{"id":4280,"date":"2026-09-22T20:52:39","date_gmt":"2026-09-22T15:22:39","guid":{"rendered":"https:\/\/cybx.in\/blog\/?p=4280"},"modified":"2026-09-22T20:52:41","modified_gmt":"2026-09-22T15:22:41","slug":"how-does-ssl-tls-work","status":"publish","type":"post","link":"https:\/\/cybx.in\/blog\/how-does-ssl-tls-work\/","title":{"rendered":"How Does SSL\/TLS Work?"},"content":{"rendered":"\n<meta name=\"description\" content=\"You see the little padlock in your browser and probably don't think much about it. That's the point. SSL\/TLS works quietly in the background so information m\">\n<meta property=\"og:title\" content=\"How Does SSL\/TLS Work?\">\n<meta property=\"og:description\" content=\"You see the little padlock in your browser and probably don't think much about it. That's the point. SSL\/TLS works quietly in the background so information m\">\n<meta name=\"twitter:card\" content=\"summary_large_image\">\n<meta name=\"twitter:title\" content=\"How Does SSL\/TLS Work?\">\n<meta name=\"twitter:description\" content=\"You see the little padlock in your browser and probably don't think much about it. That's the point. SSL\/TLS works quietly in the background so information m\">\n\n\n<p>You see that padlock in your browser and probably don&#8217;t think much about it. That&#8217;s the point. TLS works quietly in the background so data moving between your browser and a site isn&#8217;t sitting there in plain text.<\/p>\n<p>Modern sites technically use TLS, Transport Layer Security, SSL was the older tech before it. People still say &#8220;SSL certificate&#8221; out of habit, but TLS is really doing the work now.<\/p>\n<h2>What Happens When You Open A Secure Site<\/h2>\n<p>Before any sensitive info gets sent, your browser establishes a secure connection first, starting with a TLS handshake. Browser tells the server which TLS versions it supports, server picks one they both can use, then comes the identity check.<\/p>\n<h2>The Certificate Check<\/h2>\n<p>The site sends its digital certificate, containing its identity info and a public key, issued by a trusted Certificate Authority that&#8217;s already verified the site. Your browser checks if it&#8217;s valid and actually belongs to the site you&#8217;re on. Something&#8217;s off, you get a warning instead of just continuing quietly.<\/p>\n<h2>How Encryption Actually Starts<\/h2>\n<p>The clever bit, browser and server need to agree on a secret key without sending it openly across the internet. Modern TLS uses public-key cryptography for this, a public key the site shares openly and a private key that stays on the server. Both sides establish a shared secret without exposing it to anyone watching.<\/p>\n<p>Once that&#8217;s done, the connection switches to symmetric encryption since it&#8217;s much faster for the actual flow of traffic.<\/p>\n<p>The certificate proves the site&#8217;s identity, so your browser isn&#8217;t blindly trusting whoever answered first. The session key stays secret even though the connection&#8217;s traveling across networks neither side controls. And traffic gets encrypted before it even leaves your device, so snooping doesn&#8217;t get anyone anything readable.<\/p>\n<h2>Why Two Types Of Encryption<\/h2>\n<p>Sounds complicated, isn&#8217;t really. Public-key cryptography&#8217;s great for establishing trust, but using it for every bit of data would be slow. Symmetric encryption handles the ongoing conversation much faster once both sides agree on a key. Handshake does the setup, session key takes over from there.<\/p>\n<h2>What You Actually Notice<\/h2>\n<p>Basically nothing. You see HTTPS and move on, which is actually the point, good security shouldn&#8217;t get in your way. TLS also catches tampering, if someone messes with data mid transit, the cryptographic checks expose it.<\/p>\n<h2>What It Actually Protects<\/h2>\n<p>Think of it as a protected tunnel between your browser and the site, encrypted with checks built in for manipulation. But TLS doesn&#8217;t make a site trustworthy just because it&#8217;s got HTTPS. A scam site can have a valid certificate too. The encryption protects your connection, not the intentions of whoever&#8217;s running the site.<\/p>\n<p>A secure connection to a bad website is still, well, a secure connection to a bad website. Still, TLS does its job well, handshake happens, keys get established, and you barely notice any of it. That&#8217;s exactly how it should feel.<\/p>","protected":false},"excerpt":{"rendered":"<p>You see that padlock in your browser and probably don&#8217;t think much about it. That&#8217;s the point. TLS works quietly&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4280","post","type-post","status-publish","format-standard","hentry","category-learn"],"_links":{"self":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/comments?post=4280"}],"version-history":[{"count":1,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4280\/revisions"}],"predecessor-version":[{"id":4325,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4280\/revisions\/4325"}],"wp:attachment":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/media?parent=4280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/categories?post=4280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/tags?post=4280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}