75
Chromium Blog: Towards HTTPS by default
(blog.chromium.org)
This is a most excellent place for technology news and articles.
Just to expand on that, it's a very basic encryption, but it provides a little bit of a safe standard. When ppl talk about "encrypted communication" they usually talk about more than that. For example, apps like telegram use some more advanced encryption iirc.
The latest version of TLS (used in the latest version of HTTPS), 1.3, is very secure. Most websites these days support 1.3/128 bits, making it quite hard to crack. One major weakness of HTTPS is that, if a certificate authority is compromised, the hackers can issue certificates for ANY website, which browsers will accept as secure until the certificates are revoked/expired/CA removed from trusted list in browser. This loophole can also be exploited by nation states (forcing the CA to issue certificates).
If you are doing something really private, use something like Matrix (E2EE mode), Signal, or Telegram (E2EE DM).
TLDR: Modern HTTPS is incredibly secure, except there is a loophole that nation states and hackers can exploit if they compromise/gain control of an approved certificate authority. If you are doing something you really dont want anyone to find out (top secret files), use an encrypted service that does not rely on the TLS/SSL/HTTPS stack.
Oh, there was an effort to solve above loophole, I’m not sure if it got anywhere though.