HTTPS & TLS

HTTPS is HTTP inside a TLS connection. The TLS handshake agrees a secret key that never crosses the network, and the certificate proves you are talking to the real server.

Opening https://example.org

Your browser
example.org

Key exchange (Diffie-Hellman)

Public: g = 5, p = 23

Browser secret a = 6 → sends 8

Server secret b = 15 → sends 19

Shared key: ?

What an eavesdropper sees

  • nothing yet

Everything you send crosses networks you don't control. TLS makes sure only the real server can read it — and proves it is the real server.

Step 1 / 8

What's happening?

  1. Browser and server each pick a secret number and exchange only derived public values (Diffie-Hellman).
  2. Each combines its own secret with the other's public value and gets the same key; an eavesdropper with only the public values cannot.
  3. The server's certificate, signed by an authority the browser trusts, proves the key really belongs to the site — which is what stops a man-in-the-middle.

Where you'll meet it

Every padlock in the address bar, every API call from an app, and the reason public Wi-Fi can't read your passwords.

Common mistake

Thinking encryption alone is enough. Without checking the certificate, you could have a perfectly encrypted connection to an attacker.

FAQ

Are the numbers here real?

The maths is real; the numbers are tiny so you can check them. Real handshakes use 256-bit elliptic-curve values.

What can someone on the network still see?

Which server you connected to and how much data moved — not the pages, forms or cookies inside.

TLS 1.2 vs 1.3?

TLS 1.3 finishes in one round trip instead of two, encrypts the certificate, and removed weak old ciphers.