Case 16323A · Cryptography · L3 Applied
The TLS 1.3 Handshake
Practise as: Explain it · Interview · Deep dive
Interview questionExplain the TLS 1.3 handshake and what changed from TLS 1.2.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- ClientHello carries key_share (e.g. X25519) so the handshake completes in 1-RTT; 0-RTT is optional with PSKs.
- Only ephemeral (EC)DHE key exchange; static RSA key transport was removed, so forward secrecy is mandatory.
- Everything after ServerHello is encrypted, including the certificate; keys derived with HKDF key schedule.
- CertificateVerify signs the transcript hash; Finished MACs prove both sides saw the same handshake.
- Only AEAD suites remain (AES-GCM, ChaCha20-Poly1305); CBC, RC4, SHA-1 handshake signatures, compression, renegotiation gone.
If the interviewer pushes back
- Why is 0-RTT early data replayable, and what kinds of requests should never be sent in it?
- How does TLS 1.3 downgrade protection work via the ServerHello random value?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.