What Is HSTS and Should You Enable It?
One header that closes the gap attackers use to intercept a visitor's very first connection to your site.
50 guides covering the foundations: what SSL/TLS is, how the handshake works, the cryptography underneath, and every certificate type and field you'll run into.
One header that closes the gap attackers use to intercept a visitor's very first connection to your site.
The attack SSL/TLS was fundamentally designed to stop — walked through step by step, blocked at each turn.
Every certificate on the internet follows the same 1988 standard — here's what's actually inside the file.
What happens when a certificate needs to be invalidated before its expiry date — and how browsers find out.
Normal HTTPS proves the server's identity. Mutual TLS makes the client prove its identity too.
The organizations your browser already trusts — and why that trust is what makes any certificate work at all.
Your server almost never presents a root certificate directly — here's why that's by design.
Every browser will warn you about them — and for local development, that's exactly the right trade-off.
One letter, and an entire encrypted layer sitting underneath it.
Less than most people assume — and browsers have been quietly redesigning it for exactly that reason.