The Lab · Cryptography

TLS handshake

A new TLS 1.3 connection opens with the same short conversation every time: two hellos, a Diffie-Hellman agreement, a key schedule, a certificate, a signature and two MACs. We'll step through it in six exhibits using the browser's own crypto, and each exhibit can replay the handshake RFC 8448 publishes, byte for byte.

Everything runs in this tab through Web Crypto, and the page's own X25519 and HKDF are checked against it as they run. The fresh handshake uses throw-away keys, fictional names and a simplified certificate format. Nothing is sent anywhere, and only your progress is saved.

Preparing the handshakes…