HTTP (Hypertext Transfer Protocol) is the application protocol that browsers, apps and servers use to request and deliver web pages, files and API data.
How HTTP works
HTTP is a request-response protocol. A client sends a request with a method (GET, POST, PUT, DELETE and others), a URL and headers; the server answers with a status code (200 OK, 301 redirect, 404 not found, 500 server error), headers and a body. HTTP is stateless: each request stands alone, so cookies and tokens are used to keep users logged in.
- HTTP/1.1 – text-based, still widely used (RFC 9112);
- HTTP/2 – binary, many requests over one connection (RFC 9113);
- HTTP/3 – runs over QUIC on UDP for faster connections (RFC 9114).
HTTPS is HTTP inside an encrypted TLS connection, authenticated with a certificate from a certificate authority.
Why HTTP matters for security
Plain HTTP travels unencrypted, so anyone on the network – for example on public Wi-Fi – can read or change it. That is why browsers now mark HTTP sites as “Not secure” and major sites use HTTPS only. HTTP itself is also an attack surface:
- request smuggling and desync attacks between proxies and servers;
- header injection, open redirects and cookie theft;
- denial-of-service tricks such as the HTTP/2 Rapid Reset attack (2023), which enabled record-size DDoS attacks.
Best practices
- Serve every site over HTTPS and enable HSTS so browsers never fall back to HTTP.
- Set security headers: Content-Security-Policy, X-Content-Type-Options, secure and HttpOnly cookies.
- Keep web servers, proxies and CDNs updated.