How HTTPS Works

HTTPS (HyperText Transfer Protocol Secure) adds encryption to HTTP using TLS (Transport Layer Security). Every time you see the padlock icon in your browser, HTTPS is protecting your data in transit.

The TLS Handshake

When your browser connects to an HTTPS site, a "handshake" occurs:

  1. Client Hello: Your browser sends supported TLS versions and cipher suites
  2. Server Hello: The server responds with its chosen cipher suite and SSL certificate
  3. Certificate Verification: Your browser checks the certificate against trusted Certificate Authorities (CAs)
  4. Key Exchange: Both sides agree on a shared secret using asymmetric encryption (typically ECDHE)
  5. Secure Connection: All subsequent data is encrypted with the shared symmetric key (typically AES-256-GCM)

What TLS Protects Against

TLS 1.3 vs 1.2

TLS 1.3 (2018) reduced the handshake from 2 round-trips to 1, removed insecure cipher suites, and added 0-RTT resumption. All modern browsers and most servers now support TLS 1.3.

Free Certificates with Let's Encrypt

Since 2015, Let's Encrypt provides free, automated SSL certificates. There's no longer any reason for a website not to use HTTPS. Tools like Certbot make setup trivial.