You see that padlock in your browser and probably don’t think much about it. That’s the point. TLS works quietly in the background so data moving between your browser and a site isn’t sitting there in plain text.

Modern sites technically use TLS, Transport Layer Security, SSL was the older tech before it. People still say “SSL certificate” out of habit, but TLS is really doing the work now.

What Happens When You Open A Secure Site

Before any sensitive info gets sent, your browser establishes a secure connection first, starting with a TLS handshake. Browser tells the server which TLS versions it supports, server picks one they both can use, then comes the identity check.

The Certificate Check

The site sends its digital certificate, containing its identity info and a public key, issued by a trusted Certificate Authority that’s already verified the site. Your browser checks if it’s valid and actually belongs to the site you’re on. Something’s off, you get a warning instead of just continuing quietly.

How Encryption Actually Starts

The clever bit, browser and server need to agree on a secret key without sending it openly across the internet. Modern TLS uses public-key cryptography for this, a public key the site shares openly and a private key that stays on the server. Both sides establish a shared secret without exposing it to anyone watching.

Once that’s done, the connection switches to symmetric encryption since it’s much faster for the actual flow of traffic.

The certificate proves the site’s identity, so your browser isn’t blindly trusting whoever answered first. The session key stays secret even though the connection’s traveling across networks neither side controls. And traffic gets encrypted before it even leaves your device, so snooping doesn’t get anyone anything readable.

Why Two Types Of Encryption

Sounds complicated, isn’t really. Public-key cryptography’s great for establishing trust, but using it for every bit of data would be slow. Symmetric encryption handles the ongoing conversation much faster once both sides agree on a key. Handshake does the setup, session key takes over from there.

What You Actually Notice

Basically nothing. You see HTTPS and move on, which is actually the point, good security shouldn’t get in your way. TLS also catches tampering, if someone messes with data mid transit, the cryptographic checks expose it.

What It Actually Protects

Think of it as a protected tunnel between your browser and the site, encrypted with checks built in for manipulation. But TLS doesn’t make a site trustworthy just because it’s got HTTPS. A scam site can have a valid certificate too. The encryption protects your connection, not the intentions of whoever’s running the site.

A secure connection to a bad website is still, well, a secure connection to a bad website. Still, TLS does its job well, handshake happens, keys get established, and you barely notice any of it. That’s exactly how it should feel.