ContentsThe library

How a Message Stays Private

Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requested

Last timeSomebody Vouching

The complete exchange, in order, with each message traced back to the lesson it came from. Then the cost in round trips, and the two mechanisms that get it down to one or zero.

The exchange in order

Nothing new is introduced in this lesson. Key agreement came from the second,

encryption from the third, the identity problem from the fourth, and

certificates from the fifth. What remains is the order, and the order is short.

FIG 1The complete handshake
Ten steps and two network crossings. Read the right-hand column of the trace below to see which lesson each step came from, because no step here is new and the arrangement is the only thing being taught.
FIG 2Each message, and where it came from
stepdirectionwhat is sentthe job it serveslessonwhat happened
1client to serverversions, ciphers, a key sharekey agreementagreeing a secret in publicAlso carries the name of the site being asked for, which is the one field an observer can still read if the extension that encrypts it is not in use.
2server to clienta key sharekey agreementagreeing a secret in publicWith this, both sides compute the same secret from values that were all sent in the clear. Everything following is encrypted.
3server to clientcertificate chainidentitysomebody vouchingEncrypted, so it is no longer visible to a watcher. The chain is validated against the roots already on the machine.
4server to clienta signature over the transcriptbinding identity to this conversationwho you are talking toProves possession of the private key in the certificate, and proves it about this conversation rather than any other.
5both waysfinished messagesintegrity of the handshakeencrypting the bytesA value computed over the whole transcript with the derived keys. Any tampering anywhere in the handshake shows up here.
6client to serverthe actual requestthe point of all thisfrom an address to a pageOne round trip after the first message left. The request itself is the sixth thing sent and the first thing anybody wanted.
6 steps
Six rows, and five of them are overhead. The last column is the useful summary: nothing in the handshake is novel, and the design work was in finding an order where one message in each direction suffices.

What each message buys

The useful discipline is to take each message away and ask what breaks. Three

of them are load bearing in ways that are easy to miss.

FIG 3Remove one message and see what fails
no shared secret at allno idea who answeredan old recording can be
the two key shares100
the certificate010
the signature over the t011
the finished messages001
The marked row is the one people forget. The certificate on its own is a public document, so presenting it proves nothing. Only the signature over this transcript shows that the party answering holds the matching private key and is answering now, which is why that single message closes both of the two lower columns.

The signature deserves the extra sentence. It is computed over every byte of

the handshake up to that point, which includes the client key share, which the

client chose at random moments ago. An attacker replaying a recorded signature

would be replaying it over a different transcript, and the check fails. The

freshness comes free from the thing that was already there for key agreement.

The lesson stops here

3 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedyou are here
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside