HTTPS

HTTP carried over TLS, protecting web traffic's confidentiality and integrity in transit and authenticating the server by certificate; it does not prove the site itself is trustworthy.

HTTPS is the Hypertext Transfer Protocol run inside a TLS session, first described in RFC 2818 and now defined as the “https” scheme in RFC 9110. The browser and server complete a TLS handshake, commonly on well-known port 443, before any HTTP request is sent. The browser checks the server’s certificate against a trusted certificate authority in the public key infrastructure, and the session is then encrypted and integrity-protected. Its predecessor SSL is deprecated.

What HTTPS proves is narrower than users often assume. It shows that the connection is protected and that the server holds a certificate for the name in the address bar. It does not show that the organisation behind the name is honest: phishing sites, including those using a homograph attack, commonly obtain valid certificates. HTTP Strict Transport Security (HSTS, RFC 6797) tells browsers to use only HTTPS for a site, which helps counter an attacker in the path who tries to downgrade the connection to plain HTTP during a man-in-the-middle attack. Certificate pinning narrows which certificates a client will accept.

Exam relevance: a scenario is likely to test what HTTPS does and does not guarantee. Protection of web traffic in transit points to HTTPS; an option suggesting that the padlock proves a site is legitimate is a common trap.