EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
A web developer is building a RESTful API that handles sensitive user data. To ensure data privacy during transmission, they decide to implement HTTPS. Which of the following components is primarily responsible for establishing the encrypted communication channel in HTTPS?
- AContent Security Policy (CSP) headers.
- BTransport Layer Security (TLS) protocol.
- CHTTP/2 protocol for faster data transfer.
- DSHA-256 hashing for password storage.
Show answer & explanationAnswer & explanation
Correct answer: B. Transport Layer Security (TLS) protocol.
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP, which uses the Transport Layer Security (TLS) protocol to encrypt communications. TLS is responsible for establishing the encrypted channel and ensuring data integrity.
Why the other options are wrong
- A. CSP headers mitigate XSS and data injection attacks by controlling resource loading, not by encrypting the communication channel.
- C. HTTP/2 is a protocol version for performance, not encryption itself.
- D. SHA-256 is a hashing algorithm used for data integrity and password storage, not for establishing an encrypted communication channel.
Transport Layer Security (TLS)
A cryptographic protocol designed to provide communication security over a computer network. It is widely used in applications such as web browsing (HTTPS), email, instant messaging, and voice over IP (VoIP).
- Successor to SSL (Secure Sockets Layer).
- Provides encryption, authentication, and data integrity.
- Forms the 'S' in HTTPS.
Memory trick: HTTPS is secure because TLS is its core.