Skip to content
lesson Websites, hosting and domains Beginner 3 min read

What is HTTPS?

HTTPS is the encrypted way a browser talks to a website. What it protects for your visitors, what it does not, and how to turn it on.

HTTPS is the encrypted version of HTTP, the set of rules that browsers and web servers use to talk to each other. It encrypts everything that passes between the visitor and the site. You can tell a site uses it because the address starts with https.

What it does for a visitor

  • It keeps the traffic private. Passwords, card details and form entries are hard to read for anyone who intercepts them between the visitor and the site.
  • It stops the page being altered on the way. Without it, a party in between, such as an internet provider or the operator of a Wi-Fi hotspot, can change a page or insert advertising into it.
  • It confirms the site. The server has to present a certificate issued for its domain name, so the visitor knows the browser reached the address it asked for.

What it does not do

HTTPS describes the connection. It says nothing about who runs the site. The simplest kind of certificate can be issued to anyone who controls a domain, so a scam site can have HTTPS too. Google’s advice to Chrome users is to stay careful about what they share even on a secure connection, and to check the name in the address bar.

It also does nothing for the site once the data has arrived. A website with HTTPS and a neglected plugin is still open to attack.

Why every site needs it

A brochure site with no login and no payments still needs HTTPS. Google’s guidance for web developers says to protect every site this way, because any unprotected page can be tampered with, and because each unprotected request shows an onlooker something about what the visitor is reading.

  • The Australian Signals Directorate says all public-facing websites should use HTTPS.
  • Chrome labels pages without it “Not secure”.
  • Browser features that ask for permission, such as the camera and location, depend on it.
  • Google lists secure delivery among the questions it asks about a page’s experience.

How to turn it on

  1. Open your site and look at the address. If it starts with http and not https, ask your host or developer to set HTTPS up. It needs a certificate, and a suitable one can be free.
  2. Have every http address redirect to the https one, so old links and bookmarks still arrive safely.
  3. Ask for HSTS to be switched on once the site is stable. It is a setting that tells browsers to use https for your site every time.
  4. Make sure the certificate renews automatically.

Sources

  1. HTTPS (MDN Web Docs, Mozilla) developer.mozilla.org
  2. Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au
  3. Secure your website (Australian Signals Directorate) cyber.gov.au
  4. Why HTTPS matters (web.dev, Google) web.dev
  5. Check if a site’s connection is secure (Google Chrome Help) support.google.com
  6. BOD 18-01: Enhance email and web security (CISA) cisa.gov
  7. Understanding page experience in Google Search results (Google Search Central) developers.google.com

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.