Loading video...

Video Failed to Load

Go Home

HTTPS clearly explained in 7 minutes

57,561 views • 1 month ago •via X (Twitter)

5 Comments

Petar Ivanov's profile picture
Petar Ivanov1 month ago

Note: "client encrypts a session key with the server's public key" step is the exact part TLS 1.3 removed. It's called RSA key transport, and it got dropped for ephemeral Diffie-Hellman (ECDHE). The reason is forward secrecy. Under RSA, an attacker records your encrypted traffic today, steals the server's private key a year later, and decrypts all of it retroactively. Ephemeral DH uses a throwaway key pair per session, so a stolen key reveals nothing about past traffic. The private key still signs the handshake to prove identity. It just no longer unlocks the conversation.

TechP's profile picture
TechP1 month ago

Detailed explanation

VAI's profile picture
VAI1 month ago

Extremely helpful visualizer & explaining. Thanks, Alex!

veve's profile picture
veve1 month ago

7 menit doang cukup jelas?

Shiv's profile picture
Shiv1 month ago

learned a lot from bytebytego

Related Videos