<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Tls on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/tls/</link><description>Recent content in Tls on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:17:43 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/tls/index.xml" rel="self" type="application/rss+xml"/><item><title>TLS vs SSL: Encryption Protocol Evolution</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-tls-vs-ssl-encryption-protocol-evolution/</link><pubDate>Mon, 03 Aug 2026 04:17:43 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-tls-vs-ssl-encryption-protocol-evolution/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;SSL and TLS are cryptographic protocols that secure data in transit between clients and servers, but SSL is the deprecated &lt;strong class="kw"&gt;predecessor&lt;/strong&gt; while TLS is its actively maintained &lt;strong class="kw"&gt;successor&lt;/strong&gt;. Every SSL version is now broken or prohibited, yet the term &amp;ldquo;SSL&amp;rdquo; persists in everyday usage even though modern connections actually negotiate TLS.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="140" y="36" font-size="22" font-weight="bold" text-anchor="middle" style="fill:var(--primary)"&gt;SSL&lt;/text&gt;&lt;text x="480" y="36" font-size="22" font-weight="bold" text-anchor="middle" style="fill:var(--primary)"&gt;TLS&lt;/text&gt;&lt;line x1="20" y1="60" x2="620" y2="60" stroke-width="1.5" style="stroke:var(--border)"/&gt;&lt;rect x="40" y="80" width="180" height="44" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="98" font-size="14" text-anchor="middle" style="fill:var(--content)"&gt;SSL 2.0 (1995)&lt;/text&gt;&lt;text x="130" y="115" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;broken by DROWN&lt;/text&gt;&lt;rect x="40" y="140" width="180" height="44" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="158" font-size="14" text-anchor="middle" style="fill:var(--content)"&gt;SSL 3.0 (1996)&lt;/text&gt;&lt;text x="130" y="175" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;broken by POODLE&lt;/text&gt;&lt;rect x="40" y="200" width="180" height="36" rx="6" stroke-dasharray="4 3" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="130" y="223" font-size="13" text-anchor="middle" style="fill:var(--secondary)"&gt;all versions prohibited&lt;/text&gt;&lt;path d="M230 118 L390 98" style="stroke:var(--border)" stroke-width="1.5" fill="none" marker-end="url(#arrow)"/&gt;&lt;defs&gt;&lt;marker id="arrow" markerWidth="8" markerHeight="8" refX="6" refY="3" orient="auto"&gt;&lt;path d="M0,0 L6,3 L0,6 Z" style="fill:var(--border)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;rect x="400" y="70" width="200" height="38" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="94" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.0 (1999)&lt;/text&gt;&lt;rect x="400" y="118" width="200" height="38" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="142" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.1 (2006)&lt;/text&gt;&lt;rect x="400" y="166" width="200" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="190" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.2 (2008)&lt;/text&gt;&lt;text x="500" y="203" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;widely deployed&lt;/text&gt;&lt;rect x="400" y="216" width="200" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="240" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.3 (2018)&lt;/text&gt;&lt;text x="500" y="253" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;current standard&lt;/text&gt;&lt;line x1="40" y1="300" x2="600" y2="300" stroke-width="1.5" style="stroke:var(--border)" marker-end="url(#arrow)"/&gt;&lt;text x="320" y="320" font-size="12" text-anchor="middle" style="fill:var(--secondary)"&gt;time →&lt;/text&gt;&lt;text x="130" y="340" font-size="12" text-anchor="middle" style="fill:var(--compare-a)"&gt;deprecated / prohibited&lt;/text&gt;&lt;text x="500" y="340" font-size="12" text-anchor="middle" style="fill:var(--compare-b)"&gt;actively maintained&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;SSL&lt;/th&gt;
&lt;th&gt;TLS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Origin&lt;/td&gt;
&lt;td&gt;Developed by Netscape starting in 1995&lt;/td&gt;
&lt;td&gt;Standardized by the IETF in 1999 as SSL&amp;rsquo;s successor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions released&lt;/td&gt;
&lt;td&gt;SSL 2.0, SSL 3.0 (SSL 1.0 never shipped)&lt;/td&gt;
&lt;td&gt;TLS 1.0, 1.1, 1.2, 1.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Handshake process&lt;/td&gt;
&lt;td&gt;Full handshake only, with weaker key exchange options&lt;/td&gt;
&lt;td&gt;Streamlined handshake; TLS 1.3 cuts a round trip and defaults to forward secrecy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cipher suite support&lt;/td&gt;
&lt;td&gt;Permits weak ciphers like RC4, DES, and export-grade crypto&lt;/td&gt;
&lt;td&gt;Mandates modern AEAD ciphers (AES-GCM, ChaCha20-Poly1305); weak ciphers dropped entirely in 1.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Known vulnerabilities&lt;/td&gt;
&lt;td&gt;POODLE broke SSL 3.0; DROWN broke SSL 2.0&lt;/td&gt;
&lt;td&gt;BEAST and CRIME hit early TLS 1.0 but were patched in later versions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Current status&lt;/td&gt;
&lt;td&gt;All versions formally deprecated and prohibited (RFC 7568)&lt;/td&gt;
&lt;td&gt;TLS 1.2 and 1.3 are the current standards; 1.0/1.1 also deprecated&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Everyday terminology&lt;/td&gt;
&lt;td&gt;&amp;ldquo;SSL certificate&amp;rdquo; and &amp;ldquo;SSL/TLS&amp;rdquo; persist as colloquial shorthand&lt;/td&gt;
&lt;td&gt;The protocol actually negotiated by nearly every modern HTTPS connection&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSL is the obsolete &lt;strong class="kw"&gt;predecessor&lt;/strong&gt;; TLS is the actively maintained &lt;strong class="kw"&gt;successor&lt;/strong&gt; protocol&lt;/li&gt;
&lt;li&gt;TLS 1.3&amp;rsquo;s handshake trims a &lt;strong class="kw"&gt;round trip&lt;/strong&gt; compared to SSL&amp;rsquo;s full handshake&lt;/li&gt;
&lt;li&gt;SSL still permits weak ciphers like &lt;strong class="kw"&gt;RC4&lt;/strong&gt;; TLS mandates modern AEAD ciphers&lt;/li&gt;
&lt;li&gt;The label &amp;ldquo;&lt;strong class="kw"&gt;SSL certificate&lt;/strong&gt;&amp;rdquo; survives in marketing even though browsers negotiate TLS&lt;/li&gt;
&lt;li&gt;SSL 3.0 was broken by &lt;strong class="kw"&gt;POODLE&lt;/strong&gt;, forcing its complete deprecation&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;SSL&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>HTTP vs HTTPS: Plaintext vs Encrypted Web Traffic</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-http-vs-https-plaintext-vs-encrypted-web-traffic/</link><pubDate>Sat, 01 Aug 2026 20:01:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-http-vs-https-plaintext-vs-encrypted-web-traffic/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;HTTP and HTTPS are the same application-layer protocol for transferring web resources, but HTTPS wraps every request and response in a &lt;strong class="kw"&gt;TLS&lt;/strong&gt; tunnel before it touches the network. That single layer determines whether credentials, cookies, and page content travel as &lt;strong class="kw"&gt;plaintext&lt;/strong&gt; visible to anyone on the path, or as ciphertext only the two endpoints can read.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="20" y="32" font-size="18" font-weight="700" style="fill:var(--primary)"&gt;HTTP&lt;/text&gt;&lt;rect x="40" y="70" width="110" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="95" y="100" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;rect x="490" y="70" width="110" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="545" y="100" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="150" y1="95" x2="490" y2="95" style="stroke:var(--compare-a)" stroke-width="2" stroke-dasharray="5,4" marker-end="url(#arrowA)"/&gt;&lt;text x="320" y="82" font-size="12" text-anchor="middle" style="fill:var(--content)"&gt;GET /login?pwd=hunter2&lt;/text&gt;&lt;circle cx="320" cy="140" r="14" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;path d="M310 140 Q320 132 330 140 Q320 148 310 140 Z" style="fill:none;stroke:var(--compare-a)" stroke-width="1.3"/&gt;&lt;circle cx="320" cy="140" r="2.5" style="fill:var(--compare-a)"/&gt;&lt;text x="320" y="165" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;visible to anyone on path&lt;/text&gt;&lt;line x1="0" y1="195" x2="640" y2="195" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;text x="20" y="225" font-size="18" font-weight="700" style="fill:var(--primary)"&gt;HTTPS&lt;/text&gt;&lt;rect x="40" y="260" width="110" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="95" y="290" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;rect x="490" y="260" width="110" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="545" y="290" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="150" y1="285" x2="490" y2="285" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;text x="320" y="272" font-size="12" text-anchor="middle" style="fill:var(--content)"&gt;x8f#9a2$qL0e...&lt;/text&gt;&lt;rect x="308" y="296" width="24" height="18" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;path d="M313 296 v-8 a7 7 0 0 1 14 0 v8" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="320" y="335" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;TLS-encrypted, tamper-evident&lt;/text&gt;&lt;defs&gt;&lt;marker id="arrowA" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;HTTP&lt;/th&gt;
&lt;th&gt;HTTPS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Default port&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;443&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connection establishment&lt;/td&gt;
&lt;td&gt;Single TCP three-way handshake&lt;/td&gt;
&lt;td&gt;TCP handshake plus a TLS handshake to negotiate cipher and exchange keys&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Certificate requirement&lt;/td&gt;
&lt;td&gt;None&lt;/td&gt;
&lt;td&gt;X.509 certificate issued by a trusted CA (or self-signed) required&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data encryption&lt;/td&gt;
&lt;td&gt;Plaintext — headers, cookies, and body sent unencrypted&lt;/td&gt;
&lt;td&gt;Encrypted end-to-end using TLS/SSL symmetric ciphers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data integrity&lt;/td&gt;
&lt;td&gt;No built-in tamper detection&lt;/td&gt;
&lt;td&gt;MAC/AEAD in TLS detects in-transit tampering&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Browser indicator&lt;/td&gt;
&lt;td&gt;&amp;ldquo;Not secure&amp;rdquo; warning in modern browsers&lt;/td&gt;
&lt;td&gt;Padlock icon; no warning shown&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Performance overhead&lt;/td&gt;
&lt;td&gt;Lower — no crypto or extra round trip&lt;/td&gt;
&lt;td&gt;Slightly higher handshake/CPU cost, largely offset by TLS 1.3 and session resumption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical use case&lt;/td&gt;
&lt;td&gt;Local development, internal tools on trusted networks, legacy static content&lt;/td&gt;
&lt;td&gt;Any production site, especially logins, payments, and APIs handling sensitive data&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HTTPS is HTTP tunneled through &lt;strong class="kw"&gt;TLS&lt;/strong&gt;, not a separate application protocol&lt;/li&gt;
&lt;li&gt;HTTP traffic is readable in plaintext by anyone with network access; HTTPS traffic is &lt;strong class="kw"&gt;encrypted&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;HTTPS requires a valid &lt;strong class="kw"&gt;certificate&lt;/strong&gt; from a trusted CA to establish trust&lt;/li&gt;
&lt;li&gt;Modern browsers flag HTTP sites as &lt;strong class="kw"&gt;not secure&lt;/strong&gt;, pushing HTTPS as the default&lt;/li&gt;
&lt;li&gt;TLS 1.3 has shrunk the historical HTTPS &lt;strong class="kw"&gt;handshake&lt;/strong&gt; cost to near parity with plain TCP&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;HTTP&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>