HTTPS
In short: HTTP over a TLS-encrypted connection — the same communication as HTTP, but protected against eavesdropping and manipulation.
In more detail: Before the actual HTTP exchange, a TLS handshake takes place in which the server (and optionally the client) identifies itself with a certificate and a shared session key is negotiated. Recognisable by the padlock symbol in the browser and the https:// prefix. Standard for practically every website today.
In Depth
Procedure in two phases
Calling up an HTTPS page runs in two separate phases: first the TLS handshake (negotiating encryption and verifying identity), then the actual HTTP exchange — completely encrypted within the negotiated TLS channel:
1. Client connects to the server on port 443
2. TLS handshake: server shows its certificate, both negotiate a session key
3. Only now: normal HTTP request/response, but completely encrypted
The certificate’s dual role
The server certificate fulfils two tasks at the same time: it provides the public key for encryption, AND it proves (signed by a trusted certification authority, a so-called certificate authority) that the server really is who it claims to be — without this identity check, an attacker could insert themselves between the client and the real server and still communicate in encrypted form without it being noticed (man-in-the-middle attack). If the certificate expires, doesn’t come from a trusted authority, or the domain name entered in the certificate doesn’t match the URL called, the browser warns clearly with a full-page warning instead of silently allowing the connection.
Integrity in addition to encryption
Besides pure encryption, HTTPS also brings integrity protection — every transmitted message carries cryptographic proof that it wasn’t altered in transit. Even if an attacker wanted to intercept and manipulate the encrypted data stream (even without being able to decrypt the content), the manipulation would be detected by the receiving end and the connection aborted immediately, instead of manipulated data being processed silently.
Perfect forward secrecy
Modern TLS versions (from TLS 1.2, mandatory in TLS 1.3) additionally use so-called “perfect forward secrecy”: the session key for each individual connection is freshly negotiated and not stored permanently anywhere — even if an attacker steals the server’s private key years later, they can’t use it to decrypt past, recorded connections afterwards, because the session keys needed for that have long been discarded.
HTTPS as the de facto standard
Search engines now also actively favour HTTPS pages in their rankings, and modern browsers explicitly mark pure HTTP pages as “not secure” in the address bar — HTTPS has thus effectively become the mandatory standard for practically every public website. Free certificate authorities such as Let’s Encrypt have also completely removed the former financial hurdle (certificates used to cost several hundred euros a year).
See also: HTTP, TLS, Certificate, Handshake, Session key