Ch.9 Protecting Devices and Networks Vocabulary 242 words

HTTPS/TLS: data in transit, not site trust

HTTPS/TLS protects data in transit between user and website, but does not verify the site is honest — a phishing site can also use HTTPS.

Audio

Écouter cette page (bêta)

Sous-titres

HTTPS and TLS encrypt data as it travels from your browser to the website's server, stopping anyone on the same Wi-Fi or network from reading it. This means passwords, credit card numbers, and messages are scrambled in transit. But the padlock icon only shows the connection is encrypted, not that the site is legitimate. A phishing site can easily get a free TLS certificate and show a padlock too, so never rely on HTTPS alone to trust a site.

In exams, watch for questions that imply HTTPS guarantees site honesty — it does not. A quick elimination trick: if a question says 'HTTPS proves the website is safe to use', that is false. Another hint: TLS protects against eavesdropping, not against the site being malicious. Also remember that HTTPS does not protect data once it reaches the server; the site could still mishandle your information. When you see 'encryption in transit' in a question, think of TLS, but never confuse it with site trust or data storage security.

To test yourself, imagine you are on public Wi-Fi and see a padlock. Ask: 'Does this mean I can safely enter my bank details?' The answer is no — the padlock only stops others on the Wi-Fi from seeing your data, but the site itself could be a fake. A compact memory aid: 'HTTPS locks the road, not the destination.' Always check the site's address and reputation separately, even if the padlock is present.

Flashcard liée

What does HTTPS/TLS mainly protect?

Data in transit between the user and the website or service.

Retour à la flashcard Voir toutes les flashcards