Is HTTPS Always Necessary?

Is HTTPS Always Necessary? Featured Image

The hypertext transfer protocol (HTTP) is perhaps the most pervasive development on the Web, being the one thing that all websites use to send data to browsers. Its secure version (HTTPS) uses transport layer security (TLS) to enhance the communication between you and the websites you browse by ensuring their privacy.

If you’ve been on the Internet since the late 90s, you’ll probably notice that since 2007 the ubiquity of “https://” in URLs has increased almost exponentially. Is using HTTPS everywhere necessarily a good thing?

Why HTTPS?

httpsweb-crypt

HTTPS works by encrypting your connection to the server in such a way that your communication cannot be sniffed by a third party. If a website gives you a cookie (for your login session, for example), anyone who grabs your cookie can act on your behalf from their computer, essentially making them an impostor. By making the connection private and encrypted, such a thing is much less likely.

The problem with HTTPS historically has been the cost of implementing it as a host. You had to have a lot of processing power back in the day to be able to encrypt the thousands of connections larger websites had to handle. The prohibitive cost (at least in terms of computing power) needed to run an HTTPS website is no longer a factor because of the impressive amount of speed that even the most affordable CPUs have boasted in more recent years.

This still begs the question: is it always necessary to use HTTPS on a web server?

Cases in Which HTTPS Isn’t Needed

httpsweb-masm32

You’ll see lots of major initiatives trying to promote the use of HTTPS in every situation on every website everywhere. With one broad brush, they wish to paint the entire world in the hue of encryption. This gives people the perception that it is a necessity in every situation.

The idea that HTTPS must be used in everything and the truth are, as usual, parallel to one another. The truth is that HTTPS is only useful in situations where data related to you personally is being exchanged. Allow me to explain. When you log into Facebook or whatever you use to distribute memes, you send intimate data about yourself, such as your username and password, to the company’s servers. That should be encrypted if you don’t want third parties to have access to it, especially when you are connecting through a public Wi-Fi hub.

But what about static sites that are there to send you information about themselves without ever asking for any data from you? These kinds of sites are a bit of a rarity nowadays, but they’re still around. Frankly, they do not need HTTPS to maintain your security. And if they are sending their data indiscriminately, it’s likely that they don’t need to keep it private.

Should HTTPS Be Used Everywhere Anyway?

There are many sites out there that use HTTPS without it actually serving a productive purpose, but they are few and far between. The reason HTTPS is the go-to option for most web hosts is because it is so easy to implement in this day and age. The low cost in terms of processing power barely shows up as a blip on the radar. The general market has decided that it is easier to just slap HTTPS on everything and not debate whether or not it should be used as a way of saying “better safe than sorry.”

Whether or not HTTPS should be used everywhere is a question whose answer won’t change the way the Web marches on. It’s already being answered by millions of individuals acting on their own accord, and that answer seems to be a resounding “yes!”

Do you think that HTTPS should be debatable on an individual basis? Or would you rather only visit sites that use it? Tell us your reasoning in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe