{"id":13324,"date":"2020-10-26T16:09:27","date_gmt":"2020-10-26T20:09:27","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=13324"},"modified":"2024-07-30T16:22:31","modified_gmt":"2024-07-30T20:22:31","slug":"how-does-https-work","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/how-does-https-work\/","title":{"rendered":"How Does HTTPS Work?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"we-all-know-that-https-=-secure-but-do-you-know-how-https-works-under-the-hood-let\u2019s-take-a-look-at-how-https-works-to-make-the-internet-safer-for-all-of-us\">We all know that HTTPS = secure. But do you know how HTTPS works under the hood? Let\u2019s take a look at how HTTPS works to make the internet safer for all of us&#8230;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">95% of webpages viewed in the US are viewed using HTTPS. (That\u2019s according to Google Chrome user data via the <a href=\"https:\/\/transparencyreport.google.com\/https\/overview?hl=en&amp;load_os_region=chrome-usage:1;series:page-load;groupby:os&amp;lu=load_os_region\">Google Transparency report<\/a>.) Other countries also overwhelmingly use HTTPS URLs \u2014 93% in Germany, 85% in Japan, and 85% in India. HTTPS has been adopted worldwide as the preferred protocol for most websites. But just how does HTTPS work and what does it do?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re reading this article, you probably already know that the \u201cS\u201d in <a href=\"https:\/\/www.thesslstore.com\/blog\/is-https-secure-a-look-at-how-secure-https-is\/\">HTTPS means secure<\/a>. You\u2019ve likely looked for https:\/\/ (or a padlock icon) at the beginning of a URL to confirm it was secure before entering your credit card details online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-https-what-https-stands-for\/\">what does HTTPS do<\/a> for the average internet user? And how does HTTPS work in a more technical sense?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\">How HTTPS works is actually a pretty big topic, so we&#8217;ll break it down into several sections&#8211;starting with the basics. If you&#8217;re already somewhat familiar with HTTPS and want to skip around, you can use this table of contents to jump to the part that interests you.<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">What we&#8217;re hashing out&#8230;<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#we-all-know-that-https-=-secure-but-do-you-know-how-https-works-under-the-hood-let\u2019s-take-a-look-at-how-https-works-to-make-the-internet-safer-for-all-of-us\">We all know that HTTPS = secure. But do you know how HTTPS works under the hood? Let\u2019s take a look at how HTTPS works to make the internet safer for all of us&#8230;<\/a><ol><\/ol><\/li><li><a href=\"#how-https-works-101-the-two-things-https-does-to-make-the-internet-safer\">How HTTPS Works 101: The Two Things HTTPS Does to Make the Internet Safer<\/a><ol><li><a href=\"#https-authentication-ensures-you\u2019re-connected-to-the-correct-website-and-that\u2019s-more-important-than-it-sounds\">HTTPS Authentication Ensures You\u2019re Connected to the Correct Website (And That\u2019s More Important Than It Sounds)<\/a><ol><li><a href=\"#why-https-authentication-is-important\">Why HTTPS Authentication Is Important<\/a><ol><li><a href=\"#how-do-dns-attacks-like-this-work\">How Do DNS Attacks Like This Work?<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-https-authentication-works\">How HTTPS Authentication Works<\/a><ol><li><a href=\"#step-1-getting-a-certificate\">Step 1: Getting a Certificate<\/a><ol><\/ol><\/li><li><a href=\"#step-2-\u201cpassport-please\u201d\">Step 2: \u201cPassport, Please!\u201d<\/a><ol><\/ol><\/li><li><a href=\"#step-3-verifying-the-certificate\">Step 3: Verifying the Certificate<\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/li><li><a href=\"#https-encryption-ensures-others-can\u2019t-spy-on-your-communications\">HTTPS Encryption Ensures Others Can\u2019t Spy on Your Communications<\/a><ol><li><a href=\"#how-https-encryption-works\">How HTTPS Encryption Works<\/a><ol><\/ol><\/li><li><a href=\"#what-https-encryption-doesn\u2019t-do\">What HTTPS Encryption Doesn\u2019t Do<\/a><ol><\/ol><\/li><li><a href=\"#but-wait\u2026-howwhy-would-anyone-be-spying-on-my-communications\">But Wait\u2026 How\/Why Would Anyone Be Spying on My Communications?<\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/li><li><a href=\"#how-https-works-201-the-technical-details\">How HTTPS Works 201: The Technical Details<\/a><ol><li><a href=\"#http-vs-https\">HTTP vs. HTTPS<\/a><ol><\/ol><\/li><li><a href=\"#how-https-works-under-the-hood-https-runs-on-pki\">How HTTPS Works Under the Hood: HTTPS Runs on PKI<\/a><ol><li><a href=\"#digital-certificates\">Digital Certificates<\/a><ol><\/ol><\/li><li><a href=\"#public-keys-amp;-private-keys\">Public Keys &amp; Private Keys<\/a><ol><\/ol><\/li><li><a href=\"#certificate-authorities\">Certificate Authorities<\/a><ol><\/ol><\/li><li><a href=\"#digital-signatures\">Digital Signatures<\/a><ol><\/ol><\/li><li><a href=\"#root-stores\">Root Stores<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-https-works-for-website-owners-how-to-enable-https-on-your-website\">How HTTPS Works for Website Owners: How to Enable HTTPS on Your Website<\/a><ol><li><a href=\"#step-1-acquire-an-ssltls-certificate\">Step 1: Acquire an SSL\/TLS Certificate<\/a><ol><\/ol><\/li><li><a href=\"#step-2-install-the-ssl-certificate-on-your-website\">Step 2: Install the SSL Certificate on Your Website<\/a><ol><\/ol><\/li><li><a href=\"#step-3-change-your-site-settings-to-use-https\">Step 3: Change Your Site Settings to Use HTTPS<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-https-works-for-website-users-the-tls-handshake\">How HTTPS Works for Website Users: The TLS Handshake<\/a><ol><li><a href=\"#creating-a-secure-connection-with-the-ssltls-handshake\">Creating a Secure Connection with the SSL\/TLS Handshake<\/a><ol><li><a href=\"#steps-1-2-hello-amp;-cipher-suites\">Steps 1-2: Hello &amp; Cipher Suites!<\/a><ol><\/ol><\/li><li><a href=\"#steps-3-5-certificate-amp;-key-exchange\">Steps 3-5: Certificate &amp; Key Exchange<\/a><ol><\/ol><\/li><li><a href=\"#steps-6-10-setting-up-symmetric-encryption\">Steps 6-10: Setting Up Symmetric Encryption<\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/li><li><a href=\"#handy-https-usage-tips-for-users\">Handy HTTPS Usage Tips For Users<\/a><ol><li><a href=\"#google-chrome-hides-the-https\">Google Chrome Hides the HTTPS<\/a><ol><\/ol><\/li><li><a href=\"#you-can-verify-company-details-using-their-ssl-certificate\">You Can Verify Company Details Using Their SSL Certificate<\/a><ol><\/ol><\/li><li><a href=\"#be-very-careful-proceeding-past-an-https-warning\">Be Very Careful Proceeding Past an HTTPS Warning<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#so\u2026that\u2019s-how-https-works\">So\u2026That\u2019s How HTTPS Works<\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/div>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"how-https-works-101-the-two-things-https-does-to-make-the-internet-safer\">How HTTPS Works 101: The Two Things HTTPS Does to Make the Internet Safer<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">When you go to a website that starts with https:\/\/, that tells you two very specific things:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li><strong>A third party has authenticated the website<\/strong>. The website has been authenticated to verify it is the website it claims to be \u2014 if your browser bar says <a href=\"https:\/\/www.amazon.com\">https:\/\/www.amazon.com<\/a>, you can be confident that you\u2019re actually on amazon.com.<\/li>\n\n\n\n<li><strong>The site uses encryption<\/strong>. Data you send to\/from the website is encrypted so other parties can\u2019t see\/steal it\u2014you can submit credit card numbers or other sensitive data and know that nobody can intercept your info while it\u2019s making the trip to amazon.com.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"743\" height=\"338\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does.png\" alt=\"How HTTPS Works - The Two Things HTTPS Does\" class=\"wp-image-13331 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does.png 743w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does-300x136.png 300w\" sizes=\"auto, (max-width: 743px) 100vw, 743px\" \/><figcaption>How HTTPS Works &#8211; The Two Things HTTPS Does<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Important note about terminology: you\u2019ll hear the terms \u201cSSL\u201d and \u201cTLS\u201d used in conjunction with HTTPS. A few quick facts will make these terms easier to keep straight:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Secure sockets layer (SSL) and transport layer security (TLS) refer to the type of secure connection that HTTPS uses for communication between a web browser and web server.<\/li>\n\n\n\n<li>Technically speaking, SSL is an older technology that was deprecated and replaced with TLS.<\/li>\n\n\n\n<li>Practically speaking, most people use the terms interchangeably. That\u2019s why you\u2019ll sometimes see us use \u201cSSL\/TLS\u201d or \u201cSSL\/TLS Certificate.\u201d<\/li>\n\n\n\n<li>SSL\/TLS and HTTPS go together like dirt and grass. You can\u2019t grow grass without dirt, and you can\u2019t have HTTPS without SSL\/TLS.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s dig a little deeper into how HTTPS works to provide these two security benefits\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"https-authentication-ensures-you\u2019re-connected-to-the-correct-website-and-that\u2019s-more-important-than-it-sounds\">HTTPS Authentication Ensures You\u2019re Connected to the Correct Website (And That\u2019s More Important Than It Sounds)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned, the first thing that HTTPS does is authenticate the website to verify that your browser is connected to the correct website. If you typed in amazon.com, your browser uses HTTPS to ensure that the website you\u2019re connected to is the real amazon.com (not a fake website run by a hacker in a back alley in San Fransokyo).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"why-https-authentication-is-important\">Why HTTPS Authentication Is Important<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now, you may be wondering why this is necessary \u2014 &#8220;can\u2019t I just look at the URL in my browser\u2019s address bar?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If it says amazon.com and it looks like amazon.com, it must be amazon.com, right? Not necessarily.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"397\" height=\"185\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-HTTPS.png\" alt=\"\" class=\"wp-image-13332\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-HTTPS.png 397w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-HTTPS-300x140.png 300w\" sizes=\"auto, (max-width: 397px) 100vw, 397px\" \/><figcaption class=\"wp-element-caption\">Amazon.com isn&#8217;t always amazon.com<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Your browser\u2019s address bar is always a good place to check, but it\u2019s not foolproof \u2014 it\u2019s possible that you could type <a href=\"http:\/\/www.amazon.com\">http:\/\/www.amazon.com<\/a> into your browser\u2019s address bar and get a website that looks like Amazon.com\u2026 but is actually a fake website run by a hacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers can use DNS poisoning, <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-malware-types-of-malware-how-they-work\/\">malware<\/a>, or other attack methods so your browser invisibly connects to the wrong website server. So while it looks like you\u2019re connecting to a legitimate URL in your browser bar, you\u2019re actually on a fake website run by a hacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s consider a real-life example. &nbsp;Hackers used DNS poisoning to take a legitimate domain name and point visitors to a fake website where they stole <a href=\"https:\/\/www.coindesk.com\/150k-stolen-myetherwallet-users-dns-server-hijacking\">$150K from MyEtherWallet users.<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"437\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/MyEtherWallet-dns-attack.png\" alt=\"MyEtherWallet DNS attacks\" class=\"wp-image-13333\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/MyEtherWallet-dns-attack.png 603w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/MyEtherWallet-dns-attack-300x217.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"how-do-dns-attacks-like-this-work\">How Do DNS Attacks Like This Work?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">First of all, we need to briefly discuss how your computer actually connects to websites. When you type in amazon.com, your computer doesn\u2019t actually understand \u201camazon.com\u201d as an address it can connect to. Amazon.com is the human-readable address, the actual address your computer connects to is the IP address (which looks like this: 176.32.103.205). Your computer needs to lookup amazon.com\u2019s IP address using the DNS system before it can connect to the amazon.com web server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a simplified representation of the process:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"489\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/dns-how-your-computer-connects-to-a-website.png\" alt=\"How DNS Works\" class=\"wp-image-13339 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/dns-how-your-computer-connects-to-a-website.png 694w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/dns-how-your-computer-connects-to-a-website-300x211.png 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><figcaption><em>How DNS works. (An important prerequisite before we tackle the question: how does HTTPS work?)<\/em><\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">When you visit a website, your computer uses the DNS system to get the IP address of the website you\u2019re trying to visit. Your computer is actually connecting to an IP address, not to an address like amazon.com. In a DNS poisoning attack, your computer is given an incorrect IP address, which means that your computer connects you to the wrong server. Your computer thinks it\u2019s amazon.com and you think it\u2019s amazon.com, but it\u2019s not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Want to read further? If you\u2019d like to read the in-depth version of how DNS poisoning attacks work, read our <a href=\"https:\/\/www.thesslstore.com\/blog\/dns-poisoning-attacks-a-guide-for-website-admins\/\">guide on DNS Poisoning Attacks<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The good news is that HTTPS is an effective defense against hacker tricks like DNS poisoning. How? Let\u2019s dive into how HTTPS works to ensure that you\u2019re on the correct website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"how-https-authentication-works\">How HTTPS Authentication Works<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">So, how does HTTPS ensure that you\u2019re connected to the correct website?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your browser uses an SSL\/TLS certificate and the <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-certificate-authority-ca-and-what-do-they-do\/\">certificate authority<\/a> that issued it to authenticate each HTTPS website that you visit. Here\u2019s how it works\u2026<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"step-1-getting-a-certificate\">Step 1: Getting a Certificate<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">First, the website needs to have an SSL certificate issued by a publicly trusted certificate authority. An SSL certificate is a lot like a passport \u2014 but it\u2019s for websites, not people. An SSL certificate includes details such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The website\u2019s URL(s),<\/li>\n\n\n\n<li>A public key (which is linked to a private key only possessed by the website),<\/li>\n\n\n\n<li>The certificate authority that issued the certificate,<\/li>\n\n\n\n<li>The certificate\u2019s expiration date, and<\/li>\n\n\n\n<li>The legal organization that runs the website (optional).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">To get a valid SSL certificate, the website owner will have to go through a few steps:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>Generate a public key and a private key (more on how they\u2019re use later).<\/li>\n\n\n\n<li>Go through a specific process to prove to the certificate authority that they\u2019re the actual owner of the website.<\/li>\n\n\n\n<li>In the case of OV and EV SSL certificates, the website owner also has to prove that they\u2019re an actual, legally registered organization.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Once those steps are completed, the certificate authority issues an SSL certificate to the website owner. This certificate is installed on the web server and is automatically provided every time someone visits the website via an https:\/\/ URL.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h4 class=\"wp-block-heading\" id=\"step-2-\u201cpassport-please\u201d\">Step 2: \u201cPassport, Please!\u201d<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">When you visit an HTTPS website, the website sends its SSL\/TLS certificate to your web browser. Let\u2019s use our website as an example. If you click on the padlock in your browser, then click to view certificate details, you can see our website\u2019s certificate and the information it includes.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"401\" height=\"397\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate.png\" alt=\"SSL certificate\" class=\"wp-image-13345 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate.png 401w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate-300x297.png 300w\" sizes=\"auto, (max-width: 401px) 100vw, 401px\" \/><figcaption>SSL certificate for www.thesslstore.com<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you open the Details tab, you\u2019ll see more information about the website and the organization that runs it, like this:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"439\" height=\"440\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate-details.png\" alt=\"SSL certificate details\" class=\"wp-image-13346\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate-details.png 439w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/HTTPS-thesslstore-certificate-details-300x300.png 300w\" sizes=\"auto, (max-width: 439px) 100vw, 439px\" \/><figcaption class=\"wp-element-caption\">SSL certificate details for www.thesslstore.com<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Some websites (like ours) have certificates that also show their company details (such as company name, location, etc.). These are called organization validation (OV) or extended validation (EV) certificates. The company details are also verified, so you can be 100% confident you know exactly who is running the website you\u2019re on.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"step-3-verifying-the-certificate\">Step 3: Verifying the Certificate<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Now we come to the critical step \u2014 verifying the website\u2019s SSL certificate. Just because the website presents an SSL certificate doesn\u2019t mean that your browser should trust it. After all, as Albert Einstein famously said:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"316\" height=\"309\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/einstein-internet.jpg\" alt=\"Don't believe everything you read, just because it's on the internet&quot; -  Albert Einstein - Serious Albert Einstein | Make a Meme\" class=\"wp-image-13348\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/einstein-internet.jpg 316w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/einstein-internet-300x293.jpg 300w\" sizes=\"auto, (max-width: 316px) 100vw, 316px\" \/><figcaption class=\"wp-element-caption\">Albert Einstein&#8217;s advice is a critical part of how HTTPS works! \ud83d\ude09<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Fortunately, your browser has a way it can verify the website\u2019s SSL certificate to ensure it\u2019s accurate and not a fake. Specifically, your browser will verify whether:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>The website\u2019s SSL certificate was issued by a certificate authority on the browser\u2019s trusted list. (The browser uses the certificate authority\u2019s digital signature to instantly confirm that the certificate authority issued the website\u2019s certificate.)<\/li>\n\n\n\n<li>The SSL certificate is valid for the website domain\/URL you\u2019re visiting.<\/li>\n\n\n\n<li>The SSL certificate is currently valid and has not expired or been revoked.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If the certificate passes those checks, your browser will display the website, along with https:\/\/ and a padlock next to the URL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you look at our website\u2019s certificate, you\u2019ll see that it is issued by DigiCert. Our website\u2019s certificate includes a digital signature from DigiCert that your browser can use to verify the certificate is a valid and was issued by DigiCert.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"401\" height=\"272\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature.png\" alt=\"Digital signature on an SSL certificate.\" class=\"wp-image-13350 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature.png 401w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature-300x203.png 300w\" sizes=\"auto, (max-width: 401px) 100vw, 401px\" \/><figcaption>Digital signature on an SSL certificate.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll dive into more technical details later, but the main point for now is: your browser checks each website\u2019s HTTPS credentials, just like airport authorities check your passport before you can board an airplane.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"https-encryption-ensures-others-can\u2019t-spy-on-your-communications\">HTTPS Encryption Ensures Others Can\u2019t Spy on Your Communications<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The second thing that HTTPS does is encrypt all information that\u2019s sent between you and the website you\u2019re visiting. This ensures that nobody (other than you and the website you\u2019re connected to) can read your data as it\u2019s sent across the internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s use amazon.com again as an example. Say, you\u2019re shopping for a lovely <a href=\"https:\/\/www.amazon.com\/gp\/product\/B07FCG1HPG\/ref=as_li_tl?ie=UTF8&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B07FCG1HPG&amp;linkCode=as2&amp;tag=eathnoth06-20&amp;linkId=e6a8874d8f1bd7fb8832f6869aecca8e\">Nicholas Cage sequin pillow<\/a>:<\/p>\n\n\n<div class=\"wp-block-image addshadow\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"354\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-nicholas-cage.png\" alt=\"Nicolas cage example on amazon.com\" class=\"wp-image-13351\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-nicholas-cage.png 720w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/amazon.com-nicholas-cage-300x148.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">You want to place your order online, but security and privacy are very important to you. You don\u2019t want anyone to steal your credit card details, and perhaps more importantly you don\u2019t want anyone to know that you sleep with a Nicholas Cage pillow on your bed. (I won\u2019t judge you!)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because amazon.com uses HTTPS, that means all data sent to\/from amazon.com is encrypted before being sent. Let\u2019s a take a brief look at how HTTPS works on the encryption side\u2026<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"how-https-encryption-works\">How HTTPS Encryption Works<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In order to buy that Nicholas Cage pillow, you need to enter your credit card details:<\/p>\n\n\n<div class=\"wp-block-image addshadow\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"665\" height=\"281\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-https-works-amazon.com-credit-card-encryption.png\" alt=\"How HTTPS works for encryption on amazon.com\" class=\"wp-image-13354\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-https-works-amazon.com-credit-card-encryption.png 665w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-https-works-amazon.com-credit-card-encryption-300x127.png 300w\" sizes=\"auto, (max-width: 665px) 100vw, 665px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">When you enter your credit card numbers in the above field and click \u201cAdd your card,\u201d your credit card details are submitted to Amazon.com. But first, your browser will encrypt the data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The data is encrypted using an encryption key so only Amazon can unlock (decrypt) the data, and<\/li>\n\n\n\n<li>Your credit card (and other data) will look like gibberish to anyone who doesn\u2019t have the decryption key.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The data will travel across the internet in its encrypted (unreadable) state. Once it reaches amazon.com, Amazon would decrypt the data so it can read your credit card number to process your payment:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"492\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Encryption-Decryption-1024x492.png\" alt=\"Encryption and Decryption demonstrated\" class=\"wp-image-9953\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Encryption-Decryption-1024x492.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Encryption-Decryption-300x144.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Encryption-Decryption-768x369.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Encryption-Decryption.png 1251w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You might be wondering \u2014 what exactly is encrypted text (aka ciphertext)? Here\u2019s an example, showing actual encrypted data (as you can see, it\u2019s gibberish unless you have the decryption key to read it):<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Data you enter:<\/strong><\/td><td><strong>Encrypted data (ciphertext) that is sent over the internet:<\/strong><\/td><td><strong>After Amazon decrypts the data:<\/strong><\/td><\/tr><tr><td>1234123412341243<\/td><td>MHecmaRMbHdU8KRzY0h+n7n9<br>A3yR1ZJOBbY6PuEYRH0=<\/td><td>1234123412341243<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Encryption makes it safe to send encrypted data across the internet.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-https-encryption-doesn\u2019t-do\">What HTTPS Encryption Doesn\u2019t Do<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s one important distinction to make \u2014 HTTPS encryption only protects your data while it\u2019s traveling to the website (i.e. amazon.com in this case). Once the data reaches the website, it\u2019ll be decrypted and then it\u2019s up to the website owner what happens to your data from that point onward. That\u2019s why it\u2019s so important to only shop on websites you trust to protect your data after they receive it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is an advantage of OV\/EV SSL certificates. Because these certificates contain information about the organization that runs the website, it\u2019s easier for you to know exactly who you\u2019re sending your information to.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"but-wait\u2026-howwhy-would-anyone-be-spying-on-my-communications\">But Wait\u2026 How\/Why Would Anyone Be Spying on My Communications?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You might be wondering how anyone would spy on the data you\u2019re sending over the internet. If I\u2019m submitting something to amazon.com, how would anyone else even have the opportunity to see that? I\u2019m sending it directly to amazon.com, right?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Actually, no\u2026you\u2019re not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most people think that sending information online works something like this:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"463\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-not-private.png\" alt=\"Image Preview\" class=\"wp-image-13357 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-not-private.png 694w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-not-private-300x200.png 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><figcaption>Ah, an idyllic afternoon of relaxation and private conversation. (Not if you&#8217;re not using HTTPS!)<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cI\u2019m talking directly to the other party, and there\u2019s nobody else around to hear\u2026right?\u201d Not quite.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In reality, sending data over the internet is more like a game of telephone, where each party whispers the message to the next until it reaches your intended recipient. You have no idea how many people heard your message along the way or what they\u2019re doing with it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"463\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-like-telephone-game.png\" alt=\"Without HTTPS, anyone could be listening to your online communication.\" class=\"wp-image-13363\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-like-telephone-game.png 694w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/http-communication-is-like-telephone-game-300x200.png 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><figcaption class=\"wp-element-caption\">Without HTTPS, anyone could be listening to your online communication.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">When you send data across the internet, it\u2019s routed through dozens of DNS servers, routers, and waypoints\u2026 each controlled by different governments, ISPs, and other companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This <a href=\"https:\/\/cyber.harvard.edu\/digitaldemocracy\/week1\/followtheheader.html\">graphic shows the actual route data took<\/a> when sent between Harvard researchers in Ghana and Mongolia:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"512\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/harvard-internet-path.png\" alt=\"Harvard internet path graphic\" class=\"wp-image-13369\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/harvard-internet-path.png 738w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/harvard-internet-path-300x208.png 300w\" sizes=\"auto, (max-width: 738px) 100vw, 738px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As <a href=\"https:\/\/cyber.harvard.edu\/digitaldemocracy\/week1\/followtheheader.html\">one of the researchers pointed out<\/a>, that\u2019s more than 70 different computers owned by \u201cdozens and dozens of organizations, from Internet architects to ISPs, located in at least 20 different legal jurisdictions.\u201d It\u2019s pretty likely that there\u2019s one or more \u201cleaks\u201d along that route. For example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>One or more of those organizations has a computer that\u2019s been compromised by a hacker.<\/li>\n\n\n\n<li>One or more of the ISPs is collecting data for ad targeting and\/or selling to data aggregator companies.<\/li>\n\n\n\n<li>One of more of the countries has a spy\/intelligence program that collects data sent via the internet.<\/li>\n\n\n\n<li>One or more of the organizations has an insider threat (employee that\u2019s collecting\/selling data).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Fortunately, HTTPS encryption keeps your data safe, no matter who owns those 70+ computers along the way or what they try to do with the data that passes through. If your data is encrypted, those computers can\u2019t see or read the actual data you\u2019re sending.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"how-https-works-201-the-technical-details\">How HTTPS Works 201: The Technical Details<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">So, we\u2019ve covered what HTTPS does and how HTTPS works at a high level \u2014 now it\u2019s time to dive into the nitty-gritty details of how HTTPS works.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"http-vs-https\">HTTP vs. HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we alluded to before, HTTPS is simply the secure version of HTTP. You can think of it as HTTP communication that&#8217;s done over a secure channel. If you&#8217;re familiar with how HTTP works, the fundamentals work the same with HTTPS:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Request methods such as GET, POST, etc.<\/li>\n\n\n\n<li>HTTP status codes such as 200 (OK), 404 (File Not Found), etc.<\/li>\n\n\n\n<li>Request headers such as User-Agent, Accept, etc.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">One key difference to be aware of is that <a href=\"https:\/\/www.thesslstore.com\/blog\/introduction-to-http2-hypertext-transfer-protocol\/\">HTTP\/2<\/a> (a newer, faster version of HTTP) only works over HTTPS. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-https-works-under-the-hood-https-runs-on-pki\">How HTTPS Works Under the Hood: HTTPS Runs on PKI<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before we can dive deeper into how HTTPS works, we need to go over a few technical details of the system that HTTPS, SSL, and TLS are all built on top of \u2014 <a href=\"https:\/\/www.thesslstore.com\/blog\/how-pki-works\/\">public key infrastructure<\/a>, or PKI. Just like your car runs on an internal combustion engine, HTTPS and TLS\/SSL run using PKI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PKI is a system made up of five main components, including:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>Digital certificates (i.e. SSL certificates).<\/li>\n\n\n\n<li>Public &amp; private key pairs.<\/li>\n\n\n\n<li>Certificate authorities.<\/li>\n\n\n\n<li>Digital signatures.<\/li>\n\n\n\n<li>Root stores.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s briefly cover how each of these work, so you can better understand how HTTPS works.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"digital-certificates\">Digital Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We already covered these \u2014 they\u2019re like passports for organizations\/websites.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"public-keys-amp;-private-keys\">Public Keys &amp; Private Keys<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">First, quick review: when we encrypt data, we use an encryption key to turn readable text into unreadable text (called ciphertext), like this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hello! &gt;&gt;&gt; Encrypted with key \u201cmykey\u201d &gt;&gt;&gt; HgPpAhtl<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We can do the same in reverse to decrypt the ciphertext:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HgPpAhtl &gt;&gt;&gt; Decrypted with key \u201cmykey\u201d &gt;&gt;&gt; Hello!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Notice that we\u2019re using the same key to encrypt and decrypt the text? That\u2019s called symmetric encryption. Asymmetric encryption is a bit different\u2014it uses two different keys, one for encryption and one for decryption:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The public key (used for encryption) is given out freely for anyone to use to send you an encrypted message.<\/li>\n\n\n\n<li>You keep the private key (used for decryption) so you\u2019re the only one who can read the encrypted messages.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/symmetric-encryption-101-definition-how-it-works-when-its-used\/\">Symmetric encryption<\/a> uses the same private key for encryption and decryption, whereas asymmetric encryption uses a public\/private key pair:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large addshadow\"><img loading=\"lazy\" decoding=\"async\" width=\"934\" height=\"474\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/08\/Asymmetric-vs-Symmetric.png\" alt=\"Asymmetric vs Symmetric: two different types of encryption\" class=\"wp-image-10668\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/08\/Asymmetric-vs-Symmetric.png 934w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/08\/Asymmetric-vs-Symmetric-300x152.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/08\/Asymmetric-vs-Symmetric-768x390.png 768w\" sizes=\"auto, (max-width: 934px) 100vw, 934px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s critical for SSL\/TLS to work. If you have amazon.com\u2019s certificate and public key, you can send a message that only amazon.com can read. (This, by extension, also means that you can easily confirm that the server you\u2019re talking to is actually amazon.com. If they can understand a message encrypted with amazon.com\u2019s public key, that means they have amazon.com\u2019s private key\u2026which must mean they are amazon.com!)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To learn more check out our blog post on <a href=\"https:\/\/www.thesslstore.com\/blog\/difference-asymmetric-encryption-algorithms-vs-symmetric-encryption-algorithms\/\">asymmetric and symmetric encryption<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"certificate-authorities\">Certificate Authorities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We already covered these above \u2014 remember, certificate authorities are companies that are trusted to issue SSL certificates.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"digital-signatures\">Digital Signatures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Digital signatures are a way of proving who\/where a piece of software or document came from. If you have an author\u2019s public key, you can verify anything they signed with their private key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is critical, because this is how your browser can tell which certificate authority really issued an SSL certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s go back to the SSL certificate for our website, thesslstore.com. That certificate was issued by DigiCert, so it has DigiCert\u2019s digital signature on the SSL certificate:<\/p>\n\n\n<div class=\"wp-block-image addshadow\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"401\" height=\"272\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature.png\" alt=\"Digital signature on an SSL certificate\" class=\"wp-image-13350\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature.png 401w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-digital-signature-300x203.png 300w\" sizes=\"auto, (max-width: 401px) 100vw, 401px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">If your browser has DigiCert\u2019s public key, it can verify that our certificate really was issued by DigiCert.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, this raises an important question\u2026 does your browser have DigiCert\u2019s public key?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"root-stores\">Root Stores<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In order to verify a website\u2019s SSL certificate, your browser will need the certificate authority\u2019s public key. Fortunately, there\u2019s a system setup for that \u2014 root stores.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every device has what\u2019s called a root store or trust store. The root store contains the digital certificates and associated public keys of every certificate authority that it trusts. Every device comes with a default <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-certificate-authority-list-and-where-can-i-find-one\/\">list of certificate authorities<\/a> that it trusts \u2014 you can modify this list if you want, but very few people do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s look at the certification path for our SSL certificate. Note that there are three certificates:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"443\" height=\"184\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/ssl-certification-path.png\" alt=\"Certification Path for www.thesslstore.com SSL certificate\" class=\"wp-image-13373\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/ssl-certification-path.png 443w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/ssl-certification-path-300x125.png 300w\" sizes=\"auto, (max-width: 443px) 100vw, 443px\" \/><figcaption class=\"wp-element-caption\">Certification Path for www.thesslstore.com&#8217;s SSL certificate<\/figcaption><\/figure>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>The top certificate, \u201cDigiCert\u201d is the root certificate. That certificate should be pre-loaded on your computer, in your device\u2019s root store.<\/li>\n\n\n\n<li>The middle certificate is called the intermediate certificate\u2014it\u2019s digitally signed by the \u201cDigiCert\u201d root certificate so your browser will also trust it. Your browser can verify the signature using the DigiCert\u2019s public key, which is pre-loaded on your computer as part of the root certificate.<\/li>\n\n\n\n<li>The bottom certificate \u201c<a href=\"http:\/\/www.thesslstore.com\">www.thesslstore.com<\/a>\u201d is our website\u2019s SSL certificate \u2014 our web server sent it to your browser when you connected. Your browser can verify it using the intermediate certificate\u2019s digital signature.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">These three certificates together are called the \u201cchain of trust\u201d and are how your browser can verify any website\u2019s SSL certificate to ensure it is valid and trusted.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"how-https-works-for-website-owners-how-to-enable-https-on-your-website\">How HTTPS Works for Website Owners: How to Enable HTTPS on Your Website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OK, so know you understand the basic components of PKI, and you want to enable HTTPS on your website. Let\u2019s cover how you can do that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All popular web servers (such as Apache, NGINX, and IIS) and website control panels (such as cPanel or Plesk) include support for HTTPS, so you don\u2019t need to build or install custom software to handle HTTPS communication. You just need to install an SSL certificate for your website then update your site settings to use HTTPS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"step-1-acquire-an-ssltls-certificate\">Step 1: Acquire an SSL\/TLS Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Your SSL certificate proves that your website (let\u2019s say yoursite.com) is the real yoursite.com. You need to get an SSL certificate issued by a trusted certificate authority. If you acquire a certificate from a certificate authority that your website visitor\u2019s browser doesn\u2019t automatically trust, they\u2019ll see a warning message like this.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"701\" height=\"472\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-untrusted-warning.png\" alt=\"HTTPS warning for untrusted certificate.\" class=\"wp-image-13375\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-untrusted-warning.png 701w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-untrusted-warning-300x202.png 300w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><figcaption class=\"wp-element-caption\">HTTPS doesn&#8217;t work if your certificate isn&#8217;t trusted.<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Tip: All of the SSL certificates sold on thesslstore.com are trusted by all modern browsers, operating systems, and devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are a few steps you\u2019ll need to complete to get your SSL certificate. Fortunately, these can be done in as little as a few minutes:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Generate a certificate signing request (CSR).<\/strong>&nbsp;You can usually do this in your web hosting control panel. This also generates the public key and private key that are required for HTTPS to work. Tip: our knowledgebase provides&nbsp;<a href=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-generate\/\">CSR generation guides for 20+ different hosting platforms and server types<\/a>. This screenshot shows what the CSR generation form looks like in cPanel:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"646\" height=\"572\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-csr.png\" alt=\"Generate a new CSR in cPanel\" class=\"wp-image-13377\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-csr.png 646w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-csr-300x266.png 300w\" sizes=\"auto, (max-width: 646px) 100vw, 646px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Submit the certificate signing request to your SSL provider \/ certificate authority.<\/strong> Once you submit the CSR, the certificate authority will begin the process required to issue an SSL certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Complete the certificate authority\u2019s validation process.<\/strong> This will vary depending on the type of certificate you\u2019ve purchased, but at minimum you\u2019ll need to prove that you own\/manage your domain. See our <a href=\"https:\/\/www.thesslstore.com\/new-to-ssl\/ssl-authentication-levels.aspx\">SSL validation guide<\/a> for more details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you\u2019ve completed those steps, the certificate authority will send your SSL certificate to you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"step-2-install-the-ssl-certificate-on-your-website\">Step 2: Install the SSL Certificate on Your Website<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now that you have your SSL certificate, you\u2019ll need to install it on your website. Again, you can usually do this using your web hosting control panel. Here\u2019s what the installation form looks like for cPanel:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"760\" height=\"559\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-install.png\" alt=\"Install an SSL certificate in cPanel\" class=\"wp-image-13376\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-install.png 760w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/cpanel-ssl-install-300x221.png 300w\" sizes=\"auto, (max-width: 760px) 100vw, 760px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Tip: See our knowledgebase for <a href=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-install\/\">installation guides for 20+ server and web hosting platforms<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"step-3-change-your-site-settings-to-use-https\">Step 3: Change Your Site Settings to Use HTTPS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019ve installed the SSL certificate on your website, so your website is now capable of using HTTPS. Now you just need to tell your website that you want it to use HTTPS every time (not HTTP).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How to do this will depend on how your website is set up, but you need to do three things:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>Change your website CMS to use https:\/\/ for all pages.<\/li>\n\n\n\n<li>Setup 301 redirects pointing http:\/\/ URLs to the same URL on https:\/\/.<\/li>\n\n\n\n<li>Be sure that all images, CSS files, Javascript files, etc. are loaded with https:\/\/ URLs.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Now that you\u2019ve setup HTTPS on your website, visitors to your website will be able to enjoy the benefits of HTTPS: authentication and encryption. But how does HTTPS work to do that at the technical level? Let\u2019s dive in deeper, but first\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-https-works-for-website-users-the-tls-handshake\">How HTTPS Works for Website Users: The TLS Handshake<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we covered in the first part of this article, when you visit an HTTPS website, your browser is authenticating the website and encrypting the data sent to and from the client:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large addshadow\"><img loading=\"lazy\" decoding=\"async\" width=\"743\" height=\"338\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does.png\" alt=\"How HTTPS Works - Two Things\" class=\"wp-image-13331\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does.png 743w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works-the-two-things-HTTPS-does-300x136.png 300w\" sizes=\"auto, (max-width: 743px) 100vw, 743px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To do that, your browser and the website server need to create a secure connection to communicate through. Setting up the secure connection is a process called the SSL\/TLS handshake.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"creating-a-secure-connection-with-the-ssltls-handshake\">Creating a Secure Connection with the SSL\/TLS Handshake<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">So, you\u2019ve typed https:\/\/www.amazon.com into your browser bar \u2014 how does your browser setup a secure HTTPS connection to amazon.com? Technically speaking, HTTPS is the same as HTTP except the communication happens over a secure SSL\/TLS connection. To set up that secure SSL\/TLS connection, your browser and the server need to go through what is called the SSL\/TLS handshake process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note: In this article, we\u2019ll be covering the basics of the TLS 1.2 handshake process (it\u2019s the most commonly used). If you want a more detailed coverage, including how the newer (and faster) TLS 1.3 handshake works, check out our article <a href=\"https:\/\/www.thesslstore.com\/blog\/explaining-ssl-handshake\/\">Taking a Closer Look at the SSL\/TLS Handshake<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following illustration shows all of the steps of the TLS handshake (how your browser and server setup a secure connection). The client (your browser) is on the left, and the web server is on the right:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"809\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/SSL_Handshake_10-Steps.gif\" alt=\"TLS SSL Handshake for HTTPS\" class=\"wp-image-3359\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s go over what happens in these steps:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"steps-1-2-hello-amp;-cipher-suites\">Steps 1-2: Hello &amp; Cipher Suites!<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The browser and server say hello and agree on which cipher suite (encryption algorithm) to use. (HTTPS\/SSL\/TLS supports multiple cipher suites.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Fun fact:<\/strong> Some browsers (such as Firefox) let you easily see what cipher suite your connection to a specific website uses. In Firefox, click the padlock, then click the \u201c&gt;\u201d, then click \u201cMore Information\u201d to see information like this:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"626\" height=\"146\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/firefox-https-cipher-suite.png\" alt=\"How HTTPS Works: HTTPS Cipher in Firefox\" class=\"wp-image-13378\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/firefox-https-cipher-suite.png 626w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/firefox-https-cipher-suite-300x70.png 300w\" sizes=\"auto, (max-width: 626px) 100vw, 626px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to know how to interpret what that info means, check out our article on <a href=\"https:\/\/www.thesslstore.com\/blog\/cipher-suites-algorithms-security-settings\/\">Cipher Suites: Ciphers, Algorithms and Negotiating Security Settings<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"steps-3-5-certificate-amp;-key-exchange\">Steps 3-5: Certificate &amp; Key Exchange<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The server sends its SSL certificate and intermediate certificate, along with the associated public keys, to the browser. As covered above in the \u201cPKI\u201d section, the browser will verify the SSL certificate based on its digital signature and the root certificates the browser trusts. If any of the checks fail, the connection will abort and an error message will display.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Provided that none of the checks fail, at this point, we technically have a secure communication channel:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The browser has verified the web server\u2019s SSL certificate, so the web server has been authenticated.<\/li>\n\n\n\n<li>The browser now has the server\u2019s public key, so the browser can encrypt messages that can only be read by the server.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But the connection can only be used securely one way (browser &#8211;&gt; server), so we\u2019re not done yet\u2026<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"steps-6-10-setting-up-symmetric-encryption\">Steps 6-10: Setting Up Symmetric Encryption<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">It turns out that symmetric encryption (using the same key for encryption and decryption) is actually more efficient, so the browser and server will now create a new, shared encryption key that they can use for encryption and decryption moving forward. (Exactly how the browser and server create a shared session key depends on the cipher suite [encryption methods] being used.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the session key is generated, the TLS handshake process completes. Your browser and the server will use the session key to encrypt and decrypt all data that they exchange.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Congratulations, your browser now has a two-way secure communication channel for secure HTTPS communication with the web server. You can send <em>and<\/em> receive data securely, without worrying about someone in-route spying on your info.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"handy-https-usage-tips-for-users\">Handy HTTPS Usage Tips For Users<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now you know about what HTTPS does and even the technical details of how HTTPS works. Here are a few practical tips and things to keep in mind when visiting HTTPS websites.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"google-chrome-hides-the-https\">Google Chrome Hides the HTTPS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re using Chrome as your browser, keep in mind that Google actually hides the https:\/\/ part of the URL. Here are three quick ways you can verify if a webpage is HTTPS:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Look for the padlock:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"268\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-padlock-chrome.png\" alt=\"How HTTPS works: showing the padlock\" class=\"wp-image-13379\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-padlock-chrome.png 669w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-padlock-chrome-300x120.png 300w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Double click on the URL to see the https:\/\/:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"435\" height=\"251\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-https-url.png\" alt=\"How HTTPS Works - check for https:\/\/\" class=\"wp-image-13381\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-https-url.png 435w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/thesslstore-https-url-300x173.png 300w\" sizes=\"auto, (max-width: 435px) 100vw, 435px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Make sure there isn\u2019t a \u201cNot Secure\u201d label:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"387\" height=\"120\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/not-secure-chrome-example-http.png\" alt=\"Not secure warning in Chrome (not HTTPS)\" class=\"wp-image-13382\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/not-secure-chrome-example-http.png 387w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/not-secure-chrome-example-http-300x93.png 300w\" sizes=\"auto, (max-width: 387px) 100vw, 387px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"you-can-verify-company-details-using-their-ssl-certificate\">You Can Verify Company Details Using Their SSL Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As we alluded to earlier, some websites\u2019 SSL certificates contain verified company details so you can identify the exact company that runs the website. This can be useful to avoid scam websites or simply to have greater transparency on who you\u2019re dealing with online. (With so many companies having dozens of websites out there, sometimes it\u2019s hard to figure out which ones are official websites and which ones aren\u2019t.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the website has an EV SSL certificate, you can view the company details by just clicking on the padlock:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"474\" height=\"405\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details.png\" alt=\"How HTTPS works: showing company details on EV SSL certificates\" class=\"wp-image-13383\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details.png 474w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details-300x256.png 300w\" sizes=\"auto, (max-width: 474px) 100vw, 474px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If the website has an OV SSL certificate, you\u2019ll need to open up the SSL certificate details and view the subject field:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"441\" height=\"440\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details-ov.png\" alt=\"Viewing company details with OV SSL certificates\" class=\"wp-image-13384\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details-ov.png 441w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-company-details-ov-300x300.png 300w\" sizes=\"auto, (max-width: 441px) 100vw, 441px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This information has been verified by the certificate authority, so it can\u2019t be faked. This is why it\u2019s crucial for businesses that handle sensitive data to use SSL\/TLS certificates with organizational validation as a minimum.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"be-very-careful-proceeding-past-an-https-warning\">Be Very Careful Proceeding Past an HTTPS Warning<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you visit a website and see a warning like this, it may be tempting to just click past the warning to get to the website you\u2019re trying to visit. But be very careful doing this \u2014 it can trigger warnings like this when a hacker is performing a <a href=\"https:\/\/www.thesslstore.com\/blog\/man-in-the-middle-attack\/\">man-in-the-middle (MitM) attack<\/a> on your connection. (For example, showing you a fake website that looks like the real website you\u2019re trying to visit.)<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"685\" height=\"481\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-man-in-the-middle-attack-example.png\" alt=\"\" class=\"wp-image-13385\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-man-in-the-middle-attack-example.png 685w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/https-man-in-the-middle-attack-example-300x211.png 300w\" sizes=\"auto, (max-width: 685px) 100vw, 685px\" \/><figcaption class=\"wp-element-caption\">This is an HTTPS error that could indicate a man-in-the-middle or DNS attack.<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In many cases, these errors are triggered due to the website letting its certificate expire or not configuring their server correctly. But occasionally they\u2019re for a more sinister reason \u2014 a hacker is trying to spy on your connection or trick you!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"so\u2026that\u2019s-how-https-works\">So\u2026That\u2019s How HTTPS Works<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">I hope you\u2019ve found this article useful. There are a ton of details we could cover on how HTTPS works, we tried to make this article accessible and easy to understand, while still covering the important details. Hopefully, you found the level of detail \u201cjust right\u201d (like Goldilocks\u2019 porridge)!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Still have more questions about \u201chow does HTTPS work?\u201d Or do you have suggestions for additional details we should include or points we can further clarify? Drop a note in the comments!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We all know that HTTPS = secure. But do you know how HTTPS works under the hood? Let\u2019s take a look at how HTTPS works to make the internet safer&#8230;<\/p>\n","protected":false},"author":23,"featured_media":13389,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,10200],"tags":[13053,170],"class_list":["post-13324","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-monthly-digest","tag-how-https-works","tag-https","post-with-tags"],"views":49372,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/10\/how-HTTPS-works.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=13324"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13324\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13389"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=13324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=13324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=13324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}