Limited Offer

30% OFF Lifetime Access ($139) with code SYSTEM30

TOPIC #6Beginner 6 min read

HTTP/HTTPS Fundamentals

💡
Core Architecture Summary

Understand the application protocol powering the World Wide Web, including plaintext HTTP vulnerabilities, TLS encapsulation, and status semantics.

Key Glossary Concepts in this TopicAll Glossary Terms

HTTP vs HTTPS Protocol Security Comparison 🔒

How TLS encapsulates application HTTP data inside an encrypted tunnel over TCP.

HTTP vs HTTPS Protocol Security Comparison 🔒
100%
Rendering visual architecture flowchart...

01.1. What is HTTP (Hypertext Transfer Protocol)?

HTTP is an application-layer request-response protocol running over reliable transport (TCP or QUIC). It is inherently stateless, meaning each request is executed independently without the server retaining context between requests unless explicitly tracked via cookies, tokens, or sessions.

An HTTP/1.1 request is human-readable ASCII text. When you open a raw TCP socket to port 80 and send:

GET /api/users HTTP/1.1\r\nHost: api.example.com\r\nAccept: application/json\r\n\r\n

The server receives this literally as plaintext bytes — no encryption, no obfuscation. Every router, switch, ISP, and network tap along the path can read every byte.

02.2. Why HTTPS (HTTP Secure) is Mandatory

Plaintext HTTP transmits raw bytes across routers, switches, and ISPs. Anyone along the path can perform eavesdropping (packet sniffing) or tampering (Man-in-the-Middle injection).

HTTPS wraps HTTP requests inside TLS (Transport Layer Security), providing 3 critical guarantees:

  1. Confidentiality: Payloads are encrypted symmetrically (AES-256-GCM or ChaCha20-Poly1305). Even if captured, the bytes are cryptographically unreadable without the session key.
  2. Integrity: HMAC message authentication codes verify that packets were not altered or injected in flight. A single bit flip causes authentication failure and connection termination.
  3. Authentication: X.509 Certificates (signed by a trusted Certificate Authority) verify that you are talking to the real server, not an impersonator with the same domain name.

03.3. HTTP/2 and HTTP/3: Evolution of the Protocol

HTTP/1.1 (1997): One request per TCP connection (or pipelined, with HOL blocking). Textual headers repeat on every request.

HTTP/2 (2015): Binary framing layer over TLS/TCP. Key improvements:

  • Multiplexing: Multiple streams (requests) share a single TCP connection without HOL blocking at the HTTP layer.
  • Header Compression (HPACK): Repeating headers like Authorization or Accept-Encoding are compressed, reducing overhead by 30-50%.
  • Server Push: Server can proactively send resources (e.g., CSS files) before the client requests them.

HTTP/3 (2022): Runs on QUIC (UDP-based). Key improvements over HTTP/2:

  • No TCP HOL blocking: Each stream is independent; packet loss on stream 1 does not block stream 2.
  • 0-RTT connection establishment: Returning clients can send data in the first packet.
  • Connection migration: Sessions survive WiFi ↔ Cellular handoffs (perfect for mobile).

As of 2024, ~30% of web traffic uses HTTP/3 (Google, Facebook, Cloudflare).

04.4. HSTS — HTTP Strict Transport Security

HSTS instructs browsers to always use HTTPS for a domain, even if the user types http:// in the address bar. The server sends this header:

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

This means: remember to use HTTPS for this domain for the next 1 year (31,536,000 seconds), including all subdomains.

HSTS Preload List: A hardcoded list inside Chrome, Firefox, Safari, and Edge containing thousands of domains that must always use HTTPS, even on the very first visit — before the server has a chance to send an HSTS header. This is the ultimate protection against SSL-stripping attacks on new connections.

Submit your domain at https://hstspreload.org to join the preload list (requires max-age ≥ 1 year and includeSubDomains).

⚖️Architectural Trade-offs & Production Realities

Architectural Advantages

  • Complete end-to-end privacy and data protection
  • Mandatory for modern browser APIs (Service Workers, Geolocation, HTTP/2)
  • HTTP/3 eliminates TCP head-of-line blocking for mobile users

Trade-offs & Constraints

  • Minor initial handshake CPU and latency overhead (mitigated by TLS 1.3 0-RTT session resumption)
  • Certificate management and renewal adds operational complexity (mitigated by Let's Encrypt / ACM automation)
Production Implementation in Big Tech
Stripe• Payment Processing APIs

Stripe mandates TLS 1.2+ for all incoming API calls, rejecting outdated cipher suites to guarantee PCI-DSS Tier 1 compliance during credit card tokenization.

🎯 Staff+ Engineering Takeaways

  • HTTP is stateless; HTTPS = HTTP + TLS encryption.
  • HTTPS provides Confidentiality, Integrity, and Server Authentication.
  • Port 80 = HTTP, Port 443 = HTTPS.
  • HTTP/2 adds multiplexing and header compression over TLS/TCP.
  • HTTP/3 (QUIC) runs over UDP, eliminating TCP head-of-line blocking.
  • HSTS + Preload List prevents SSL-stripping attacks on first connections.

Topic Knowledge Assessment 🧠

Step through 1 scenario question to test your staff-level grasp.

Question 1 of 10 answered
#1

Which of the following is NOT one of the core security guarantees provided by HTTPS/TLS?

Rate This Architecture Chapter4.9 / 5.0 (38 ratings)

How clear and staff-actionable was this system breakdown?