 17 of 50

HTTPS

Hypertext Transfer Protocol Secure

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/https

In short

HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.

What is HTTPS?

HTTPS is regular HTTP sent through an encrypted connection created with TLS (Transport Layer Security), the successor to the older SSL protocol. It gives three guarantees: others on the network cannot read the data (confidentiality), the data cannot be changed in transit without detection (integrity), and the browser is talking to the real site rather than an impostor (authentication).

When a browser connects, it performs a TLS handshake. The server presents a certificate, a digital document signed by a trusted certificate authority (CA) that proves it controls the domain, and the two sides agree on encryption keys for the session. Free, automated certificates from authorities such as Let's Encrypt have made HTTPS the default for almost every website.

Plain HTTP is like sending a postcard that every mail carrier can read, while HTTPS is like a sealed, tamper-evident envelope delivered to a verified address. Browsers mark HTTP pages as not secure, and many modern features, such as service workers, geolocation, and Secure cookies, only work over HTTPS.

HTTPS protects data in transit, not the website itself: a site served over HTTPS can still have bugs like XSS or SQL injection, and the padlock icon does not mean a site is trustworthy. To use it well, redirect all HTTP traffic to HTTPS, enable HSTS (HTTP Strict Transport Security) so browsers never fall back to plain HTTP, and keep certificates and TLS settings up to date.

At a glance

Over HTTP, anyone on the network between the browser and the server can read and change a request, password included; over HTTPS the same request travels inside a TLS-encrypted connection, so they see only scrambled bytes.HTTPPOST /login password=hunter2anyone on the network can read and change itBrowserServerHTTPS8f2c e91a 03bd 7c44 …TLS: unreadable, and any change is detectedBrowserServercertificate ✓
The server's certificate proves it is the real site, and any change on the way is detected. HTTPS protects the trip, not the site's own code.

Key takeaways

  • HTTPS is HTTP encrypted with TLS.
  • It provides confidentiality, integrity, and server authentication.
  • Certificates from trusted authorities prove a site's identity.
  • HSTS forces browsers to always use HTTPS for a site.
  • HTTPS secures the connection, not the application's code.

Example

Redirecting to HTTPS and enabling HSTS (nginx)nginx
# Send all plain HTTP traffic to HTTPS
server {
  listen 80;
  server_name example.com;
  return 301 https://$host$request_uri;
}

server {
  listen 443 ssl;
  server_name example.com;
  ssl_certificate     /etc/ssl/example.com/fullchain.pem;
  ssl_certificate_key /etc/ssl/example.com/privkey.pem;
  # Tell browsers to use only HTTPS for this site for the next year
  add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
}

Readers ask

What is the difference between HTTP and HTTPS?

HTTP sends data as plain text that anyone on the network path can read or modify. HTTPS wraps the same HTTP messages in TLS encryption and verifies the server's identity with a certificate.

Does the padlock mean a website is safe?

No. The padlock only means the connection is encrypted and the certificate matches the domain. Phishing and other malicious sites can use HTTPS too.

What is the difference between SSL and TLS?

SSL is the original protocol from the 1990s and is now obsolete and insecure. TLS replaced it, with TLS 1.2 and TLS 1.3 in use today, although many people still say SSL certificate out of habit.

Often compared

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings