10 Feb 2019

HTTPS Everywhere

The HTTP/2 specification was published as RFC 7540 in May 2015, making it officially part of the standard — a major milestone, and a good time to upgrade servers to HTTP/2. One of the most important aspects is backwards compatibility with HTTP/1.1 and the negotiation mechanism used to choose a protocol. The standard doesn’t mandate encryption, but no browser currently supports HTTP/2 unencrypted — giving HTTPS another push toward being everywhere.

Network stack overview

From the perspective of a website running in the browser (application level), the layers to reach the IP level look roughly like:

  1. Client browser
  2. HTTP
  3. SSL/TLS
  4. TCP
  5. IP

What HTTPS provides

HTTPS is nothing more than HTTP on top of SSL/TLS, so all the usual rules of HTTP still apply. What the additional layer buys you: authentication via keys and certificates; a kind of privacy and confidentiality, since the connection is encrypted asymmetrically; and data integrity, so transmitted data can’t be changed in transit.

Performance considerations

A common myth is that SSL/TLS requires too many resources and slows the server down. That’s no longer true, and no specialized cryptography hardware is needed either — for Google, the SSL/TLS layer accounts for less than 1% of CPU load, and the network overhead of HTTPS versus HTTP is below 2%. It wouldn’t make sense to skip HTTPS to avoid that little overhead.

TLS versions and encryption

The most recent version is TLS 1.3. TLS is the successor to SSL, whose final release was SSL 3.0 — the changes from SSL to TLS break interoperability, though the basic procedure is unchanged. There are three encrypted channels involved: a public key infrastructure for certificate chains, public key cryptography for key exchange, and symmetric cryptography for the actual data transfer.

TLS 1.3 uses hashing for several important operations. Theoretically any hashing algorithm could work, but SHA-2 or stronger is strongly recommended — SHA-1 was a long-standing standard but has recently become obsolete.

Client-side privacy

HTTPS is also getting more attention on the client side. Privacy and security concerns have always existed, but they’re growing along with the amount of data and services people access online. The “HTTPS Everywhere” browser extension is a useful tool that encrypts communication with most websites by default.