# HTTPS (Hypertext Transfer Protocol Secure)

URL: https://softwaredictionary.org/terms/https
Category: Security
Last updated: 2026-09-29

In short: HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.

## What is HTTPS?

HTTPS is regular HTTP sent through an encrypted connection created with TLS (Transport Layer Security), the successor to the older SSL protocol. It gives three guarantees: others on the network cannot read the data (confidentiality), the data cannot be changed in transit without detection (integrity), and the browser is talking to the real site rather than an impostor (authentication).

When a browser connects, it performs a TLS handshake. The server presents a certificate, a digital document signed by a trusted certificate authority (CA) that proves it controls the domain, and the two sides agree on encryption keys for the session. Free, automated certificates from authorities such as Let's Encrypt have made HTTPS the default for almost every website.

Plain HTTP is like sending a postcard that every mail carrier can read, while HTTPS is like a sealed, tamper-evident envelope delivered to a verified address. Browsers mark HTTP pages as not secure, and many modern features, such as service workers, geolocation, and `Secure` cookies, only work over HTTPS.

HTTPS protects data in transit, not the website itself: a site served over HTTPS can still have bugs like XSS or SQL injection, and the padlock icon does not mean a site is trustworthy. To use it well, redirect all HTTP traffic to HTTPS, enable HSTS (HTTP Strict Transport Security) so browsers never fall back to plain HTTP, and keep certificates and TLS settings up to date.

## Key takeaways

- HTTPS is HTTP encrypted with TLS.
- It provides confidentiality, integrity, and server authentication.
- Certificates from trusted authorities prove a site's identity.
- HSTS forces browsers to always use HTTPS for a site.
- HTTPS secures the connection, not the application's code.

## Example: Redirecting to HTTPS and enabling HSTS (nginx)

```nginx
# Send all plain HTTP traffic to HTTPS
server {
  listen 80;
  server_name example.com;
  return 301 https://$host$request_uri;
}

server {
  listen 443 ssl;
  server_name example.com;
  ssl_certificate     /etc/ssl/example.com/fullchain.pem;
  ssl_certificate_key /etc/ssl/example.com/privkey.pem;
  # Tell browsers to use only HTTPS for this site for the next year
  add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
}
```

## Frequently asked questions

**What is the difference between HTTP and HTTPS?**

HTTP sends data as plain text that anyone on the network path can read or modify. HTTPS wraps the same HTTP messages in TLS encryption and verifies the server's identity with a certificate.

**Does the padlock mean a website is safe?**

No. The padlock only means the connection is encrypted and the certificate matches the domain. Phishing and other malicious sites can use HTTPS too.

**What is the difference between SSL and TLS?**

SSL is the original protocol from the 1990s and is now obsolete and insecure. TLS replaced it, with TLS 1.2 and TLS 1.3 in use today, although many people still say SSL certificate out of habit.

## Sources

- [RFC 2818: HTTP Over TLS](https://www.rfc-editor.org/rfc/rfc2818.html)
- [RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3](https://www.rfc-editor.org/rfc/rfc8446.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
