What is SSL?
SSL stands for "Secure Sockets Layer." It encrypts the communication between a website and your phone or PC. Today the underlying technology is actually called TLS (Transport Layer Security), a newer standard, but the name "SSL" has stuck through habit.
Without SSL, a password or personal detail you send over Wi-Fi could be intercepted by someone on the same network. With SSL, the traffic is encrypted so that even if someone captures it, they can't read the contents.
http vs. https
Whether a URL starts with "http://" or "https://" tells you if the connection is encrypted. The "s" stands for secure. In browsers like Chrome, visiting an http site triggers a "Not secure" warning. Google's search algorithm also rewards https sites with better rankings.
Situations where SSL protects you
Public Wi-Fi is the most dangerous situation. Without SSL (https), anyone connected to the same hotspot may be able to read your traffic. Most major sites now support HTTPS, but it's a good habit to check the "s" in the URL whenever you open an unfamiliar site.
How to get SSL for free
A non-profit certificate authority called "Let's Encrypt" issues SSL certificates for free. Most VPS and shared hosting control panels let you enable it with a single click. On GitHub Pages, Netlify, Vercel, and Cloudflare, SSL turns on automatically the moment you connect a custom domain.
SSL certificates used to cost thousands to tens of thousands of yen per year. Since Let's Encrypt launched in 2014, anyone can get one at no cost.
In practice, certificate renewal matters too. SSL/TLS certificates have an expiry date, and an expired certificate causes a browser warning that blocks visitors. Most shared hosting and managed services renew automatically, but if you set up SSL yourself on a VPS, verify that the auto-renewal process is running.
Watch out for these pitfalls
- Don't assume "https = safe." Scam sites use https too, so also check the domain spelling (e.g., amazon-jp.com is NOT amazon.com).
- SSL certificates expire (usually every 90 days to 1 year). An expired certificate shows a browser warning and blocks access to your site.
- Old "SSL 3.0" and "TLS 1.0" are vulnerable. Configure your server to use only TLS 1.2 or 1.3.
How will this help you later?
SSL and encrypted communication knowledge is needed by web engineers, security engineers, and infrastructure engineers alike. Understanding how SSL works also helps you spot phishing sites, which means you can protect your family and friends from online scams.
Remember: a padlock icon does not guarantee the site is trustworthy — only that the connection is encrypted. If the site itself is fake, it's still dangerous. As an engineer, you need to check certificates, domain names, redirects, mixed content, and renewal dates together. As a user, always confirm the domain name in the URL bar.
Start today
- Check the URLs of apps and sites you use every day and confirm they start with https.
- Click the padlock icon in your browser and look at the certificate issuer.
- If you have a website live, confirm that SSL is enabled on it.
Summary
Check The lock (HTTPS) means?