HTTPS = HTTP + TLS
TLS, transport layer security, is the cryptographic protocol that builds an encrypted channel between the client, normally a browser, and the server. It gives three guarantees:
- Confidentiality — the data is encrypted, so intercepted traffic is unreadable
- Integrity — the data cannot be altered in transit without detection
- Authentication — the certificate confirms the server is who it claims to be
The TLS handshake happens on every new connection: certificates are exchanged, algorithms negotiated, session keys generated. After that all traffic is encrypted with symmetric session keys.
TLS 1.2 against TLS 1.3
| Property | TLS 1.2 | TLS 1.3 |
|---|---|---|
| Round trips to establish a connection | 2 RTT | 1 RTT, or 0-RTT on resumption |
| Cipher suites | Broad, including obsolete ones | Only modern, safe ones |
| Browser support | All current browsers | All current browsers since 2019 |
TLS 1.3 is both faster and safer and is the sensible minimum for new deployments. TLS 1.0 and 1.1 are obsolete and disabled in most browsers.
Practical requirements for e-commerce
Certificates
- Let’s Encrypt — free certificates with automatic renewal through Certbot, enough for most cases
- Wildcard (
*.example.com) — one certificate covering every subdomain - EV (extended validation) — for large retailers; it shows the company name in the browser bar (hidden in Chrome since 2019, still supported elsewhere)
- Expiry: track it automatically — a lapsed certificate blocks access to the site outright
Mixed content — the usual sources
<!-- Bad — loaded over HTTP on an HTTPS page -->
<img src="http://cdn.example.com/image.jpg">
<script src="http://analytics.example.com/tag.js"></script>
<!-- Good — a protocol-relative URL -->
<img src="//cdn.example.com/image.jpg">
<!-- Good — explicit HTTPS -->
<img src="https://cdn.example.com/image.jpg">
APIs and personalization
Every call to an external API — personalization, analytics, search — has to go over HTTPS. That is especially critical for:
– Sending API keys and authorisation tokens
– Event data: views, add-to-cart events, purchases
– A/B testing, where the data says which group a visitor belongs to
Important: never pass API keys or tokens in URL parameters — they end up in server logs, browser history and Referer headers. Use the
AuthorizationorX-API-Keyheaders over HTTPS and nothing else.