A 74-minute block of TCP port 443 by China’s Great Firewall in August 2025 cast HTTPS as both essential web infrastructure and a censorship chokepoint.
HTTPS is the encrypted web-transport protocol that appears in coverage as a baseline security and privacy layer, rather than as a conventional company. Stories connect it to browsers and platform vendors including Google, Chrome, Apple, Firefox and Mozilla, as well as to DNS, Cloudflare, Windows, censorship systems and attacks that seek to bypass or abuse trusted connections.
Coverage peaked in late 2015, during the broader push to make encrypted browsing the norm, and was shaped by failures that made the protocol’s protections tangible: Lenovo’s Superfish adware intercepted HTTPS connections, while the FREAK flaw affected Google and Apple devices. Google’s later report that 75% of requests to its non-YouTube sites were encrypted captured the ensuing adoption shift from exceptional security feature to default web expectation.
Recent stories have moved from adoption toward the limits of that default. Google’s 2023 plan to replace Chrome’s HTTPS lock icon acknowledged that phishing sites also use HTTPS; Cloudflare’s 2022 disclosure of a 26 million-request-per-second HTTPS DDoS attack showed encrypted traffic as an attack surface; and the 2024 .mobi WHOIS-domain lapse enabled researchers to generate counterfeit HTTPS certificates. In 2025, the Great Firewall’s roughly 74-minute blocking of TCP port 443 showed how disrupting HTTPS can affect broad swaths of normal web traffic.
The central tension is that HTTPS has become necessary but not sufficient: browsers such as Chrome and Firefox use it to reduce interception and ISP snooping, yet certificate failures, man-in-the-middle malware, phishing, DDoS traffic and state filtering can exploit or work around the same trusted channel. The Tor Project’s WebTunnel, which mimics HTTPS to evade Tor censorship, further illustrates the contest between tools that blend into ordinary encrypted traffic and networks trying to identify or block them.
If encrypted transport remains the web’s default, security judgments will increasingly depend on the surrounding trust infrastructure—certificate issuance, DNS behavior, browser indicators and network policy—rather than the presence of HTTPS alone. That raises the stakes of failures such as the .mobi certificate episode and port-443 blocking, while leaving open whether browser, infrastructure and anti-censorship changes can preserve HTTPS’s privacy benefits without making abuse or broad disruption harder to detect.
HTTPS has appeared in 77 articles since 2014-12. Coverage peaked in 2020Q1 with 4 articles. Frequently mentioned alongside Google, Chrome, Apple, Firefox.