Explaining HTTP & HTTPS

HTTP
HTTP stands for Hyper Text Transfer Protocol. It is an application-layer protocol that is used for distributed, collaborative, hypermedia information systems. HTTP is the protocol used between web clients and web servers.
HTTP client sends HTTP request to the server in the form of a request message after receiving and processing it, the server responds with an HTTP response message, and that’s why it is also called as a request-response protocol.
HTTP is stateless which means every request is completely independent and it is not going to store any information about the users, as every request is new and separate from any previous request.
HTTP Messages
HTTP messages are of two types: request and response. Both message types follow the same format.
Request Message: The request message is sent by the client that consists of a request line, headers, and sometimes a body.
Response Message: The response message is sent by the server to the client that consists of a status line, headers, and sometimes a body.
Limitations of HTTP
HTTP is less secure because the data is transferred in form of text and anyone can do a man-in-middle attack and can listen to traffic.
HTTP is unencrypted that’s why the man-in-middle attack is possible, the data can tamper with, and one can change the data and forward thus it is less reliable.
7 layers of the OSI Model

HTTPS
It stands for Hyper Text Transfer Protocol Secure. It is a protocol that secures communication and data transfer between a user's web browser and a website. HTTPS is the secure version of HTTP. It uses cryptography for secure communication over a computer network and is widely used on the Internet.
HTTPS is now used more often by web users than the original, non-secure HTTP, primarily to protect page authenticity on all types of websites, secure accounts, and keep user communications, identity, and web browsing private.
HTTP vs HTTPS

HTTP | HTTPS |
It is unsecured as the plain text is sent, which can be accessible by hackers. | It is secure as it sends encrypted data which hackers cannot understand. |
It is an application layer protocol. | It is a transport layer protocol. |
It does not use SSL. | It uses SSL which provides the encryption of the data. |
It is mainly used for those websites that provide information like blog writing. | It is a secure protocol, so it is used for those websites that require to transmit the bank account details or credit card numbers. |
The page loading speed is fast. | The page loading speed is comparatively slow because of the additional feature i.e., security. |

