Computer Networks · Module 7 — Application Layer
HTTP and HTTPS
TCP delivers a stream of bytes. It has no idea what those bytes mean.
Sign in to track your score
Everything so far has been delivery — addresses, routes, ports, acknowledgements. None of it said what Aisha actually wants. That sentence is HTTP.
Why & what
Why HTTP exists. TCP delivers a stream of bytes. It has no idea what those bytes mean.
Both sides need an agreed way to say "give me the results page" and "here it is, and it is HTML, and it is 60 KB". That agreement is HTTP.
What HTTP is. HTTP (HyperText Transfer Protocol) is the language browsers and web servers speak. It is plain text, and simple enough to read by eye.
A request has:
- a method — GET to fetch, POST to send data, PUT to update, DELETE to remove
- a path — /results
- headers — extra information, like Host: college.edu
A response has:
- a status code — 200
- headers — like Content-Type: text/html
- a body — the actual page
Status codes, by first digit:
| Family | Means | Common example |
|---|---|---|
| 2xx | it worked | 200 OK |
| 3xx | look somewhere else | 301 Moved Permanently |
| 4xx | your mistake | 404 Not Found |
| 5xx | the server's mistake | 500 Internal Server Error |
HTTP is stateless. The server remembers nothing between requests. Each one arrives with no memory of the last. Cookies exist precisely to work around that — the browser sends a small token back each time so the server can recognise the same user.
What HTTPS is. HTTPS is exactly the same HTTP, wrapped inside TLS encryption, on port 443 instead of 80.
TLS does three things:
- Encryption — nobody in between can read the contents.
- Identity — a certificate, signed by a trusted authority, proves the server really is college.edu.
- Integrity — tampering in transit is detected.
How it works
- TCP is already connected — that was the handshake in Topic 6.3.
- For HTTPS, a TLS handshake runs next: the server presents its certificate, both sides agree on keys.
- Aisha's browser sends the request: GET /results HTTP/1.1, with Host: college.edu.
- The server finds the page and replies with 200 OK, headers, and the HTML body.
- The browser reads the HTML, spots images and stylesheets it needs, and sends more requests for those — often reusing the same connection.

Common confusion
Students think HTTPS is a different protocol from HTTP. Actually, HTTPS is the identical protocol, running inside an encrypted tunnel.
The methods are the same, the headers are the same, the status codes are the same. Change nothing but the port and the wrapper. This also explains what HTTPS does not hide. The routers along the path still see Aisha's IP address, the server's IP address, and the port. They cannot see the path she asked for, the headers, or the page. The envelope is sealed; the address on the outside is still readable.
Interview angle
Asked as: "Difference between HTTP and HTTPS?" and "What does 404 mean?" — plus the strong follow-up "what does stateless mean?"
Model answer:
HTTP is the request-response protocol between a browser and a web server. A request carries a method like GET or POST, a path, and headers. A response carries a status code, headers and a body. Status codes group by first digit: 2xx success, 3xx redirection, 4xx client error like 404 Not Found, 5xx server error. HTTP is stateless — the server keeps no memory between requests, which is why cookies and sessions exist. HTTPS is the same protocol carried inside TLS on port 443. TLS gives encryption, integrity, and server identity through a certificate. Someone watching the traffic still sees which IP addresses are talking, but not the URL path, the headers or the content.
- 1.
What does a 404 status mean?
- 2.
HTTPS differs from HTTP by
- 3.
"HTTP is stateless" means
- 4.
With HTTPS, what can a router along the path still see?