How HTTP Works

Comparison

HTTP vs HTTPS: What TLS Adds and What It Does Not Hide

HTTP vs HTTPS: what TLS encrypts and authenticates, what still leaks (IP, SNI, sizes), where ECH stands, HSTS, mixed content, and the SEO effect of moving to HTTPS.

Bottom line: HTTPS is HTTP carried inside TLS. It encrypts and authenticates the conversation between browser and server, but it still reveals the server IP, usually the hostname, and the rough size and timing of traffic.

By How HTTP WorksReview process
HTTP
vs
HTTPS

TL;DR: HTTPS is HTTP inside a TLS connection: it encrypts the request and response, proves the server’s identity with a certificate, and detects tampering. It does not hide the server’s IP address, usually does not hide the hostname (SNI), and does not hide how much data moves and when. Use HTTPS everywhere, then add HSTS.

Side By Side

HTTPHTTPS
TransportPlain TCPTLS over TCP, or QUIC for HTTP/3
Default port80443
EncryptedNoYes (path, query, headers, cookies, body)
Server identity verifiedNoYes, by certificate chain and hostname match
Tampering by networkPossible: ads, injected scripts, rewritten downloadsDetected and rejected
HTTP/2 in browsersNot supportedRequired in practice (browsers only do HTTP/2 over TLS)
HTTP/3Not availableAvailable (HTTP/3 always uses TLS 1.3)
Browser featuresPowerful APIs such as service workers, geolocation, camera, and Secure cookies are restrictedAvailable
Cert costn/aFree certificates exist via Let’s Encrypt and others

What TLS Adds

  1. Confidentiality. A passive observer on the same Wi-Fi or upstream network sees ciphertext.
  2. Integrity. Any modification in transit breaks the record authentication, so ISPs and hotspots cannot inject content.
  3. Server authentication. The certificate chain must validate to a trusted root and match the hostname, which is what stops a man-in-the-middle from impersonating the site. Failures surface as errors such as NET::ERR_CERT_COMMON_NAME_INVALID; see ERR_CERT_COMMON_NAME_INVALID.

Here is what a plain HTTP request exposes to everyone on the path:

GET /account/settings?tab=billing HTTP/1.1
Host: shop.example.com
Cookie: session=7d3c1c2e...

On HTTPS, the observer sees only a TLS handshake to shop.example.com and then opaque records.

What HTTPS Does Not Hide

Visible to the networkWhy
Destination IP addressPackets must be routed to it
Hostname, in most casesThe TLS ClientHello carries it in the SNI extension in cleartext, unless ECH is used
DNS lookupsSeparate protocol; encrypted only with DoH or DoT
Request and response sizes, timing, directionTraffic analysis can distinguish pages and sometimes infer what a user did
That you used HTTPS at allThe handshake is recognizable

ECH status. Encrypted Client Hello is published as RFC 9849, a Proposed Standard on the Internet Standards Track. It encrypts the inner ClientHello, including SNI, under a public key the server publishes in a DNS HTTPS record. It requires TLS 1.3, and both the client and the server or CDN must support it, with the key discovered over DNS. It also helps most when many sites share one frontend, since the IP still reveals a single-tenant server. Check your specific browser and hosting provider before telling users it is on.

Also visible at the application layer: anything a corporate TLS-inspection proxy can decrypt. Managed devices with an installed enterprise root certificate allow that proxy to read the traffic.

HSTS: Closing The First-Request Gap

Typing shop.example.com in a browser usually starts with http://, and a redirect to HTTPS happens only after that cleartext request, which is where an attacker on the network can strip or intercept. HSTS makes the browser remember to use HTTPS:

HTTP/1.1 200 OK
Strict-Transport-Security: max-age=31536000; includeSubDomains

Details and rollout order are in Strict-Transport-Security.

Mixed Content

An HTTPS page that requests http:// subresources undermines the whole page. Browsers block active mixed content (scripts, stylesheets, iframes, fetch/XHR) and handle passive content (images, audio, video) by upgrading or warning, depending on the browser and version. A typical console message is Mixed Content: The page at 'https://...' was loaded over HTTPS, but requested an insecure script 'http://...'. This request has been blocked. The fix is to change the URL in the HTML, CSS, or database content. See Mixed content blocked for diagnosis. Content-Security-Policy: upgrade-insecure-requests is a stopgap while you clean up hardcoded URLs.

Behind a TLS-terminating proxy, apps that build absolute URLs from the incoming scheme will emit http:// links unless they trust X-Forwarded-Proto.

SEO, Stated Carefully

Common Mistakes

Believing HTTPS makes an app secure. It protects the transport only. SQL injection, broken access control and leaked tokens are unaffected.

Serving HTTPS but leaving port 80 open without a redirect. Users who type the bare domain end on a dead or HTTP-only page.

Redirecting with 302 during migration. Use a permanent redirect so search engines consolidate on the HTTPS URL.

Cookies without Secure. A session cookie lacking Secure is also sent over any plain-HTTP request to the host, which defeats HTTPS. Pair Secure with HSTS.

Enabling includeSubDomains or preload before checking every subdomain. Forgotten internal hosts that only speak HTTP become unreachable.

Assuming a padlock means the site is trustworthy. It means the connection is encrypted to whoever holds a valid certificate for that name. Phishing sites have valid certificates too.

Expecting a CDN to fix an expired origin certificate. Depending on the SSL mode, edge-to-origin TLS can still fail with 525 or 526; see 525 SSL handshake failed.

FAQ

What is the difference between HTTP and HTTPS?

HTTPS is the same HTTP protocol sent through a TLS connection. TLS adds encryption (nobody on the path can read or change the request and response), server authentication through a certificate, and integrity checks. The default port changes from 80 to 443, and the URL scheme from http:// to https://.

Does HTTPS hide which websites I visit?

Only partly. The path, query string, headers, cookies and body are encrypted, but a network observer still sees the destination IP address and, in most connections, the hostname in the TLS Server Name Indication (SNI) field. DNS queries are separate and are visible unless you use DNS over HTTPS or TLS. Encrypted Client Hello (ECH, standardized as RFC 9849) encrypts the SNI, but it needs support on both the client and the server or CDN, so do not assume it is active.

Can my employer or ISP see what I do on HTTPS sites?

They can see which hostnames and IPs you connect to, when, and roughly how much data moves. They cannot read page contents unless a managed device has a corporate root certificate installed that lets a proxy decrypt the traffic, which is common on company laptops.

What is HSTS and do I need it?

HTTP Strict Transport Security is a response header (Strict-Transport-Security: max-age=31536000; includeSubDomains) that tells the browser to use HTTPS for your host for the given period and refuse to continue past certificate errors. It prevents the first plain-HTTP request from being intercepted on later visits. Browsers ignore the header when it arrives over plain HTTP, so you need a working HTTPS site first.

Does switching to HTTPS improve SEO?

Google has said since 2014 that HTTPS is a lightweight ranking signal, so do not expect a jump from it alone. The practical SEO work is in the migration: 301 redirect every HTTP URL to its HTTPS twin, update canonical URLs, sitemaps and internal links, and make sure no resources load over HTTP.

Why does my HTTPS page say “Not secure” or show a broken padlock?

Usually mixed content: the page is HTTPS but loads a script, stylesheet, image or frame over http://. Browsers block active mixed content such as scripts and iframes and may auto-upgrade or warn about passive content. Fix the URLs in your HTML or CSS, or add a Content-Security-Policy upgrade-insecure-requests directive as a stopgap.

References

Browse /search