What's happening?
- Browser and server each pick a secret number and exchange only derived public values (Diffie-Hellman).
- Each combines its own secret with the other's public value and gets the same key; an eavesdropper with only the public values cannot.
- The server's certificate, signed by an authority the browser trusts, proves the key really belongs to the site — which is what stops a man-in-the-middle.
Where you'll meet it
Every padlock in the address bar, every API call from an app, and the reason public Wi-Fi can't read your passwords.
Common mistake
Thinking encryption alone is enough. Without checking the certificate, you could have a perfectly encrypted connection to an attacker.
FAQ
Are the numbers here real?
The maths is real; the numbers are tiny so you can check them. Real handshakes use 256-bit elliptic-curve values.
What can someone on the network still see?
Which server you connected to and how much data moved — not the pages, forms or cookies inside.
TLS 1.2 vs 1.3?
TLS 1.3 finishes in one round trip instead of two, encrypts the certificate, and removed weak old ciphers.