HTTPS or Hypertext Transfer Protocol Secure, is a security mechanism used to protect communication between a web browser and a website.
It is the secure version of HTTP, the protocol that allows browsers and web servers to exchange information.
HTTPS uses Transport Layer Security (TLS) to encrypt information while it travels across a network. TLS is designed to help prevent unauthorized parties from reading, changing, or impersonating communications. The current TLS 1.3 specification was updated and formally replaced by RFC 9846 in July 2026, which superseded the earlier RFC 8446 specification.

When a website uses HTTPS, its address normally begins with https://. Browsers may also display a lock or other security indicator to show that an encrypted connection has been established.
HTTPS does not mean that every part of a website is automatically secure. It protects the connection between the browser and the website, while other security controls are needed to protect accounts, applications, servers, databases, and devices.
How HTTPS Encryption Works
HTTPS combines encryption, authentication, and data integrity mechanisms. A simplified HTTPS connection generally follows these steps:
- A browser connects to a website using HTTPS.
- The website presents a digital certificate containing its identity information and public key.
- The browser checks whether the certificate is valid and trusted.
- The browser and server perform a TLS handshake to establish secure communication parameters.
- Cryptographic keys are established for the session.
- Data exchanged during the session is encrypted and protected against unauthorized modification.
TLS therefore provides more than simple encryption. The IETF describes TLS as a mechanism intended to provide authentication and protection against eavesdropping, tampering, and message forgery.
HTTPS, SSL and TLS Explained
The terms SSL and TLS are often used together, but they are not identical.
SSL, or Secure Sockets Layer, refers to older generations of the technology. Modern encrypted web connections use TLS rather than the obsolete SSL protocols. The term “SSL certificate” remains common because certificates are still frequently described using that phrase.
| Term | Main purpose | Current relevance |
|---|---|---|
| HTTP | Transfers web information | Does not encrypt traffic |
| HTTPS | HTTP protected by TLS | Standard approach for secure web connections |
| SSL | Earlier security protocol | Obsolete |
| TLS | Modern cryptographic protocol | Current foundation of HTTPS |
| Digital certificate | Helps authenticate a website | Important part of HTTPS |
TLS 1.3 introduced several cryptographic improvements and a redesigned handshake compared with earlier versions. The July 2026 RFC 9846 specification now represents the updated TLS 1.3 standard.
Why HTTPS Matters Today
HTTPS has become important because websites routinely handle sensitive information. This can include login credentials, personal details, account information, search activity, communications, and other data.
Without encryption, information transmitted through an insecure connection may be exposed to network attackers in situations where traffic can be observed or manipulated.
HTTPS helps address several risks:
- Eavesdropping: Encryption makes transmitted information difficult for unauthorized observers to interpret.
- Tampering: TLS includes mechanisms designed to detect changes to protected traffic.
- Website impersonation: Digital certificates help browsers verify the identity associated with a website.
- Session protection: HTTPS helps protect data exchanged during authenticated web sessions.
- User privacy: Encrypted connections reduce the amount of readable information exposed while data travels across networks.
HTTPS is relevant to individuals, organizations, website administrators, developers, educational institutions, government portals, and cloud applications.
However, HTTPS is only one layer of cybersecurity. It cannot prevent weak passwords, malicious software, insecure application code, compromised devices, or attacks against a website's backend systems.
HTTPS and Modern Browser Security
Browsers have increasingly treated HTTPS as the expected default for public websites. Google announced in October 2025 that Chrome would enable its “Always Use Secure Connections” setting by default for public sites with the release of Chrome 154 in October 2026. The feature is designed to warn users before accessing a public website without HTTPS.
Google also reported that HTTPS-related protections had already become a major part of Chrome security controls. On Android, its “Always Use Secure Connections” setting can require HTTPS where possible and request permission before an insecure connection is made.
These developments indicate a broader shift toward encrypted web communication as a normal security expectation rather than an optional feature.
Recent Updates in HTTPS and TLS
The most significant recent development is the publication of RFC 9846 in July 2026. It updates the TLS 1.3 standard and obsoletes RFC 8446, the earlier TLS 1.3 specification. The updated standard continues to define TLS as a protocol designed to protect Internet communications from eavesdropping, tampering, and message forgery.
Another important development is the planned Chrome 154 change in October 2026. Chrome announced that “Always Use Secure Connections” would become enabled by default for public websites. Chrome had previously planned an earlier rollout for users who had enabled Enhanced Safe Browsing.
For website administrators, these changes reinforce the importance of maintaining valid certificates, avoiding outdated protocols, correcting mixed-content problems, and ensuring that HTTP requests are redirected appropriately to HTTPS.
HTTPS and Indian Laws and Policies
In India, HTTPS encryption exists within a wider cybersecurity and data-protection framework.
The Information Technology Act, 2000 provides the broader legal foundation for electronic information and cybersecurity matters. The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology, has also issued cybersecurity directions under Section 70B of the Act. CERT-In identifies these directions as relating to information-security practices, incident prevention, response, and reporting.
India's Digital Personal Data Protection Act, 2023 is also relevant when websites process digital personal data. The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, on November 14, 2025. MeitY describes the rules as establishing an implementation framework for protecting digital personal data.
HTTPS itself does not automatically establish compliance with the DPDP framework. Organizations handling personal data may need broader technical and organizational safeguards, depending on their activities and applicable requirements.
CERT-In guidance also emphasizes broader application-security practices, including access controls, security testing, regular reviews, and compliance with its cybersecurity directions.
Tools and Resources for HTTPS Security
Several resources can help website administrators and developers understand or evaluate HTTPS configurations:
- SSL Labs SSL Server Test: Useful for examining a website's TLS configuration and identifying configuration weaknesses.
- Mozilla Observatory: Helps evaluate various web security controls and configuration practices.
- Chrome DevTools: Provides browser-based information about certificates, connections, security warnings, and mixed content.
- IETF TLS documentation: Provides authoritative technical specifications for TLS and related standards.
- CERT-In resources: Provides Indian cybersecurity advisories, directions, and security guidance.
- Browser security documentation: Chrome and other major browsers publish information about HTTPS-related security changes.
These tools should be treated as assessment and learning resources rather than complete security audits.
Common HTTPS Security Considerations
A properly configured HTTPS environment generally requires attention to several areas:
- Use a valid digital certificate appropriate for the website's domain.
- Keep TLS configurations aligned with modern browser and security standards.
- Avoid obsolete SSL protocols.
- Monitor certificate validity and renewal dates.
- Redirect appropriate HTTP traffic to HTTPS.
- Identify and correct mixed-content resources.
- Protect private keys carefully.
- Use secure cookies and appropriate security headers.
- Keep website software and server components updated.
- Combine HTTPS with authentication, access controls, application security, and monitoring.
HTTPS encryption protects data while it travels between endpoints, but it does not replace comprehensive cybersecurity practices.
Frequently Asked Questions
What is HTTPS encryption?
HTTPS encryption protects communication between a browser and a website by using TLS. It helps prevent unauthorized reading or modification of information transmitted through the connection.
Is HTTPS the same as SSL?
No. HTTPS is the secure form of HTTP, while modern HTTPS connections use TLS. SSL is an older protocol family that has been replaced by newer TLS standards. The phrase “SSL certificate” remains widely used for digital certificates associated with HTTPS.
Does HTTPS make a website completely secure?
No. HTTPS protects network communication between the browser and server, but it cannot prevent every type of cyberattack. Vulnerable software, weak authentication, malicious code, compromised devices, and server-side weaknesses can still create security risks.
Why do browsers warn about HTTP websites?
HTTP does not provide the same encrypted transport protection as HTTPS. Modern browsers increasingly encourage encrypted connections and can warn users before they access websites through insecure connections.
What is TLS 1.3?
TLS 1.3 is a modern version of the Transport Layer Security protocol used to protect Internet communications. In July 2026, RFC 9846 updated the TLS 1.3 specification and replaced RFC 8446 as the governing specification.
Conclusion
HTTPS encryption is a fundamental part of modern web security. By using TLS, HTTPS helps protect information exchanged between browsers and websites against eavesdropping, tampering, and certain forms of connection-level impersonation.
Recent developments are continuing to strengthen the expectation that public websites should use encrypted connections. The updated TLS 1.3 specification published in July 2026 and Chrome's planned October 2026 default HTTPS protection demonstrate the continued movement toward secure-by-default web communication.
For users and website administrators, HTTPS should be understood as one important layer within a broader cybersecurity strategy. Proper certificate management, modern TLS configuration, secure application development, strong authentication, regular updates, and appropriate data-protection practices all contribute to a safer digital environment.