Home/Labs/HTTP to HTTPS Evolution
All 280 Labs
INTERACTIVE LAB🛡️

HTTP/HTTPS Fundamentals Lab (Interactive)

Switch protocol versions and see connection counts, handshake RTTs, and exactly what a network tap can read. Compare plaintext HTTP, HTTPS, HTTP/2 multiplexing, and HTTP/3 QUIC against a man-in-the-middle wire view of a login flow.

HTTP → HTTPS → HTTP/2 → HTTP/3 Evolution

Pick a protocol and workload; compute connection counts, handshake RTTs, and what an on-path attacker sees.

1 RTT TCP + 1 RTT TLS per connection; payload encrypted with AES-GCM/ChaCha20.

TCP/QUIC connections
6
Setup cost
270 ms
Total page time
590 ms
What the network tap sees (443) ENCRYPTED
C → S•••• •••••• ••••• •••••••••••••••• (AES-256-GCM ciphertext)
C → S•••••••••••••••••••••••••••••••••••••••• (AES-256-GCM ciphertext)
S → C••••••••••• ••••••••••••••••••••• •••••• (AES-256-GCM ciphertext)
Head-of-line behaviour: 2 sequential waves — one slow response head-of-line blocks its whole socket. TCP ties identity to the IP+port 5-tuple, so a network change kills the connection.

How It Works Under the Hood

HTTP is a stateless application protocol whose plaintext bytes are readable at every router, ISP, and tap along the path — catastrophic for cookies and passwords. HTTPS wraps HTTP inside TLS, delivering confidentiality (AES-GCM/ChaCha20), integrity (HMAC), and authentication (CA-signed X.509 certificates). Protocol evolution then attacked connection overhead: HTTP/1.1 browsers open only six sockets per host and suffer head-of-line blocking; HTTP/2 multiplexes all streams over one TLS connection with HPACK header compression; HTTP/3 moves to QUIC over UDP, adding 0-RTT resumption and Connection-ID-based migration across WiFi-to-LTE handoffs. HSTS preload forces HTTPS even on a first visit, blocking SSL-stripping.

Core Architectural Principles

  • HTTPS = HTTP over TLS on port 443, guaranteeing confidentiality, integrity, and server authentication.
  • HTTP/2 multiplexes many streams on one connection; HTTP/3 removes TCP head-of-line blocking per stream.
  • HSTS preload list in browsers converts http:// to https:// before any byte is sent.
Interview Round Script

State that all external endpoints assume HTTPS with TLS 1.3, and offer mTLS for service-to-service auth. When asked how to cut connection overhead for parallel API calls, answer HTTP/2 multiplexing; for first-visit SSL-stripping protection, answer HSTS preload — these are the exact trigger phrases interviewers map to depth.

Key Trade-Offs

Full end-to-end privacy costs one to two handshake RTTs and certificate lifecycle operations, mitigated by TLS 1.3 resumption and automated CAs.

Related Curriculum Chapter

HTTP/HTTPS Fundamentals

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs