TLS vs. SSL

Ukuphepha kwe-intanethi kusebenza kanjani

Njengoba kunamaphutha amakhulu kakhulu edatha ezindabeni zakamuva, ungase uzibuze ukuthi idatha yakho ivikelwe kanjani uma uxhumekile ku-intanethi. Uyazi, uya kwiwebhusayithi ukwenza izinto ezithile, faka inombolo yakho yekhadi lesikweletu, futhi ngethemba lokuthi ezinsukwini ezimbalwa iphakheji lifika emnyango wakho. Kodwa kulowo mzuzu ngaphambi kokuchofoza u- oda , ingabe wake wazibuza ukuthi ukuphepha kwe-inthanethi kusebenza kanjani?

Okuyisisekelo Sokuphepha Kwama-intanethi

Ngendlela eyisisekelo kakhulu, ukuphepha kwe-intanethi - yilokho ukuphepha okwenzeka phakathi kwekhompyutha yakho kanye newebhusayithi ovakashelayo - kwenziwa ngokusebenzisa uchungechunge lwemibuzo nezimpendulo. Uthayipha ikheli lewebhu kwisiphequluli sakho , isiphequluli sakho sicela ukuthi isayithi liqinisekise ubuqiniso bayo, isayithi liphendula emuva ngolwazi olufanele, futhi uma kokubili bevumelana, isayithi livuleka kusiphequluli sakho sewebhu.

Phakathi kwemibuzo ebuzwayo kanye nolwazi olushintshaniswayo idatha mayelana nohlobo lokubethela olusetshenziselwa ukudlulisa ulwazi lwesiphequluli sakho, ulwazi lwekhompyutha, nolwazi lomuntu siqu phakathi kwesiphequluli sakho kanye newebhusayithi. Lemibuto nezimpendulo zibizwa ngokuthi ukuxhunyana ngesandla. Uma ngabe ukuxhashazwa kwesandla kungenzeki, i-website ozama ukuyivakashela iyobonakala ingaphephile.

HTTP ngokumelene ne-HTTPS

Into eyodwa ongayibona uma uvakashela amasayithi kuwebhu ukuthi abanye banekheli eliqala nge- http futhi abanye baqala nge- https . I-HTTP isho i- Hypertext Transfer Protocol ; kungumthetho noma isethi yemihlahlandlela ebeka ukuxhumana okuphephile phezu kwe-intanethi. Ungase uqaphele ukuthi amanye amasayithi, ikakhulukazi amasayithi lapho uceliwe ukuba unikeze ulwazi olubucayi noma olukhomba ukuthi ungabonisa ukuthi i- https noma iluhlaza noma inombomvu. I-HTTPS isho i-Hypertext Transfer Protocol Evikelekile, futhi okuluhlaza kusho isayithi esinesitifiketi sokuphepha esiqinisekisiwe. Okubomvu ngendlalelo kusho ukuthi isayithi ayinaso isitifiketi sokuphepha, noma isitifiketi asinembile noma iphelelwe yisikhathi.

Nakhu lapho izinto zithola ukudideka okuncane. I-HTTP ayisho ukuthi idatha idluliselwe phakathi kwikhompyutha yakho nokuthi iwebhusayithi ibhalwe ngekhodi. Kusho kuphela ukuthi iwebhusayithi ekhuluma nesiphequluli sakho isitifiketi sokuphepha esisebenzayo. Kuphela uma i- S (njengase-HTTP S ) ifakiwe idatha edluliselwa ephephile, futhi kukhona omunye ubuchwepheshe obusetshenziselwa ukwenza lokho kukhishwa okuphephile .

Ukuqonda Uhlelo lwe-SSL

Uma ucabangela ukwabelana ngokubambisana nomunye umuntu, lokho kusho ukuthi kukhona iqembu elibili elihilelekile. Ukuphepha kwe-intanethi kufana ngendlela efanayo. Ngokubambisana okuqinisekisa ukuthi ukuphepha ku-intanethi kufanele kwenzeke, kumele kube khona iqembu lesibini elihilelekile. Uma i-HTTPS iyi-protocol esetshenziselwa isiphequluli sewebhu ukuqinisekisa ukuthi kukhona ukuphepha, ingxenye yesibili yalokhu ukuxhawula ngesandla yi-protocol eqinisekisa ukubethela.

Ukubethela ubuchwepheshe obusetshenziselwa ukuguqula idatha edluliselwa phakathi kwamadivayisi amabili kunethiwekhi. Kufeziwe ngokushintsha izinhlamvu ezibonakalayo zibe yi-gibberish engaqondakali engabuyiselwa esimweni sayo sokuqala usebenzisa ukhiye wokubhala. Lokhu kwasekuqaleni kufinyelelwe kubuchwepheshe obubizwa nge- Secure Socket Layer (SSL) .

Empeleni, i-SSL yayibuchwepheshe obuphendulela noma iyiphi idatha ehamba phakathi kwewebhusayithi nesiphequluli ukuze iguquke bese ibuyela emuva kudatha. Nakhu ukuthi kusebenza kanjani:

Inqubo iphinda yona uma ufaka igama lakho lomsebenzisi nephasiwedi, ngezinye izinyathelo ezengeziwe.

Le nqubo iyenzeka kumasekhondi we-nano, ngakho-ke awuboni isikhathi esithatha ngayo le ngxoxo yonke futhi uxhumane ngokuhlanganyela phakathi kwesiphequluli sewebhu kanye newebhusayithi.

SSL vs TLS

I-SSL yayiyi-protocol yokuvikela yangempela eyayisetshenziselwa ukuqinisekisa ukuthi amawebhusayithi nedatha edlula phakathi kwabo bephephile. Ngokusho kwe-GlobalSign, i-SSL yathulwa ngo-1995 njengenguqulo 2.0. Inguqulo yokuqala (1.0) ayizange ibe yindlela eya esizindeni somphakathi. I-Version 2.0 ishintshwe ngu-version 3.0 phakathi nonyaka ukubhekana nokukhubazeka kwiprothotho. Ngo-1999, enye inguqulo ye-SSL, ebizwa ngeText Layer Security (TLS) yasungulwa ukuze ithuthukise ijubane lenkulumo nokuphepha kwesandla. I-TLS yiyona nguqulo esebenzayo njengamanje, nakuba ivame ukubizwa ngokuthi i-SSL ngenxa yokulula.

Ukubethela kwe-TLS

Ukubethela kwe-TLS kuqaliswe ukuthuthukisa ukuphepha kwedatha. Ngenkathi i-SSL yayibuchwepheshe obuhle, izinguquko zokuphepha zihamba ngokushesha, futhi lokho kwaholela ekudingeni ukuthi kube nokuvikeleka okungaphezulu kokusesikhathini. I-TLS yakhiwe ngohlaka lwe-SSL ngokuthuthukiswa okuphawulekayo kuma-algorithms alawula inqubo yokuxhumana nokusebenza ngesandla.

Nguyiphi i-TLS Version Eningi kakhulu yamanje?

Njenge-SSL, ukubethela kwe-TLS kuyaqhubeka nokuthuthukisa. Inguqulo yamanje ye-TLS ngu-1.2, kodwa i-TLSv1.3 ibhalwe phansi futhi ezinye izinkampani kanye neziphequluli zisebenzise ukuphepha okwesikhashana. Ezimweni eziningi, babuyela emuva ku-TLSv1.2 ngoba inguqulo 1.3 isapheleliswa.

Uma kuqedile, i-TLSv1.3 izoletha ukuthuthukiswa okuningi kokuphepha, kufaka phakathi ukwesekwa okuthuthukisiwe kwezinhlobo eziningi zamanje zokubethela. Kodwa-ke, i-TLSv1.3 izophinde ilahle ukusekelwa kwezinguqulo ezindala zezinhlelo ze-SSL nezinye ubuchwepheshe bokuphepha ezingasenamandla okwanele ukuqinisekisa ukuphepha okufanele nokubethelwa kwedatha yakho yomuntu siqu.