HTTPS
Hypertext Transfer Protocol Secure
In short
HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
What is HTTPS?
HTTPS is regular HTTP sent through an encrypted connection created with TLS (Transport Layer Security), the successor to the older SSL protocol. It gives three guarantees: others on the network cannot read the data (confidentiality), the data cannot be changed in transit without detection (integrity), and the browser is talking to the real site rather than an impostor (authentication).
When a browser connects, it performs a TLS handshake. The server presents a certificate, a digital document signed by a trusted certificate authority (CA) that proves it controls the domain, and the two sides agree on encryption keys for the session. Free, automated certificates from authorities such as Let's Encrypt have made HTTPS the default for almost every website.
Plain HTTP is like sending a postcard that every mail carrier can read, while HTTPS is like a sealed, tamper-evident envelope delivered to a verified address. Browsers mark HTTP pages as not secure, and many modern features, such as service workers, geolocation, and Secure cookies, only work over HTTPS.
HTTPS protects data in transit, not the website itself: a site served over HTTPS can still have bugs like XSS or SQL injection, and the padlock icon does not mean a site is trustworthy. To use it well, redirect all HTTP traffic to HTTPS, enable HSTS (HTTP Strict Transport Security) so browsers never fall back to plain HTTP, and keep certificates and TLS settings up to date.
At a glance
Key takeaways
- HTTPS is HTTP encrypted with TLS.
- It provides confidentiality, integrity, and server authentication.
- Certificates from trusted authorities prove a site's identity.
- HSTS forces browsers to always use HTTPS for a site.
- HTTPS secures the connection, not the application's code.
Example
# Send all plain HTTP traffic to HTTPS
server {
listen 80;
server_name example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/ssl/example.com/fullchain.pem;
ssl_certificate_key /etc/ssl/example.com/privkey.pem;
# Tell browsers to use only HTTPS for this site for the next year
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
}Readers ask
What is the difference between HTTP and HTTPS?
HTTP sends data as plain text that anyone on the network path can read or modify. HTTPS wraps the same HTTP messages in TLS encryption and verifies the server's identity with a certificate.
Does the padlock mean a website is safe?
No. The padlock only means the connection is encrypted and the certificate matches the domain. Phishing and other malicious sites can use HTTPS too.
What is the difference between SSL and TLS?
SSL is the original protocol from the 1990s and is now obsolete and insecure. TLS replaced it, with TLS 1.2 and TLS 1.3 in use today, although many people still say SSL certificate out of habit.
Often compared
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- CookieWeb Development, p. 6A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
- CDNDevOps & Cloud, p. 7A CDN is a network of servers spread around the world that stores copies of website content and delivers it to each user from the nearest location.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
Sources
Spotted a mistake or something missing on this page?Suggest an edit