You’ve seen that padlock beside a website address, looks too ordinary to notice now. Usually means the site’s got an SSL certificate and is using HTTPS to protect the connection between your browser and the site.
Why A Site Needs One
Enter a password without encryption, and that data’s traveling to the server exposed. If the connection isn’t protected, someone monitoring the network could see it.
SSL scrambles what gets sent, so it looks like nonsense to anyone who shouldn’t be looking. Once HTTPS is working, you never think about it, it just runs in the background.
How It Works
When you visit an HTTPS site, your browser checks its certificate, which has identity info from a trusted Certificate Authority. If it checks out, browser and server create a secure connection, agree on encryption, and establish keys protecting data as it moves between them.
You don’t set any of this up, your browser handles it while you’re just waiting for the page to load.
SSL’s the older name people still use, sites actually run on TLS now, which replaced it. “SSL certificate” just stuck as a term.
What The Padlock Actually Tells You
It’s useful, not a magic safety stamp. Mainly means HTTPS is active and the certificate passed your browser’s checks.
Encryption protects data moving between you and the site, doesn’t guarantee the site itself is trustworthy. The domain matters too, an attacker can build a fake site that also uses HTTPS. Certificate errors shouldn’t be dismissed. No padlock at all, don’t enter sensitive info until you know why.
Why It Matters For Businesses
HTTPS is basically expected now, browsers actively warn when a connection isn’t secure. Protects login details, forms, and page loads instead of visitors seeing warnings.
A site without HTTPS feels dated at this point. An SSL certificate won’t make a bad site good, but it gives the connection real protection, something every serious site should have.