How HTTPS actually works, building the impossible-looking part
Every time you see the padlock, your browser and a server you have never contacted before agreed on a secret encryption key, and they did it over a network where anyone, your ISP, a coffee-shop router, an attacker, can read every byte that passes. Stop and feel how strange that is. Two people shout numbers at each other across a crowded room, everyone hears every number, and at the end the two of them share a secret that no listener can figure out. That is the heart of HTTPS, and the mechanism, Diffie-Hellman key exchange, is one of the most beautiful ideas in computing. You can build it.
The one idea
The trick rests on a mathematical operation that is easy to do and hard to undo. Raising a number to a power modulo a big prime is fast. Going backward, given the result, recovering the exponent, is the discrete logarithm problem, and for a large enough prime it would take longer than the age of the universe. So each side picks a private exponent, publishes the result of the easy direction, and combines the other side's public result with its own private exponent. Because exponents multiply the same way regardless of order, both sides land on the identical number. The eavesdropper has both public results but neither private exponent, and cannot reverse the easy operation to get them. The secret is built from parts that were never sent.
Build the exchange
Use a real 2048-bit prime (the ones HTTPS actually uses come from published standards) and the generator g = 2. Alice and Bob each pick a private secret and send only g to their secret, modulo p.
import secrets, hashlib
p = 0xFFFFFFFF... # a standard 2048-bit safe prime (RFC 3526)
g = 2
a, b = secrets.randbelow(p-2)+1, secrets.randbelow(p-2)+1 # private, never sent
A = pow(g, a, p) # Alice publishes this
B = pow(g, b, p) # Bob publishes this
alice_shared = pow(B, a, p) # Alice: Bob's public, raised to her secret
bob_shared = pow(A, b, p) # Bob: Alice's public, raised to his secret
Run it and the two shared values are identical, because both equal g to the power a times b, reached from two directions:
Alice and Bob agree on a secret: True
eavesdropper has A, B, p, g but not a, b -> stuck
Three details that matter:
pow(g, a, p)is easy; inverting it to findafromAis the discrete log, and at 2048 bits no known algorithm does it in feasible time. The entire security rests on that asymmetry, easy forward, impossibly hard backward.- The private exponents
aandbnever leave their machines. OnlyAandBgo on the wire. An attacker who records the whole conversation still cannot compute the shared secret, which is why HTTPS protects data even against someone who saves every packet. - Modern HTTPS uses the elliptic-curve version of this exact idea, ECDHE, which gets the same security from much smaller numbers and is faster. The concept is unchanged: a one-way operation combined in two orders to the same result.
From shared secret to encrypted traffic
The shared number is not the key itself; you hash it into a proper symmetric key, then use fast symmetric encryption for the actual data. Here is that second half in miniature, one derived key encrypting a request and decrypting it back.
key = hashlib.sha256(str(alice_shared).encode()).digest()
cipher = stream_xor(b"GET /account HTTP/1.1", key)
plain = stream_xor(cipher, key) # Bob derives the same key, recovers the text
ciphertext (hex): 63ca5d780dcd948b5053560ba06300f0 ...
Bob decrypts: GET /account HTTP/1.1
The request traveled as unreadable bytes and came back out as plain text on the other side, using a key that was never transmitted. Real HTTPS uses AES-GCM here instead of a toy XOR stream, which also authenticates the data so it cannot be tampered with, but the shape is exactly this: exchange a secret with Diffie-Hellman, encrypt the bulk traffic with a symmetric cipher.
Where this shows up
This is the core of the TLS handshake behind every HTTPS connection, plus one more piece: a certificate, signed by a trusted authority, that proves the server you exchanged keys with is really the site in the address bar and not an impostor in the middle. That signature is what stops an active attacker from doing their own key exchange with each side. Diffie-Hellman gives you a secret with a stranger; certificates tell you the stranger is who they claim. Together they are the padlock.
If you want to build the certificate checks, the symmetric ciphers, and the full handshake, then attack the weak versions to see why each piece exists, that is the path the cybersecurity track on IWTLP walks through, cryptography you build rather than trust.