GCSE · Computer Science · AQA · Spec 8525

HTTPS

Someone is listening in while you log in. Over HTTP they read your password like a postcard. Over HTTPS they get a jumble. Same route, same listener. So what changed?

Computer Science · Networks

Same login. Same route. Watch the listener.

Step through it once with HTTP, then once with HTTPS. Keep your eyes on the middle box.

Before you step on: the listener is in the middle both times. Predict what they end up holding under HTTP, and then under HTTPS.

Message: username=sam_14&password=hunter2

Your browser→Someone listening in→Web server
Contents=username=sam_14&password=hunter2Protocol=HTTPLeaves your browser as=plain text

Output

 

Step 1: You press Log in. Over HTTP, the form data leaves your browser as plain text.

1 / 6

Step through the trace — every value is the lesson’s, not run by the page.

Step 1 of 6: You press Log in. Over HTTP, the form data leaves your browser as plain text..

Watch out: HTTPS does not stop the listener getting hold of the data. It stops them being able to read it.

Computer Science · Networks

What do you think HTTPS actually does?

Dev's school-trip payment page uses HTTPS. Someone on the same network is listening in on all the traffic.

Which of these is closest to what you think is happening?
How sure are you?

HTTP versus HTTPS

HTTPvsHTTPS

Start with the first row: it's the one people mix up most.

Focus

What it is

HTTP

The protocol browsers (clients) and web servers use to request and send web pages and other web resources.

HTTPS

The secure form of HTTP (Hypertext Transfer Protocol Secure): HTTP running over the TLS encryption layer.

The insight

Same job. HTTPS is HTTP with an encryption layer under it, not a different language.

How the data travels

HTTP

As plain text.

HTTPS

Encrypted while it travels between browser and server.

Checking the website is genuine

HTTP

The browser has no digital certificate to check.

HTTPS

The browser can check the server's digital certificate.

When it is used

HTTP

Not the choice when the data needs to be kept confidential.

HTTPS

Used instead of HTTP whenever the data needs to be kept confidential.

Computer Science · Structure

Where HTTPS sits in the TCP/IP model

Tap a layer to see its role in carrying HTTPS.

Application layer: where HTTPS livesruns overrelies on

Tap any part of the diagram to see what it does.

Computer Science · Networks

Your turn: explain it in your own words

An online shop asks customers to log in with a password and to type in their card details. Explain why the shop's website should use HTTPS instead of HTTP. [3 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

What you need to know

  • Browsers (clients) and web servers use HTTP to request and send web pages and other web resources.
  • HTTP sends data as plain text, so anyone who intercepts it can read it.
  • Have a goPlain text crossing a network: is it more like a sealed envelope or a postcard? Pick one.

    A postcard.

    Plain text has nothing scrambling it in transit, so whoever intercepts it can read it, just as anyone handling a postcard can.

  • HTTPS is the secure form of HTTP: Hypertext Transfer Protocol Secure.
  • Its purpose is to transfer web data securely, encrypting it while it travels between browser and server.
  • Because it's encrypted, an interceptor can't read it, which protects passwords, personal details and payment information.
  • Have a goDev says, 'HTTPS is a force field: hackers can't touch my data on the way.' Fix Dev's sentence in about ten words.

    Hackers can still intercept it, but they can't read it.

    Encryption doesn't block interception; it makes whatever is intercepted unreadable.

  • TLS (the successor to SSL) is the encryption layer, and HTTPS works by running HTTP over it. It doesn't replace HTTP.
  • That layer also lets the browser check the server's digital certificate, so you can be confident it's the genuine website.
  • Have a goA login page looks perfect, but you want proof it's the real site and not something pretending. What can your browser check?

    The server's digital certificate.

    The encryption layer lets the browser check the certificate, so you can be confident you're connected to the genuine website.

  • Whenever the data being exchanged needs to be kept confidential, HTTPS is used instead of HTTP.
  • In the TCP/IP model, HTTPS is an application-layer protocol that relies on the transport, internet and link layers to deliver its data.

The big picture

HTTP sends web data as plain text, so anyone who intercepts it can read it. HTTPS is the secure form of HTTP: it runs HTTP over an encryption layer (TLS), so the data is encrypted while it travels and an interceptor cannot read it. It also lets the browser check the server's digital certificate. HTTPS is used instead of HTTP whenever data must stay confidential, and it sits at the application layer of the TCP/IP model.

Key points

1HTTP sends data as plain text, so it can be read if intercepted.
2HTTPS is HTTP running over an encryption layer (TLS), so the data is encrypted while it travels.
3HTTPS doesn't stop interception. It means an interceptor cannot read what they get.
4The browser can check the server's digital certificate, so you can be confident the site is genuine.
5Use HTTPS instead of HTTP whenever the data must be kept confidential. It is an application-layer protocol in the TCP/IP model.

Worked example

Problem

A learner on a café's wi-fi runs a tool that copies the data passing by. It catches a login to each of two sites. Capture A: username=ana_7&password=blue42. Capture B: Zk3#9vQ!mP2x… Which site used HTTP and which used HTTPS? And did the tool manage to intercept the data in both cases?

⚠ Watch out

Saying HTTPS 'blocks' or 'stops' interception, or that it's a different protocol that replaces HTTP. The data can still be intercepted. HTTPS is HTTP running over an encryption layer (TLS), so what's intercepted is unreadable.

🧠

Memory hook

HTTPS = HTTP + TLS. Intercepted? Yes. Readable? No.

✓

Check yourself

Cover the page. In one sentence each: what does a listener get under HTTP, what do they get under HTTPS, and which part of the journey is different?

Flashcards

(10)
What is HTTP used for?
Browsers (clients) and web servers use it to request and send web pages and other web resources.
How does HTTP send data?
As plain text, which can be read if it is intercepted.
What does HTTPS stand for, and what is it?
Hypertext Transfer Protocol Secure: the secure form of HTTP.
What is the purpose of HTTPS?
To transfer web data securely: it is encrypted while it travels between browser and server.
Can HTTPS data still be intercepted?
Yes. But it is encrypted, so whoever intercepts it cannot read it.
Which kinds of data does HTTPS protect?
Sensitive data such as passwords, personal details and payment information.
How does HTTPS get its security?
By running HTTP over an encryption layer, TLS (the successor to SSL).
What can a browser check thanks to HTTPS?
The server's digital certificate, so the user can be confident they are connected to the genuine website.
When is HTTPS used instead of HTTP?
Whenever the data being exchanged needs to be kept confidential.
Which TCP/IP layer is HTTPS in?
The application layer. It relies on the transport, internet and link layers to deliver its data.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.