What Is HTTPS?

HTTPS (HyperText Transfer Protocol Secure) is a protocol that adds TLS (Transport Layer Security) encryption to HTTP. When a website's URL begins with "https://", all communication between your browser and the server is encrypted.

HTTPS has become the standard for web traffic. Google has treated HTTPS adoption as one of its search ranking factors since 2014, and major browsers display a "Not Secure" warning for sites served over plain HTTP.

How TLS Works

TLS (Transport Layer Security) is a protocol designed to encrypt communications. SSL (Secure Sockets Layer) is its former name, and the successor standard, TLS, is what is actually used.

The TLS Handshake

When an HTTPS connection is established, a process called the "TLS handshake" takes place between the browser and the server.

  1. The browser requests a connection and sends a list of supported TLS versions and cipher suites
  2. The server selects a TLS version and cipher suite, then sends its SSL/TLS certificate
  3. The browser verifies the certificate's validity (CA signature, expiration date, domain name match)
  4. A shared encryption key (session key) is securely generated through a key exchange algorithm
  5. All subsequent communication is encrypted using the session key

This process typically completes in just a few tens of milliseconds, so users rarely notice it happening.

TLS Versions

TLS 1.3 (Recommended)

Standardized in 2018 as RFC 8446, this is the newest version of TLS as of August 2026. The specification document itself was replaced by RFC 9846 in July 2026, but the version number remains 1.3. The handshake has been reduced to a single round trip (1-RTT), which improves connection speed. Weak cipher suites were removed, and forward secrecy is mandatory. The RFC documents that define internet standards such as TLS are also known for the ASCII art hidden inside them, not only for their technical content. Understanding how TLS interacts with cookie tracking is also important for a complete picture of browser security.

TLS 1.2

Finalized in 2008 and still in wide use as of August 2026. It provides adequate security when configured with appropriate cipher suites, though improper configuration can leave room for weaker ciphers.

TLS 1.0 / 1.1 (Deprecated)

These versions have known vulnerabilities, and support has been dropped by all major browsers. Servers that only support these versions are no longer accessible.

The IP Check-san Connection Protocol section lets you check the TLS version and cipher suite used in your current connection.

The Role of SSL/TLS Certificates

An SSL/TLS certificate is a digital certificate that verifies a website's identity. Issued by a Certificate Authority (CA), it contains the following information:

  • Domain name
  • Certificate owner information
  • CA signature
  • Public key
  • Expiration date

Types of Certificates

  • DV (Domain Validation) certificate: Verifies domain ownership only. Available for free from providers like Let's Encrypt
  • OV (Organization Validation) certificate: Also verifies the organization's existence. Suited for business websites
  • EV (Extended Validation) certificate: Issued after the most rigorous vetting process. Used by financial institutions and similar organizations

These verification methods rely on established trust hierarchies. Emerging cryptographic approaches like zero-knowledge proofs offer alternative ways to verify identity without revealing underlying data.

Validity Periods Are Getting Shorter in Stages

The maximum validity period of a certificate is set by the Baseline Requirements of the CA/Browser Forum, the body in which certificate authorities and browser vendors participate. Under the rules in force as of August 2026, the limit is 398 days for certificates issued before March 15, 2026, 200 days on and after March 15, 2026, 100 days on and after March 15, 2027, and 47 days on and after March 15, 2029.

The shorter the renewal interval becomes, the harder it is to keep swapping certificates by hand. The practical takeaway is to automate renewal with a tool that supports ACME (Automatic Certificate Management Environment), so that an expired certificate never turns into a connection error.

What Is a Cipher Suite?

A cipher suite is a combination of cryptographic algorithms used in a TLS connection. It consists of four components: key exchange, authentication, encryption, and hashing.

For example, TLS_AES_256_GCM_SHA384 means encryption with AES-256-GCM and hashing with SHA-384.

On IP Check-san, you can check the cipher suite used in your current connection in the Connection Protocol section.

ALPN and HTTP/2 · HTTP/3

ALPN (Application-Layer Protocol Negotiation) is a mechanism for negotiating the application-layer protocol (HTTP/1.1, HTTP/2, HTTP/3, etc.) during the TLS handshake.

HTTP/2 runs over TLS and dramatically improves communication efficiency through multiplexing and header compression. HTTP/3 runs over the QUIC protocol, delivering even faster speeds and more stable connections.

On IP Check-san, you can also check the HTTP version, TLS version, and handshake type.

How to Verify a Secure Connection

  • Confirm that a padlock icon appears in your browser's address bar
  • Verify that the URL begins with "https://"
  • Check the HTTPS/TLS connection rating on IP Check-san's Security Score
  • Confirm that TLS 1.2 or higher is being used

Verifying your HTTPS connection is especially important when using public Wi-Fi. Use IP Check-san to check your TLS version, cipher suite, and overall connection security at a glance. Understanding HTTP security headers provides an additional layer of insight into a website's security posture.

Related Glossary Terms

TLS/SSL Cryptographic protocols that encrypt internet communications to ensure confident… HTTPS A protocol that adds TLS encryption to HTTP, securing communication between the … Firewall A security mechanism placed at network boundaries that inspects and controls inc… Public Key Cryptography A cryptographic method that uses a mathematically linked pair of keys - a public… Digital Certificate An electronic document issued by a trusted Certificate Authority (CA) that binds…

Frequently Asked Questions

Is my traffic completely safe as long as the site uses HTTPS?

HTTPS guarantees that the connection is encrypted, but not that the site itself is trustworthy. Phishing sites can also use HTTPS, so checking the URL and domain name is still essential.

Is it dangerous to visit HTTP sites?

Simply reading a page without entering personal information or logging in carries limited risk, but the traffic can be intercepted by third parties. As of August 2026 the vast majority of sites support HTTPS, so a site that is still HTTP-only is a reason to question how it is maintained.