GCSE · Computer Science · AQA · Spec 8525
HTTPS
Someone is listening in while you log in. Over HTTP they read your password like a postcard. Over HTTPS they get a jumble. Same route, same listener. So what changed?
Computer Science · Networks
Same login. Same route. Watch the listener.
Step through it once with HTTP, then once with HTTPS. Keep your eyes on the middle box.
Before you step on: the listener is in the middle both times. Predict what they end up holding under HTTP, and then under HTTPS.
Message: username=sam_14&password=hunter2
Output
Step 1: You press Log in. Over HTTP, the form data leaves your browser as plain text.
Step through the trace — every value is the lesson’s, not run by the page.
Computer Science · Structure
Where HTTPS sits in the TCP/IP model
Tap a layer to see its role in carrying HTTPS.
Tap any part of the diagram to see what it does.
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
What you need to know
- Browsers (clients) and web servers use HTTP to request and send web pages and other web resources.
- HTTP sends data as plain text, so anyone who intercepts it can read it.
Have a goPlain text crossing a network: is it more like a sealed envelope or a postcard? Pick one.
A postcard.
Plain text has nothing scrambling it in transit, so whoever intercepts it can read it, just as anyone handling a postcard can.
- HTTPS is the secure form of HTTP: Hypertext Transfer Protocol Secure.
- Its purpose is to transfer web data securely, encrypting it while it travels between browser and server.
- Because it's encrypted, an interceptor can't read it, which protects passwords, personal details and payment information.
Have a goDev says, 'HTTPS is a force field: hackers can't touch my data on the way.' Fix Dev's sentence in about ten words.
Hackers can still intercept it, but they can't read it.
Encryption doesn't block interception; it makes whatever is intercepted unreadable.
- TLS (the successor to SSL) is the encryption layer, and HTTPS works by running HTTP over it. It doesn't replace HTTP.
- That layer also lets the browser check the server's digital certificate, so you can be confident it's the genuine website.
Have a goA login page looks perfect, but you want proof it's the real site and not something pretending. What can your browser check?
The server's digital certificate.
The encryption layer lets the browser check the certificate, so you can be confident you're connected to the genuine website.
- Whenever the data being exchanged needs to be kept confidential, HTTPS is used instead of HTTP.
- In the TCP/IP model, HTTPS is an application-layer protocol that relies on the transport, internet and link layers to deliver its data.
The big picture
HTTP sends web data as plain text, so anyone who intercepts it can read it. HTTPS is the secure form of HTTP: it runs HTTP over an encryption layer (TLS), so the data is encrypted while it travels and an interceptor cannot read it. It also lets the browser check the server's digital certificate. HTTPS is used instead of HTTP whenever data must stay confidential, and it sits at the application layer of the TCP/IP model.
Key points
Worked example
Problem
A learner on a café's wi-fi runs a tool that copies the data passing by. It catches a login to each of two sites. Capture A: username=ana_7&password=blue42. Capture B: Zk3#9vQ!mP2x… Which site used HTTP and which used HTTPS? And did the tool manage to intercept the data in both cases?
⚠ Watch out
Saying HTTPS 'blocks' or 'stops' interception, or that it's a different protocol that replaces HTTP. The data can still be intercepted. HTTPS is HTTP running over an encryption layer (TLS), so what's intercepted is unreadable.
Memory hook
HTTPS = HTTP + TLS. Intercepted? Yes. Readable? No.
Check yourself
Cover the page. In one sentence each: what does a listener get under HTTP, what do they get under HTTPS, and which part of the journey is different?
Flashcards
(10)What is HTTP used for?
How does HTTP send data?
What does HTTPS stand for, and what is it?
What is the purpose of HTTPS?
Can HTTPS data still be intercepted?
Which kinds of data does HTTPS protect?
How does HTTPS get its security?
What can a browser check thanks to HTTPS?
When is HTTPS used instead of HTTP?
Which TCP/IP layer is HTTPS in?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore AQA GCSE Computer Science topics
How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.