What Is SSL?

That padlock icon 🔒 in your browser's address bar is SSL — technically TLS, but everyone still calls it SSL. Without it, entering a password or paying online would be dangerously unsafe. This article explains what SSL does, the difference between http and https, and how to get a free certificate.

What is SSL?

SSL stands for "Secure Sockets Layer." It encrypts the communication between a website and your phone or PC. Today the underlying technology is actually called TLS (Transport Layer Security), a newer standard, but the name "SSL" has stuck through habit.

Without SSL, a password or personal detail you send over Wi-Fi could be intercepted by someone on the same network. With SSL, the traffic is encrypted so that even if someone captures it, they can't read the contents.

http vs. https

http vs. https: 6-Factor Comparison (2025) Source: Google Transparency Report / Let's Encrypt stats / HTTP Archive Web Almanac 2024 Factor http (no encryption) https (encrypted) Encryption None (exposed) Yes (unreadable) Browser display "Not secure" warning 🔒 Padlock icon Google search rank Penalized Boosted Global adoption Under 5% Over 95% Free Wi-Fi risk Snooping possible Snoop = unreadable Setup cost None needed Free (Let's Encrypt) ★ https wins all 6 factors. Over 95% of the world's sites already use https. Always enable it on any new site.
Fig. 1: https wins all 6 factors. Over 95% of sites worldwide have already switched to https. Use Let's Encrypt for free on any new site.

Whether a URL starts with "http://" or "https://" tells you if the connection is encrypted. The "s" stands for secure. In browsers like Chrome, visiting an http site triggers a "Not secure" warning. Google's search algorithm also rewards https sites with better rankings.

Situations where SSL protects you

8 Scenarios SSL Protects: What It Guards & Damage If Leaked Source: IPA "Top 10 IT Security Threats 2024" / Consumer Agency & NPA incident reports Scenario What it protects If leaked ① Login Password Account takeover ② Online shopping Card number, address Fraud, package theft ③ Banking / payments Balance, transfers Direct financial loss ④ School Grades, assignments Privacy breach ⑤ Medical Appointments, records Sensitive data exposure ⑥ Contact forms Name, email, phone Spam, scams ⑦ Social media DMs Messages, photos Bullying, blackmail ⑧ Free Wi-Fi usage All traffic Sniffable on same Wi-Fi
Fig. 2: SSL is essential in all 8 scenarios. Scenario ⑧ — free Wi-Fi — is especially risky: any http site can be intercepted by others on the same network.

Public Wi-Fi is the most dangerous situation. Without SSL (https), anyone connected to the same hotspot may be able to read your traffic. Most major sites now support HTTPS, but it's a good habit to check the "s" in the URL whenever you open an unfamiliar site.

How to get SSL for free

A non-profit certificate authority called "Let's Encrypt" issues SSL certificates for free. Most VPS and shared hosting control panels let you enable it with a single click. On GitHub Pages, Netlify, Vercel, and Cloudflare, SSL turns on automatically the moment you connect a custom domain.

SSL certificates used to cost thousands to tens of thousands of yen per year. Since Let's Encrypt launched in 2014, anyone can get one at no cost.

In practice, certificate renewal matters too. SSL/TLS certificates have an expiry date, and an expired certificate causes a browser warning that blocks visitors. Most shared hosting and managed services renew automatically, but if you set up SSL yourself on a VPS, verify that the auto-renewal process is running.

Watch out for these pitfalls

Common SSL misconceptions
  • Don't assume "https = safe." Scam sites use https too, so also check the domain spelling (e.g., amazon-jp.com is NOT amazon.com).
  • SSL certificates expire (usually every 90 days to 1 year). An expired certificate shows a browser warning and blocks access to your site.
  • Old "SSL 3.0" and "TLS 1.0" are vulnerable. Configure your server to use only TLS 1.2 or 1.3.

How will this help you later?

SSL and encrypted communication knowledge is needed by web engineers, security engineers, and infrastructure engineers alike. Understanding how SSL works also helps you spot phishing sites, which means you can protect your family and friends from online scams.

Remember: a padlock icon does not guarantee the site is trustworthy — only that the connection is encrypted. If the site itself is fake, it's still dangerous. As an engineer, you need to check certificates, domain names, redirects, mixed content, and renewal dates together. As a user, always confirm the domain name in the URL bar.

Start today

3 steps to get going
  1. Check the URLs of apps and sites you use every day and confirm they start with https.
  2. Click the padlock icon in your browser and look at the certificate issuer.
  3. If you have a website live, confirm that SSL is enabled on it.

Summary

SSL (TLS) encrypts internet traffic to protect passwords and personal information. A URL starting with "https" and a padlock icon means the connection is encrypted. Free certificates are available today, so always enable SSL when publishing your own website. Understanding SSL greatly improves your ability to spot phishing scams and stay safe online.

Check The lock (HTTPS) means?