Open cardosec

Case 16323A · Cryptography · L3 Applied

The TLS 1.3 Handshake

Practise as: Explain it · Interview · Deep dive

Interview questionExplain the TLS 1.3 handshake and what changed from TLS 1.2.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. ClientHello carries key_share (e.g. X25519) so the handshake completes in 1-RTT; 0-RTT is optional with PSKs.
  2. Only ephemeral (EC)DHE key exchange; static RSA key transport was removed, so forward secrecy is mandatory.
  3. Everything after ServerHello is encrypted, including the certificate; keys derived with HKDF key schedule.
  4. CertificateVerify signs the transcript hash; Finished MACs prove both sides saw the same handshake.
  5. Only AEAD suites remain (AES-GCM, ChaCha20-Poly1305); CBC, RC4, SHA-1 handshake signatures, compression, renegotiation gone.

If the interviewer pushes back

  • Why is 0-RTT early data replayable, and what kinds of requests should never be sent in it?
  • How does TLS 1.3 downgrade protection work via the ServerHello random value?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.