HTTPS.
A locked box you and the website both hold a key to, agreed out in the open.
- Dear Bank, my password is hunter2.1
Plain HTTP is a postcard — your password written right out in the open.
- hunter2, eh? Noted.2
So everyone who carries it on the way can read every word.
- They agreed a secret… how?!3
HTTPS opens with a handshake: a shared secret agreed in plain sight that no eavesdropper can copy.
- Signed and sealed.4
The site also shows ID — a certificate signed by an authority your browser trusts.
- …it’s gibberish.5
Everything after is sealed with that secret. To anyone in between, it’s a brick.
- Read that, Snoop.6
Two promises in one padlock: nobody can read it, and you know who’s on the other end.
Semicolony semicolony.dev/eli5/https/comic