Computer Science · Ch 12 — Security Aspects
HTTP vs HTTPS
HTTP vs HTTPS
The core idea
Before you type your password into any website, the address bar tells you a story. If the URL begins with http://, the data you send travels in plain text — readable by anyone who intercepts it. If it begins with https://, that same data is scrambled before it leaves your device and only unscrambled by the intended server. That single letter — the s — is the difference between sending a postcard and sending a sealed, locked box.
What HTTP and HTTPS are
Both HTTP (Hyper Text Transfer Protocol) and HTTPS (Hyper Text Transfer Protocol Secure) are sets of rules — protocols — that govern how data is transmitted over the World Wide Web. In plain terms, they define how a client web browser and a server talk to each other. Every time you open a webpage, your browser and the server hosting that page are following one of these two rulebooks.
How HTTP works and where it is enough
HTTP sends information over the network as it is. It does not scramble or encode the data being transmitted. This means anything you send — a form entry, a search query, a password — travels in its original, readable form. That leaves it vulnerable to attacks from hackers, who can intercept the data mid-transmission and read it directly.
Because of this weakness, HTTP is sufficient only for websites that share public information — news portals, blogs, informational pages. Nothing sensitive is being exchanged, so there is little to protect. If a hacker intercepts a news article request, they gain nothing of value.
Why HTTPS exists and how it protects you
When the conversation involves personal information, banking credentials, or passwords, plain-text transmission is unacceptable. This is where HTTPS steps in. HTTPS encrypts the data before transmission. The information is scrambled into an unreadable form at your end, sent across the network, and then decrypted at the receiver end to recover the original data. Even if a hacker intercepts the encrypted data, they cannot make sense of it without the decryption key.
The practical rule: always look for https:// at the beginning of the URL before entering banking, personal, or other sensitive information on any website.
The SSL Digital Certificate
HTTPS-based websites do not work by magic — they require an SSL Digital Certificate. This certificate is what enables the encryption and decryption process. It authenticates the website's identity and establishes the secure connection between the browser and the server. Without it, a website cannot offer HTTPS.
The practical takeaway
| Feature | HTTP | HTTPS |
|---|---|---| …