What Are HTTPS and SSL Certificates? Explained
What the padlock really means, how encryption protects your connection, and what certificates actually prove.
What HTTPS is
HTTPS is the secure version of HTTP, the protocol your browser uses to communicate with websites. The 'S' stands for secure, and it means the connection between your browser and the website is encrypted using a protocol called TLS (the successor to the older SSL, though people still say 'SSL' out of habit). When you see a padlock and 'https://' in the address bar, your connection to that site is protected, which is why HTTPS has become the standard for essentially the entire modern web.
What the encryption protects
HTTPS encryption does two main things. First, it keeps your communication private: anyone who intercepts the traffic between you and the site, on public Wi-Fi, at your internet provider, sees only scrambled data, not your passwords, messages, or the contents of pages. Second, it protects integrity: it prevents attackers from tampering with the data in transit, so the page you receive is the one the site actually sent. This is why entering sensitive information on a non-HTTPS site is risky, it could be read or altered.
What a certificate is
For HTTPS to work, a website presents a digital SSL/TLS certificate, a credential that does two jobs: it contains the cryptographic key material used to set up the encrypted connection, and it vouches for the site's identity. The certificate is issued by a trusted third party called a certificate authority (CA), which your browser and operating system are configured to trust. When you connect, your browser checks the certificate's validity and that a trusted CA issued it, then establishes the encrypted session.
How certificate authorities work
Certificate authorities are the linchpin of trust. Before issuing a certificate, a CA verifies that the requester controls the domain (and, for higher-assurance certificates, additional checks about the organization). Because browsers trust a set of established CAs, a certificate from one of them lets your browser trust that it is really talking to, say, your bank's domain and not an impostor. If a certificate is missing, expired, or not from a trusted CA, your browser warns you, those warnings exist to flag potential impersonation or interception.
What the padlock does and doesn't mean
This is the crucial nuance: the padlock means your connection to the site is encrypted and that the site proved control of its domain, it does not mean the site is trustworthy or legitimate. Scammers can and do obtain valid certificates for their phishing sites, so a padlock on a fraudulent site still shows. In other words, HTTPS confirms you are talking securely to whoever owns that domain, but it does not vouch for their honesty. The padlock is about the connection, not the character of the site.
What it means for you
Practically: always look for HTTPS before entering sensitive information, and heed browser certificate warnings, they signal a real problem. But do not treat the padlock as a seal of safety; still verify you are on the correct, legitimate domain, since a secure connection to a fake site is still dangerous. HTTPS is a foundational and hugely valuable protection that made the web far safer, understanding exactly what it does, encrypt and authenticate the connection, and what it does not, guarantee a site's intentions, lets you use it wisely.
Related on Skillo
See also: HTTP vs HTTPS and the padlock explained, What is encryption? End-to-end explained.
Sources
Published date reflects the original event date (2025-03-25). This article is original Skillo editorial written from the sources above; facts were verified in September 2026.
Written by
Skillo Staff
0 Comments
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.