HTTP vs HTTPS: what’s the difference?
HTTP sends web pages in the open and HTTPS sends them encrypted. What visitors see in the browser, and what moving a site to HTTPS involves.
HTTP and HTTPS are the same set of rules for asking a web server for a page and getting it back. The difference is the connection they travel over: HTTP sends everything in the open, and HTTPS sends it encrypted.
What each one is
HTTP is the Hypertext Transfer Protocol. A browser sends a request, the server sends a response, and nothing protects either on the way. The US cyber security agency CISA puts the weakness in one line: HTTP connections can be easily monitored, modified and impersonated.
HTTPS is HTTP sent over a secured connection. Under the standard, a browser must make sure the connection is secured, and that the server has proved it speaks for the domain, before it sends any request at all. The requests and pages inside are the same as before.
The differences side by side
- Privacy. Over HTTP, anyone on the path can read what is sent. Over HTTPS it is encrypted.
- Tampering. An HTTP page can be changed between the server and the visitor. An HTTPS page cannot be changed without the browser noticing.
- Identity. HTTP gives no proof of which server answered. HTTPS requires the server to present a certificate for its domain.
- Address. One starts with http:// and the other with https://. They also use different default ports on the server, 80 and 443.
What visitors see
Google Chrome has marked every HTTP page as “not secure” since version 68, released in July 2018. Chrome’s help page explains the label to users in these terms: the site does not use a private connection, someone may be able to view and change the information sent through it, and they should not enter private or personal information on the page. It also says the fix belongs to the site owner.
For a business, that label sits beside its name on every page, including the contact form.
How to choose
For a public website there is nothing to weigh up. The Australian Signals Directorate says all public-facing websites should use HTTPS. Cost and speed are not obstacles. A certificate that suits most sites can be had for free, and Google’s guidance for developers describes the extra work of encryption as generally small next to everything else a site does.
What takes care is the move itself:
- Install a certificate and check the site loads on its https address.
- Find anything the pages still load over http, such as images or scripts. Browsers warn about this “mixed content” or block it, which can break a page.
- Redirect every http address to its https version with a permanent redirect, so links, bookmarks and search engines follow.
- Once it has run cleanly for a while, ask for HSTS, which tells browsers to use https every time.
Sources
- RFC 9110: HTTP semantics (IETF) rfc-editor.org
- BOD 18-01: Enhance email and web security (CISA) cisa.gov
- Check if a site’s connection is secure (Google Chrome Help) support.google.com
- A milestone for Chrome security: marking HTTP as “not secure” (Google) blog.google
- Enable HTTPS on your servers (web.dev, Google) web.dev
- Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au