DIFFERENCE BETWEEN
SSL, TLS
AND HTTPS
When I first learned about web security, I honestly thought SSL, TLS, and HTTPS were just different names for the same thing.
People said things like:
“Make sure your site uses SSL”
“We already use HTTPS”
“TLS is more secure than SSL”
My brain just nodded politely without really understanding.
The Simple Mental Model
Think of sending a message from your browser to a website.
- check_circle SSL / TLS → How the message is locked
- check_circle HTTPS → The rule that says “this website must use a lock”
SSL (Secure Sockets Layer) — the old lock
SSL was the original technology created to secure communication between:
- check_circle Your browser
- check_circle Server
Before SSL, data was sent as plain text. That means if you typed:
username=joekawai
password=penghutanghandal
Anyone listening on the network could read it. That’s scary.
SSL introduced:
- check_circle Encryption (scrambling the data)
- check_circle Server authentication
- check_circle Data integrity
Versions like: SSL 2.0, SSL 3.0 are no longer secure and have been officially deprecated.
TLS (Transport Layer Security) — the modern lock
TLS is the successor to SSL. TLS ensures:
- check_circle 🔒 Data is encrypted
- check_circle ✅ The server is who it claims to be
- check_circle 🔄 Data isn’t changed in transit
Real-life analogy
Imagine sending a letter:
- check_circle SSL → an old lock that thieves now know how to open
- check_circle TLS → a modern lock that’s much harder to break
Even though TLS is what’s used today, people still casually say “SSL certificate” out of habit.
HTTPS - the rule, not the lock
Now here’s where many beginners get confused.
HTTPS = HTTP + TLS. That’s it.
When you visit: https://sawit.com
It means: “This website must communicate using HTTP over TLS encryption.”
What happens behind the scenes
- check_circle Browser connects to the server
- check_circle TLS handshake happens
- check_circle Encryption keys are agreed
- check_circle Only then HTTP data is sent
You never see TLS directly but HTTPS guarantees it’s there.
Example
Let’s say you log in to a website.
Using HTTP
POST /login
username=joekawai
password=penghutanghandal
Anyone on the network can read this.
Using HTTPS (HTTP + TLS)
POST /login
username=******
password=******
Data is encrypted, and even if intercepted, it’s unreadable.
Why browsers show a lock icon
- check_circle The site is using HTTPS
- check_circle The TLS certificate is valid
- check_circle Your connection is encrypted
If the lock is missing or red, something is wrong, don’t enter passwords.