HTTP vs HTTPS: What difference does it make to security?

We look at the difference between the two and tell you how to switch between them

HTTPS browser

Web users may have noticed over the last year or so more and more web addresses shifting from HTTP to HTTPS. These two main methods for transferring data across the internet and the World Wide Web are known as the Hypertext Transfer Protocol (HTTP) and the Hypertext Transfer Protocol Secure (HTTPS).

Advertisement - Article continues below

As you might well imagine, HTTPS has added an extra layer of security to web browsing than HTTP, with anybody and everybody’s browsing data now protected through encryption. The traditional HTTP method transmitted information as clear for all to see as if it was jotted down onto a piece of paper. 

The new protocol uses secure socket layer (SSL) and transport layer security (TLS) to encrypt any information being transmitted, meaning that it’s relatively difficult, if not impossible, to read if and when intercepted. Any attackers hoping to glean information from such data will instead be met with garbled letters and numbers.

HTTPS was traditionally used to protect highly sensitive information, such as online payments since it was conceived 26 years ago by Netscape for the Netscape Navigation web browser. In recent history, however, it’s been rolled out to almost all online platforms and has overtaken HTTP as the most common method of web-based data transfer.

What are the benefits of HTTPS over HTTP?

As mentioned above, using HTTP means data is transmitted in plain text. This means that if someone were to intercept that data while it's in transit known as a man-in-the-middle attack they would be able to see all of it without putting in any additional effort.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

HTTPS, meanwhile, uses public key encryption via SSL/TLS to thwart this kind of attack.

Network services provider Cloudflare gives the following example: When using HTTP to send the message "Hello World!", the attacker would see exactly that, plus some additional information about the server, when the text was created and so on.

With HTTPS, it would see something like the following:

t8Fw6T8UV81pQfyhDkhebbz7+oiwldr1j2gHBB3L3RFTRsQCpaSnSBZ78Vme+DpDVJPvZdZUZHpzbbcqmSW1+3xXGsERHg9YDmpYk0VVDiRvw1H5miNieJeJ/FNUjgH0BmVRWII6+T4MnDwmCMZUI/orxP3HGwYCSIvyzS3MpmmSe4iaWKCOHQ==

Additionally, in order for a website to have the SSL certificate that enables it to use HTTPS, the domain must be verified to check that it belongs to the website owner and in some cases, legal certificates must be presented to verify everything is in order.

HTTPS will also improve a website's ranking on Google, only the best and most secure get to feature on the first page and statistics show that 84% of shopper will abandon a purchase if they don't see the little green padlock next to the URL.

How to switch from HTTP to HTTPS

If you're not yet using HTTPS to secure your website, it's time to talk to your hosting company, which should issue and install an SSL certificate for you, redirecting your traffic from the HTTP to the https version with little effort.

Advertisement - Article continues below

If this isn't the case, there are plenty of third-party companies that you can purchase an SSL certificate from and then manually set it up on your FTP. You will then need to set up a redirect to tell browsers trying to access the HTTP version of the site to HTTPS.

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Most Popular

Visit/software/video-conferencing/355257/taiwan-first-country-to-ban-zoom-amid-security-concerns
video conferencing

Taiwan becomes first country to ban Zoom amid security concerns

8 Apr 2020
Visit/security/cyber-security/355271/microsoft-gobbles-up-corpcom-domain-to-keep-it-from-hackers
cyber security

Microsoft gobbles up corp.com domain to keep it from hackers

8 Apr 2020
Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020