HTTPS and cookies
What the padlock really tells you, how certificates work and how cookies keep you logged in.
What HTTPS adds
HTTPS is HTTP inside a TLS connection. It gives you three things: encryption (nobody on the path can read the traffic), integrity (tampering is detected) and server authentication (you are talking to the real owner of the domain).
Certificates
A server presents a certificate that links a domain name to a public key. It is signed by a certificate authority (CA) that your browser trusts. Free authorities such as Let's Encrypt automate issuing, and certificates for public sites now last months rather than years, so renewal is automated.
What the padlock does and does not mean
CarefulThe padlock means the connection is encrypted and the certificate matches the domain. It does not mean the site is honest or safe: phishing sites use HTTPS too. Always check the domain name itself.
HSTS
The Strict-Transport-Security header tells the browser to use HTTPS only for that site from now on, which blocks downgrade attacks to plain HTTP.
Cookies
HTTP has no memory. A cookie is a small value the server sets with Set-Cookie and the browser sends back on later requests, which is how sessions and logins work.
Set-Cookie: session=abc123; Max-Age=3600; Secure; HttpOnly; SameSite=Lax- Secure: only sent over HTTPS.
- HttpOnly: JavaScript cannot read it, which limits theft by cross-site scripting.
- SameSite: limits sending it on cross-site requests (
Strict,LaxorNone), reducing request-forgery attacks. - Max-Age or Expires: how long it lasts. Without them it is a session cookie.
Cookies and consent
Cookies that are strictly necessary, such as a login session, do not need consent in the EU. Analytics and advertising cookies do, which is why sites show a consent banner before loading them.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.