HTTPS
In depthProtocol / format
Also known as: HTTP Secure
The encrypted version of HTTP over TLS. Protects data in transit from eavesdropping.
HTTPS, explained
Written by EduVerseWhat it is
HTTPS is HTTP sent through an encrypted TLS connection. Before any data flows, the server proves its identity with a certificate from a trusted certificate authority, and both sides agree on encryption keys. In the browser you recognize it by an address that starts with https://.
Why teams use it
Plain HTTP is unencrypted, so anyone on the same café Wi-Fi or along the route could read passwords or alter pages. HTTPS stops both and confirms you’re talking to the real server. Browsers mark plain HTTP sites as “Not secure”, and features such as service workers and geolocation only work over HTTPS.
An example from work
You deploy your site over HTTPS, but a script doesn’t load and the console reports “Mixed Content”. One file is still linked with an http:// URL, and browsers block insecure scripts on a secure page. Change the URL to https:// and the warning disappears and the script runs.
Our own explanation, not a quote from the book.
Where it fits
Secure web communication (the default on the modern web)
Coverage in the book
Covered in depth: multiple pages with explanations, examples and simulations.