HTTP/HTTPS Fundamentals Lab (Interactive)
Switch protocol versions and see connection counts, handshake RTTs, and exactly what a network tap can read. Compare plaintext HTTP, HTTPS, HTTP/2 multiplexing, and HTTP/3 QUIC against a man-in-the-middle wire view of a login flow.
HTTP → HTTPS → HTTP/2 → HTTP/3 Evolution
Pick a protocol and workload; compute connection counts, handshake RTTs, and what an on-path attacker sees.
1 RTT TCP + 1 RTT TLS per connection; payload encrypted with AES-GCM/ChaCha20.
How It Works Under the Hood
HTTP is a stateless application protocol whose plaintext bytes are readable at every router, ISP, and tap along the path — catastrophic for cookies and passwords. HTTPS wraps HTTP inside TLS, delivering confidentiality (AES-GCM/ChaCha20), integrity (HMAC), and authentication (CA-signed X.509 certificates). Protocol evolution then attacked connection overhead: HTTP/1.1 browsers open only six sockets per host and suffer head-of-line blocking; HTTP/2 multiplexes all streams over one TLS connection with HPACK header compression; HTTP/3 moves to QUIC over UDP, adding 0-RTT resumption and Connection-ID-based migration across WiFi-to-LTE handoffs. HSTS preload forces HTTPS even on a first visit, blocking SSL-stripping.
Core Architectural Principles
- HTTPS = HTTP over TLS on port 443, guaranteeing confidentiality, integrity, and server authentication.
- HTTP/2 multiplexes many streams on one connection; HTTP/3 removes TCP head-of-line blocking per stream.
- HSTS preload list in browsers converts http:// to https:// before any byte is sent.
State that all external endpoints assume HTTPS with TLS 1.3, and offer mTLS for service-to-service auth. When asked how to cut connection overhead for parallel API calls, answer HTTP/2 multiplexing; for first-visit SSL-stripping protection, answer HSTS preload — these are the exact trigger phrases interviewers map to depth.
Full end-to-end privacy costs one to two handshake RTTs and certificate lifecycle operations, mitigated by TLS 1.3 resumption and automated CAs.