HTTP vs HTTPS: what is the difference?
HTTP is the protocol browsers and servers use to exchange web pages, and HTTPS is the same protocol secured with TLS encryption, which adds confidentiality, integrity and proof of the server’s identity. In practice, the S in HTTPS is TLS: the requests and responses are identical, but they travel inside an encrypted, authenticated connection, shown by the padlock in your browser. HTTPS is now the default across the web for security, trust and search reasons. This guide explains what each does, what HTTPS adds, and the role of the certificate.
What HTTP does
HTTP (Hypertext Transfer Protocol) is the set of rules a browser and a web server use to talk: the browser sends a request for a page or resource and the server sends back a response. On its own it sends everything in plain text, so anyone able to observe the connection, such as on shared Wi-Fi, could read or alter what passes between you and the site, and nothing proves you reached the genuine server. Our what is DNS guide covers how the browser finds the server in the first place.
What HTTPS adds
HTTPS is HTTP running over TLS, and TLS adds three protections that plain HTTP lacks:
- Confidentiality: the traffic is encrypted, so eavesdroppers see unreadable data rather than your pages, passwords or forms.
- Integrity: tampering in transit is detected, so content cannot be silently altered on the way.
- Server identity: the site proves who it is with a certificate, helping protect against impersonation.
The certificate and the handshake
When you connect over HTTPS, the server presents a digital certificate issued by a trusted certificate authority, and your browser checks it matches the site and has not expired. The two sides then agree encryption keys in a handshake and use them to protect the rest of the session. Both kinds of cryptography are involved: asymmetric methods establish trust and a shared key, and fast symmetric encryption protects the traffic. Our what is SSL/TLS, symmetric vs asymmetric encryption and what is public key infrastructure guides cover the details.
Why HTTPS is now the default
HTTPS became the norm because the web carries logins, payments and personal data, and unencrypted pages are open to snooping and tampering. Browsers flag plain HTTP sites as not secure, which erodes visitor trust, and search engines treat HTTPS as a positive signal, so it matters for SEO as well as safety. It is also easy to adopt: cloud providers and content delivery networks offer managed certificates, so there is rarely a good reason to serve a site over plain HTTP.
What HTTPS does not guarantee
HTTPS secures the connection, not the site’s intentions: a malicious site can use HTTPS too, so the padlock means your traffic is protected and the server is who it says, not that the site is trustworthy. It also protects data only in transit; stored data needs encryption at rest, as our what is encryption in the cloud guide explains. For exam-depth detail, our /revision library covers that syllabus lesson by lesson.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Sources
Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.
- AWS Certified Cloud Practitioner (CLF-C02) exam guide — Amazon Web Services
- AWS Certified Security – Specialty (SCS-C03) exam guide — Amazon Web Services