TLS at a glance
Key idea
HTTPS is HTTP sent inside a TLS connection. TLS does three jobs: it keeps the request and response private, detects any tampering on the way, and proves you reached a server that holds a certificate for the name you asked for.
Plain HTTP travels as readable text. Anyone on the path, such as the café Wi-Fi, your internet provider or a compromised router, can read it and change it. TLS closes that gap before the first HTTP byte is sent.
How the connection starts
How HTTPS starts: the TLS handshake
- 1Browser app.example.com Hello: app.example.com, TLS 1.3, my key share
Step 1 of 5
The browser names the site it wants (so one server can host many names), lists the TLS versions and ciphers it supports, and sends its half of a key exchange.
With TLS 1.3 the handshake costs one round trip on top of connecting. Browsers use port 443 for HTTPS, where plain HTTP uses port 80.
What TLS protects
Once the handshake finishes, everything inside the connection is encrypted:
- the path and query string (
/orders?id=42); - every header, including cookies and
Authorizationtokens; - the body: form fields, passwords, JSON, files.
Encryption comes with a check: if anyone alters a single byte in transit, the other side notices and drops the connection. That's why logins, API keys and session cookies should only ever travel over HTTPS.
What it doesn't protect
- Which site you visit. The DNS lookup, the server's IP address and, usually, the name in the browser's hello are visible to the network. The page you open on it isn't.
- Whether the site is honest. A certificate proves who controls a name, not that they're trustworthy. Phishing sites get valid certificates too.
- Data at either end. TLS covers the trip. Once the server has your data, its security is the server's job; on your device, malware sees what you see.
Why the name in the hello is visible
One server address can host many sites, so the browser names the site it wants in its first message, before any keys exist. That field is called SNI. A newer extension, Encrypted Client Hello, hides it, but only where both the browser and the server support it.
Check yourself