Without TLS, everything between browser and server — passwords, card numbers, the page itself — is readable and rewritable by anyone on the path: the café wifi, the ISP, a state firewall. TLS encrypts the channel and the certificate proves you reached the real site, not an impersonator.
What was a differentiator in 2010 is a baseline in 2025: browsers mark plain HTTP 'not secure', search engines rank HTTPS, and certificates are free and auto-renewing. Running HTTP today is not a choice, it is a bug that tells every visitor you stopped maintaining the site.
Related terms
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
Security headers
HTTP response headers that tell browsers how to handle the page safely — HSTS, CSP, X-Frame-Options — free defences most sites skip.
Session hijacking
Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.
