SaveMyCert
Cloud basics

HTTP vs HTTPS: what is the difference?

HTTP is the protocol browsers and servers use to exchange web pages, and HTTPS is the same protocol secured with TLS encryption, which adds confidentiality, integrity and proof of the server’s identity. In practice, the S in HTTPS is TLS: the requests and responses are identical, but they travel inside an encrypted, authenticated connection, shown by the padlock in your browser. HTTPS is now the default across the web for security, trust and search reasons. This guide explains what each does, what HTTPS adds, and the role of the certificate.

What HTTP does

HTTP (Hypertext Transfer Protocol) is the set of rules a browser and a web server use to talk: the browser sends a request for a page or resource and the server sends back a response. On its own it sends everything in plain text, so anyone able to observe the connection, such as on shared Wi-Fi, could read or alter what passes between you and the site, and nothing proves you reached the genuine server. Our what is DNS guide covers how the browser finds the server in the first place.

What HTTPS adds

HTTPS is HTTP running over TLS, and TLS adds three protections that plain HTTP lacks:

  • Confidentiality: the traffic is encrypted, so eavesdroppers see unreadable data rather than your pages, passwords or forms.
  • Integrity: tampering in transit is detected, so content cannot be silently altered on the way.
  • Server identity: the site proves who it is with a certificate, helping protect against impersonation.

The certificate and the handshake

When you connect over HTTPS, the server presents a digital certificate issued by a trusted certificate authority, and your browser checks it matches the site and has not expired. The two sides then agree encryption keys in a handshake and use them to protect the rest of the session. Both kinds of cryptography are involved: asymmetric methods establish trust and a shared key, and fast symmetric encryption protects the traffic. Our what is SSL/TLS, symmetric vs asymmetric encryption and what is public key infrastructure guides cover the details.

Why HTTPS is now the default

HTTPS became the norm because the web carries logins, payments and personal data, and unencrypted pages are open to snooping and tampering. Browsers flag plain HTTP sites as not secure, which erodes visitor trust, and search engines treat HTTPS as a positive signal, so it matters for SEO as well as safety. It is also easy to adopt: cloud providers and content delivery networks offer managed certificates, so there is rarely a good reason to serve a site over plain HTTP.

What HTTPS does not guarantee

HTTPS secures the connection, not the site’s intentions: a malicious site can use HTTPS too, so the padlock means your traffic is protected and the server is who it says, not that the site is trustworthy. It also protects data only in transit; stored data needs encryption at rest, as our what is encryption in the cloud guide explains. For exam-depth detail, our /revision library covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
CLF-C02SCS-C03

Questions, answered

HTTP sends web traffic in plain text, while HTTPS is HTTP secured with TLS, which encrypts the traffic, detects tampering and verifies the server’s identity. The S in HTTPS stands for secure and refers to TLS.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
REST vs GraphQL: what is the difference?
Cloud basics
Symmetric vs asymmetric encryption: what is the difference?
Cloud basics
TCP vs UDP: what is the difference?
Cloud basics
What is a SIEM? Security information and event management