Lesson 12 / الدرس 12
HTTPS: what the padlock means / HTTPS: ماذا يعني القفل
The s is one letter and a whole extra conversation. It buys you three specific guarantees — and it is worth knowing exactly which three, because people expect a fourth it never gave.
حرف s حرف واحد ومحادثة كاملة إضافية. وهو يشتري لك ثلاث ضمانات بعينها — ويستحق أن تعرف أيها بالضبط، لأن الناس ينتظرون رابعة لم يقدّمها قط.
Everything in the last five lessons travelled as plain text. A request, a response, headers, a password in a form body — all of it readable by anyone the message passes through: the café network, the internet provider, every machine along the route. HTTPS is HTTP sent through an encrypted tunnel, and the tunnel is built by a protocol called TLS.
Three guarantees, and one it does not make
-
Nobody can read it. The message is encrypted between your browser and that server. Everyone in between sees noise. لا أحد يستطيع قراءتها. فالرسالة مشفّرة بين متصفحك وذلك الخادم. وكل من بينهما يرى ضجيجًا.
-
Nobody can change it. If a single byte is altered on the way, the other end can tell and rejects the message rather than acting on it. لا أحد يستطيع تغييرها. فإن بُدّل بايت واحد في الطريق، عرف الطرف الآخر ورفض الرسالة بدل أن يعمل بها.
-
You are talking to the right machine. The server proves it really is that name, which is what the certificate in lesson 13 is for. أنت تحادث الجهاز الصحيح. فالخادم يثبت أنه فعلًا ذلك الاسم، وهذا ما وُجدت له الشهادة في الدرس 13.
How two strangers agree on a secret
The awkward part of encryption is that both sides need the same key, and the only channel available for agreeing on one is the very channel being watched. TLS solves it with two kinds of key. Every server has a public key it gives to anyone and a private key it never shares; anything locked with the public one can only be opened by the private one.
1. Client: hello — here are the ciphers I speak
2. Server: hello — let us use this one; here is my certificate
3. Client: (checks the certificate, then agrees a shared key using the public key)
4. Both: from here on, everything is encrypted with that shared key
5. Client: GET /lesson/web/https-and-tls HTTP/1.1 ← finally, the request
The two-key method is slow, so it is used only for step 3 — agreeing on an ordinary shared key. Everything afterwards uses that fast shared key. This is why the first visit to a site costs a few extra round trips and later requests do not.
Check yourself / اختبر نفسك
1. A site shows a padlock. What have you been told?
Privacy and identity, not integrity of intent. A fraudulent site can hold a perfectly valid certificate for its own name.
2. When does the HTTP request itself get sent?
The tunnel is built first and the request travels inside it. That is exactly why the path, headers and body are hidden while the host is not.
3. Why does TLS use two kinds of key instead of one?
The public and private pair solves the agreement problem; it is slow, so it is used once and then set aside for the fast shared key.
Score / النتيجة: 0 / 3