What HTTPS Protects: TLS, Certificates, CT, and HSTS

XMLans Posted on 2025-06-20 18 Views


HTTPS is HTTP carried over a secure transport. Its main jobs are to protect data in transit from eavesdropping and tampering, and to authenticate the server the browser is connecting to.

HTTPS illustration from the original explanation

TLS protects the connection

Modern HTTPS uses TLS. During the handshake, the browser and server negotiate cryptographic parameters, authenticate the server, and establish shared traffic keys. Symmetric authenticated encryption then protects the application data. It is not accurate to describe every message as encrypted with a public key in one direction and a private key in the other. See MDN’s TLS explanation.

HTTP/1.1 and HTTP/2 commonly use TLS over TCP. HTTP/3 uses QUIC, which incorporates the TLS 1.3 handshake; QUIC is not a synonym for TLS 1.3, and using it does not inherently provide weaker encryption.

Certificates authenticate a domain

A certificate links a public key to a name and is signed through a chain the browser can validate. The browser checks matters such as the requested hostname, validity period, and trusted chain. Domain validation shows control over a domain; it does not prove that the business behind a website is honest or that its content is safe.

This is why a phishing website can also use HTTPS. Check the actual domain and the request being made, rather than interpreting a connection-security indicator as a general endorsement.

Certificate Transparency and HSTS

Certificate Transparency uses publicly auditable, append-only logs so certificate issuance can be monitored. It is not a blockchain, and enforcement details differ among browsers and certificate types. Monitoring can help a domain owner notice unexpected issuance.

HSTS tells a supporting browser to use HTTPS for a host for a specified period. Once the policy applies, the browser upgrades HTTP attempts and does not offer the usual bypass for certain certificate errors. The first-visit behavior depends on whether the browser already knows the policy or the host is preloaded. It does not encrypt every unrelated resource automatically.

HTTPS adds cryptographic work, but modern implementations and connection reuse make a blanket claim of slower pages misleading. Its benefits are essential for passwords and personal information. It protects the connection; endpoint security and trustworthy application behavior remain separate requirements.

Adapted from the original Chinese article, published on June 20, 2025.

Hi! I frequently update with various articles about technology, practical tips, and cutting-edge news. I hope it will be helpful to you!
Last updated on 2026-09-30