Lesson 12 / الدرس 12

HTTPS: what the padlock means / HTTPS: ماذا يعني القفل

The s is one letter and a whole extra conversation. It buys you three specific guarantees — and it is worth knowing exactly which three, because people expect a fourth it never gave.

حرف s حرف واحد ومحادثة كاملة إضافية. وهو يشتري لك ثلاث ضمانات بعينها — ويستحق أن تعرف أيها بالضبط، لأن الناس ينتظرون رابعة لم يقدّمها قط.

Everything in the last five lessons travelled as plain text. A request, a response, headers, a password in a form body — all of it readable by anyone the message passes through: the café network, the internet provider, every machine along the route. HTTPS is HTTP sent through an encrypted tunnel, and the tunnel is built by a protocol called TLS.

Three guarantees, and one it does not make

  1. Nobody can read it. The message is encrypted between your browser and that server. Everyone in between sees noise.
  2. Nobody can change it. If a single byte is altered on the way, the other end can tell and rejects the message rather than acting on it.
  3. You are talking to the right machine. The server proves it really is that name, which is what the certificate in lesson 13 is for.

How two strangers agree on a secret

The awkward part of encryption is that both sides need the same key, and the only channel available for agreeing on one is the very channel being watched. TLS solves it with two kinds of key. Every server has a public key it gives to anyone and a private key it never shares; anything locked with the public one can only be opened by the private one.

1. Client:  hello — here are the ciphers I speak
2. Server:  hello — let us use this one; here is my certificate
3. Client:  (checks the certificate, then agrees a shared key using the public key)
4. Both:    from here on, everything is encrypted with that shared key
5. Client:  GET /lesson/web/https-and-tls HTTP/1.1   ← finally, the request
The handshake, in the order it happens. Notice that the HTTP request from lesson 7 does not appear until step 5 — every earlier lesson in this course describes what happens after this is already finished.

The two-key method is slow, so it is used only for step 3 — agreeing on an ordinary shared key. Everything afterwards uses that fast shared key. This is why the first visit to a site costs a few extra round trips and later requests do not.

Check yourself / اختبر نفسك

1. A site shows a padlock. What have you been told?

2. When does the HTTP request itself get sent?

3. Why does TLS use two kinds of key instead of one?