appzasGamesToolsDevLearnCheat sheetsQuick calcsConvertersReferenceNetworkTimeCalculatorsCompareLLM prices

HTTPS and cookies

Lesson 4 of 410 minBeginner

What the padlock really tells you, how certificates work and how cookies keep you logged in.

What HTTPS adds

HTTPS is HTTP inside a TLS connection. It gives you three things: encryption (nobody on the path can read the traffic), integrity (tampering is detected) and server authentication (you are talking to the real owner of the domain).

Certificates

A server presents a certificate that links a domain name to a public key. It is signed by a certificate authority (CA) that your browser trusts. Free authorities such as Let's Encrypt automate issuing, and certificates for public sites now last months rather than years, so renewal is automated.

What the padlock does and does not mean

CarefulThe padlock means the connection is encrypted and the certificate matches the domain. It does not mean the site is honest or safe: phishing sites use HTTPS too. Always check the domain name itself.

HSTS

The Strict-Transport-Security header tells the browser to use HTTPS only for that site from now on, which blocks downgrade attacks to plain HTTP.

Cookies

HTTP has no memory. A cookie is a small value the server sets with Set-Cookie and the browser sends back on later requests, which is how sessions and logins work.

Set-Cookie: session=abc123; Max-Age=3600; Secure; HttpOnly; SameSite=Lax
  • Secure: only sent over HTTPS.
  • HttpOnly: JavaScript cannot read it, which limits theft by cross-site scripting.
  • SameSite: limits sending it on cross-site requests (Strict, Lax or None), reducing request-forgery attacks.
  • Max-Age or Expires: how long it lasts. Without them it is a session cookie.

Cookies and consent

Cookies that are strictly necessary, such as a login session, do not need consent in the EU. Analytics and advertising cookies do, which is why sites show a consent banner before loading them.

Test yourself

Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.

1. What does the padlock in the address bar guarantee?
2. What does the HttpOnly cookie attribute do?
3. What does the Secure attribute mean?
4. Which kind of cookie needs consent in the EU?

Key terms