Theory
The S that matters
Look at your browser's address bar and you will see websites begin with https://. Occasionally you may still see plain http://. That single letter S, for Secure, marks one of the most important distinctions in everyday networking.
Both HTTP and HTTPS transfer web pages, they are the language browsers and servers speak. The difference is whether the conversation is readable by anyone who intercepts it, or encrypted and safe. This lesson explains that difference and why it matters for every login and payment you make.
Theory
HTTP: the web's transfer protocol
HTTP (HyperText Transfer Protocol) is the application-layer protocol that moves web pages between your browser and a web server: your browser requests a page, the server responds with it.
HTTP has one serious weakness for sensitive data: it sends everything in plaintext, unencrypted. That means anyone who can intercept the traffic along the way, on a shared Wi-Fi network, say, can read it: the pages, and worse, anything you type, such as a password or card number. HTTP is fine for ordinary public content, but dangerous for private information. Its default port is 80.
Theory
HTTPS: HTTP made secure
HTTPS (HTTP Secure) is the same HTTP, but running over SSL/TLS encryption. Before any web data flows, the browser and server set up an encrypted channel, so everything sent is scrambled in transit. An eavesdropper sees only unreadable ciphertext, not your password.
HTTPS does two things: it encrypts the data (so it cannot be read or tampered with on the way), and it verifies the server's identity using a certificate (so you know you are really talking to your bank, not an impostor). Browsers show a padlock for HTTPS, and its default port is 443. This is why sensitive sites always use HTTPS.
At a glance
| Aspect | HTTP | HTTPS |
|---|---|---|
| Security | Plaintext, readable if intercepted | Encrypted with SSL/TLS, unreadable to eavesdroppers |
| Identity | Server not verified | Server verified by a certificate |
| Default port | 80 | 443 |
| Browser sign | Often marked 'Not secure' | Padlock icon |
| Use for | Ordinary public content | Logins, payments, any sensitive data |
Quiz
You are entering your password and card details on a website. Which protocol should the site use, and why?
- HTTP, because it is faster without encryption
- HTTPS, because it encrypts the data with SSL/TLS so eavesdroppers cannot read your password or card number
- Either one; they are equally secure
- HTTP, because the padlock is only decorative
Show the answer
HTTPS, because it encrypts the data with SSL/TLS so eavesdroppers cannot read your password or card number
HTTPS is essential here: it encrypts the connection with SSL/TLS, so your password and card details travel scrambled and cannot be read or altered by anyone intercepting the traffic, and it verifies the server's identity. Option A is dangerously wrong: HTTP sends everything in plaintext, so on a shared or hostile network your credentials could be read outright; a small speed saving is no reason to expose sensitive data. Option C is false: HTTP and HTTPS are NOT equally secure, that is the entire point of the distinction. Option D is wrong: the padlock is not decorative; it signals a genuinely encrypted, identity-verified HTTPS connection. For anything sensitive, always insist on HTTPS.
Think first
How does HTTPS actually protect your password on public Wi-Fi?
On shared cafe Wi-Fi, others might intercept your traffic. How does HTTPS keep your password safe even then? Then tap.
Show the answer
By ENCRYPTING the data before it leaves your device, so that even someone who captures every packet sees only meaningless scrambled ciphertext, not your actual password. On open Wi-Fi, it is genuinely possible for another person on the same network to intercept traffic passing through the air. If the site used plain HTTP, your password would be in that traffic as readable plaintext, and the eavesdropper could simply lift it out. With HTTPS, before any real data is exchanged, your browser and the server perform a TLS handshake that establishes a shared secret and an encrypted channel; from then on, everything, your password included, is transformed into ciphertext that only the two legitimate ends can decode. The interceptor still captures the packets, but without the secret keys they cannot reverse the encryption, so the password is useless to them. HTTPS also checks the server's CERTIFICATE, which helps ensure you set up that encrypted channel with the real website and not an impostor who slipped in, defending against a 'man in the middle'. So the protection is not that others cannot SEE your traffic, on shared Wi-Fi they often can, but that what they see is unreadable and untamperable. Encryption turns interception from a theft into a shrug. That is why every login and payment page must be HTTPS.
Summary
Key takeaways
- HTTP (HyperText Transfer Protocol) transfers web pages between browser and server; it is an application-layer protocol.
- HTTP sends data in plaintext, so intercepted traffic (including passwords) can be read; its default port is 80.
- HTTPS (HTTP Secure) is HTTP running over SSL/TLS encryption; data is scrambled in transit; its default port is 443.
- HTTPS encrypts the data (unreadable to eavesdroppers) and verifies the server's identity with a certificate.
- Browsers show a padlock for HTTPS; use HTTPS for logins, payments, and any sensitive data.
- On shared Wi-Fi, HTTPS keeps a password safe because interceptors see only unreadable ciphertext.
- Memory hook: the S in HTTPS means Secure, HTTP plaintext on port 80, HTTPS encrypted on port 443.