SSL, TLS, HTTPS — three names people use interchangeably, and only one of them is a protocol you can still use. SSL has been formally banned for years. TLS replaced it in 1999. HTTPS is just HTTP run through a TLS tunnel.
This is what actually happens in the moment before a page loads: two kinds of encryption, a handshake that finishes in one round trip on modern TLS, and a chain of signatures that ends at a root your device already trusts.
Then the part nobody tells you: the padlock makes exactly three promises — nobody read your traffic, nobody changed it, and you're talking to the domain in the address bar. It does not promise the site is honest. By 2020, more than eight in ten phishing sites already ran on perfectly valid HTTPS.
Chapters
0:00 The Postcard
0:37 The Names on the Door
1:25 Two Kinds of Locks
2:19 The Handshake
3:11 The Chain of Trust
3:57 What the Padlock Promises
Every claim traces to a primary source: RFC 8446 (TLS 1.3), RFC 7568 (deprecating SSLv3), RFC 2818 (HTTP Over TLS), RFC 2246 (TLS 1.0), the Google Security Blog's "HTTPS by default", the APWG Phishing Activity Trends Report Q4 2020, and Let's Encrypt's 2025 year-end figures.
Visuals are code-rendered motion graphics — no stock footage, no AI imagery. Narration is synthetic.