HTTPS = HTTP + TLS

TLS, transport layer security, is the cryptographic protocol that builds an encrypted channel between the client, normally a browser, and the server. It gives three guarantees:

  1. Confidentiality — the data is encrypted, so intercepted traffic is unreadable
  2. Integrity — the data cannot be altered in transit without detection
  3. Authentication — the certificate confirms the server is who it claims to be

The TLS handshake happens on every new connection: certificates are exchanged, algorithms negotiated, session keys generated. After that all traffic is encrypted with symmetric session keys.

TLS 1.2 against TLS 1.3

Property TLS 1.2 TLS 1.3
Round trips to establish a connection 2 RTT 1 RTT, or 0-RTT on resumption
Cipher suites Broad, including obsolete ones Only modern, safe ones
Browser support All current browsers All current browsers since 2019

TLS 1.3 is both faster and safer and is the sensible minimum for new deployments. TLS 1.0 and 1.1 are obsolete and disabled in most browsers.

Practical requirements for e-commerce

Certificates

  • Let’s Encrypt — free certificates with automatic renewal through Certbot, enough for most cases
  • Wildcard (*.example.com) — one certificate covering every subdomain
  • EV (extended validation) — for large retailers; it shows the company name in the browser bar (hidden in Chrome since 2019, still supported elsewhere)
  • Expiry: track it automatically — a lapsed certificate blocks access to the site outright

Mixed content — the usual sources

<!-- Bad — loaded over HTTP on an HTTPS page -->
<img src="http://cdn.example.com/image.jpg">
<script src="http://analytics.example.com/tag.js"></script>

<!-- Good — a protocol-relative URL -->
<img src="//cdn.example.com/image.jpg">

<!-- Good — explicit HTTPS -->
<img src="https://cdn.example.com/image.jpg">

APIs and personalization

Every call to an external API — personalization, analytics, search — has to go over HTTPS. That is especially critical for:
– Sending API keys and authorisation tokens
– Event data: views, add-to-cart events, purchases
– A/B testing, where the data says which group a visitor belongs to

Important: never pass API keys or tokens in URL parameters — they end up in server logs, browser history and Referer headers. Use the Authorization or X-API-Key headers over HTTPS and nothing else.