Part 6 · 2 chapters · ~12 min

TLS from the Bytes

TLS 1.3 as a composition of the earlier parts: key exchange, the HKDF key schedule, certificates and CertificateVerify, Finished MACs, AEAD records with sequence-number nonces, session resumption and 0-RTT, and what TLS does and does not protect.

11

Every primitive in one protocol

Networking part 7 showed the handshake as messages. Here it is as cryptography: TLS 1.3 is the earlier parts of this course, composed carefully, and its design removed nearly everything that had gone wrong in older versions (RSA key transport, CBC modes, renegotiation, compression).

TLS 1.3, ASSEMBLED FROM PRIMITIVES
every part of this course in one handshake
key exchange (part 4)X25519 (or hybrid X25519 + ML-KEM) shares in ClientHello / ServerHellokey schedule (HKDF)handshake and traffic keys derived from the shared secret and transcript hashcertificate (part 5)the server's chain, sent encryptedCertificateVerify (part 3)server signs the transcript hash with its certificate keyFinished (part 0)HMAC over the transcript with a handshake keyrecords (part 1)AES-GCM or ChaCha20-Poly1305 with per-record nonces
swipe the figure sideways, or tap expand for full screen
1/5
key exchange
Client and server exchange ephemeral X25519 public keys: forward secrecy (part 4).
ephemeral ECDHEforward secrecy
12

What TLS does not protect

not protectedwhy it matters
the server name (SNI) and destination IPobservers see which site you visit (Encrypted Client Hello is emerging)
traffic size and timingcan reveal which page or action, in some cases
data at the endpointsTLS ends at the load balancer; internal hops need mTLS; data at rest needs its own encryption
a compromised endpointmalware on the phone or server sees plaintext
application logicauthorisation, idempotency and validation are still yours