Get a free website with any plan

See how
INTERNET ESSENTIALS

HTTP, HTTPS, HTTP/2 and HTTP/3 explained

Last updated

IN SHORT

HTTP transfers web data in plain text, while HTTPS encrypts that traffic using TLS for security and search rankings. HTTP/2 and HTTP/3 speed up loading by multiplexing requests over fewer connections. Flashcloud handles HTTPS and HTTP/2 automatically on hosted domains with free, auto-renewing SSL certificates and LiteSpeed Web Server.

HTTP is the protocol browsers and servers use to exchange requests and responses. HTTPS is the same protocol wrapped in encryption. HTTP/2 and HTTP/3 are newer versions of the transport layer underneath both, built to move data faster over the same connection. You need HTTPS for security and SEO, and modern hosting typically handles HTTP/2 or HTTP/3 automatically, no configuration required.

If you're troubleshooting a specific error code rather than trying to understand the protocol itself, see HTTP status codes explained.

HTTP: the base protocol

HTTP (Hypertext Transfer Protocol) defines how a client, usually a browser, asks a server for a resource and how the server replies. A request has a method (GET, POST, PUT, DELETE, and others), a URL, headers, and sometimes a body. A response has a status code, headers, and usually a body: HTML, JSON, an image, whatever was asked for.

HTTP itself is plain text on the wire. Anyone sitting between the browser and the server, a coffee shop Wi-Fi router, an ISP, a compromised network device, can read every request and response, including form submissions and login credentials. That's the problem HTTPS solves.

HTTPS: HTTP over TLS

HTTPS is HTTP sent through a TLS (Transport Layer Security) encrypted connection. Before any HTTP data moves, the browser and server perform a TLS handshake: they agree on encryption methods and the server proves its identity with an SSL/TLS certificate signed by a trusted certificate authority. Once that handshake completes, everything sent over the connection is encrypted, so an eavesdropper sees scrambled bytes instead of readable data.

This matters for three reasons. First, security: passwords, payment details, and session cookies stay private in transit. Second, trust: browsers mark plain HTTP sites as "Not secure" and will refuse to run certain features (camera, geolocation, service workers) without HTTPS. Third, SEO: search engines treat HTTPS as a ranking signal and will not show the padlock without it.

On Flashcloud, every hosted domain gets a free Let's Encrypt SSL certificate, issued automatically within about 5 minutes of your domain pointing to us, and renewed automatically before it expires. You don't request it or install it yourself.

HTTP/2: multiplexing over one connection

HTTP/1.1 has a bottleneck: a browser can only run a limited number of requests at a time per connection to a domain, so loading a page with dozens of images, scripts, and stylesheets means either queuing requests or opening several connections, each with its own overhead.

HTTP/2 fixes this with multiplexing: many requests and responses travel over a single TCP connection at the same time, interleaved as binary frames instead of queued as plain text. It also compresses headers (which repeat a lot between requests) and lets the server push resources it knows the browser will need. The practical effect is pages with many small assets load faster, with no code changes required on your end.

HTTP/3: built on QUIC instead of TCP

HTTP/2 still rides on TCP, which has its own weakness: if a single packet is lost, TCP blocks the entire connection until that packet is retransmitted, even for unrelated requests. This is called head-of-line blocking, and it's worse on unstable connections like mobile networks.

HTTP/3 replaces TCP with QUIC, a transport protocol built on UDP. QUIC handles each stream independently, so a lost packet only stalls the one request it belongs to, not the whole connection. QUIC also folds the TLS handshake into its own connection setup, which shaves a round trip off the time to first byte compared to TCP plus TLS. The result is a faster, more resilient connection, especially on unstable Wi-Fi or cellular data.

What this means for your site

You don't choose HTTP/2 or HTTP/3 the way you choose a WordPress theme. They're negotiated automatically between the browser and the server's web server software, and both sides fall back gracefully to an older version if either doesn't support the newer one. Flashcloud runs LiteSpeed Web Server on shared and WordPress plans, which supports HTTP/2, alongside LSCache for page caching. Combined with the automatic SSL mentioned above, a site on Flashcloud gets HTTPS and HTTP/2 without any manual setup.

The one thing worth checking on your own site is mixed content: if your HTML references any resources (images, scripts, stylesheets) over plain http:// instead of https://, browsers will block or warn on them even though your main page is secure. Search your site's HTML or database for hardcoded http:// links pointing at your own domain and switch them to https:// or protocol-relative paths.

When to contact support

If your domain shows "Not secure" more than a few minutes after DNS points to us, or a certificate error persists, open a ticket from Support in the portal. A real person will look into it.

Common questions

How do I get an SSL certificate for my domain?

You do not need to install anything. Flashcloud automatically issues a free Let's Encrypt SSL certificate within about 5 minutes of your domain pointing to our servers, then renews it automatically before expiration.

Why is my site showing a not secure warning?

Your page probably contains mixed content. This happens when secure pages reference images, scripts, or styles over plain http:// URLs. Update those hardcoded links to https:// or protocol-relative paths to clear the browser warning.

How do I turn on HTTP/2 on my account?

No setup is needed on your end. Browsers and web servers negotiate the protocol automatically, and Flashcloud supports HTTP/2 out of the box on shared and WordPress plans using LiteSpeed Web Server.

What makes HTTP/3 different from HTTP/2?

HTTP/3 replaces TCP with QUIC to eliminate head-of-line blocking. A lost packet only delays its specific request instead of freezing the whole connection, which speeds up browsing on unstable Wi-Fi and mobile networks.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.