Semicolony ELI5 · comic

HTTPS.

A locked box you and the website both hold a key to, agreed out in the open.

  1. Dear Bank, my password is hunter2.
    Dear Bank,pwd: hunter2 scribble…
    1

    Plain HTTP is a postcard — your password written right out in the open.

  2. hunter2, eh? Noted.
    hunter2
    2

    So everyone who carries it on the way can read every word.

  3. They agreed a secret… how?!
    the site
    3

    HTTPS opens with a handshake: a shared secret agreed in plain sight that no eavesdropper can copy.

  4. Signed and sealed.
    CERTIFICATE
    4

    The site also shows ID — a certificate signed by an authority your browser trusts.

  5. …it’s gibberish.
    #@% x9$ ?!7
    5

    Everything after is sealed with that secret. To anyone in between, it’s a brick.

  6. Read that, Snoop.
    6

    Two promises in one padlock: nobody can read it, and you know who’s on the other end.

A quick handshake in the open, then a private, ID-checked line. (Snoop has a bad day.)
Semicolony semicolony.dev/eli5/https/comic
← All ELI5 explainers