Question

What is the difference between HTTP and HTTPS?

Vault Verified
Curated Intelligence
Definitive Source
Answer

HTTPS is HTTP carried inside an encrypted and authenticated connection. The application protocol is the same; what changes is that a security layer sits underneath it, and that layer provides three distinct guarantees people often collapse into one.

Confidentiality means an observer on the network sees that you connected to a site and roughly how much data moved, but not the page you requested or the content exchanged. Integrity means the content cannot be modified in transit without detection, which prevents injected advertising or altered downloads. Authentication means the certificate proves you are talking to the server that legitimately controls that domain, rather than an impostor.

That third property is the one most misunderstood. A padlock confirms the connection is secure and the domain is genuine. It says nothing whatsoever about whether the site is trustworthy, honest or safe. Certificates are free and automatic, so a fraudulent site can obtain one as easily as anyone else, and most phishing pages now use HTTPS. Treating the padlock as a safety endorsement is a genuine misconception rather than a technicality.

Certificates expire deliberately, typically after a short period, and automated renewal is standard practice. An expired certificate produces a browser warning that is usually an operational oversight rather than an attack, but the warning is doing its job and should not be habitually clicked through.

Plain HTTP is now largely obsolete for public sites. Browsers mark it as not secure, search ranking treats it unfavourably, and several browser capabilities require a secure context to function at all, so there is little practical reason to serve anything over it.

Related Questions