Part 6 · 2 chapters · ~12 min
TLS from the Bytes
TLS 1.3 as a composition of the earlier parts: key exchange, the HKDF key schedule, certificates and CertificateVerify, Finished MACs, AEAD records with sequence-number nonces, session resumption and 0-RTT, and what TLS does and does not protect.
11
Every primitive in one protocol
Networking part 7 showed the handshake as messages. Here it is as cryptography: TLS 1.3 is the earlier parts of this course, composed carefully, and its design removed nearly everything that had gone wrong in older versions (RSA key transport, CBC modes, renegotiation, compression).
TLS 1.3, ASSEMBLED FROM PRIMITIVES
every part of this course in one handshake
swipe the figure sideways, or tap expand for full screen
1/5
key exchange
Client and server exchange ephemeral X25519 public keys: forward secrecy (part 4).
ephemeral ECDHEforward secrecy
12
What TLS does not protect
| not protected | why it matters |
|---|---|
| the server name (SNI) and destination IP | observers see which site you visit (Encrypted Client Hello is emerging) |
| traffic size and timing | can reveal which page or action, in some cases |
| data at the endpoints | TLS ends at the load balancer; internal hops need mTLS; data at rest needs its own encryption |
| a compromised endpoint | malware on the phone or server sees plaintext |
| application logic | authorisation, idempotency and validation are still yours |