{"id":4425,"date":"2026-09-24T17:16:18","date_gmt":"2026-09-24T11:46:18","guid":{"rendered":"https:\/\/cybx.in\/blog\/?p=4425"},"modified":"2026-09-24T17:16:19","modified_gmt":"2026-09-24T11:46:19","slug":"what-is-different-about-a-handshake-in-tls-1-3","status":"publish","type":"post","link":"https:\/\/cybx.in\/blog\/what-is-different-about-a-handshake-in-tls-1-3\/","title":{"rendered":"What Is Different About a Handshake in TLS 1.3?"},"content":{"rendered":"\n<meta name=\"description\" content=\"A TLS handshake used to feel like a long introduction before the actual conversation could begin. TLS 1.3 trims that introduction quite a bit. The goal is si\">\n<meta property=\"og:title\" content=\"What Is Different About a Handshake in TLS 1.3?\">\n<meta property=\"og:description\" content=\"A TLS handshake used to feel like a long introduction before the actual conversation could begin. TLS 1.3 trims that introduction quite a bit. The goal is si\">\n<meta name=\"twitter:card\" content=\"summary_large_image\">\n<meta name=\"twitter:title\" content=\"What Is Different About a Handshake in TLS 1.3?\">\n<meta name=\"twitter:description\" content=\"A TLS handshake used to feel like a long introduction before the actual conversation could begin. TLS 1.3 trims that introduction quite a bit. The goal is si\">\n\n\n<p>A TLS handshake used to feel like a long introduction before the actual conversation could begin. TLS 1.3 trims that introduction quite a bit. The goal is simple: establish security faster, with fewer messages moving back and forth before encrypted data can flow.<\/p>\n<h2>TLS 1.3 Gets to Encryption Faster<\/h2>\n<p>The biggest change is the number of round trips. In a normal TLS 1.3 connection, the client sends its initial message and includes information that lets the server choose the connection settings. The server can then respond with its own handshake messages and encrypted data can follow much sooner.<\/p>\n<p>With older TLS versions, the handshake involved more back-and-forth before both sides reached that point. And network delay matters. A lot. Even if your server is fast, waiting for another trip across the internet still takes time.<\/p>\n<h3>The Client Says More Up Front<\/h3>\n<p>A TLS 1.3 ClientHello carries more useful information than the first message in older versions. It includes a key share, which gives the server what it needs to establish the shared secret without starting another negotiation round.<\/p>\n<p>So the handshake feels quicker because the client arrives prepared rather than asking the server to come back with another step.<\/p>\n<h2>Older Security Options Are Gone<\/h2>\n<p>TLS 1.3 also cleans house. Several older cryptographic choices were removed because they weren&#8217;t worth keeping around anymore. The protocol no longer negotiates older features such as static RSA key exchange.<\/p>\n<p>That matters because TLS 1.3 focuses on forward secrecy. The handshake uses ephemeral key exchange, meaning a compromised long-term key doesn&#8217;t automatically expose old recorded sessions.<\/p>\n<h3>Fewer Choices, Fewer Headaches<\/h3>\n<p>Honestly, this is one of my favorite changes. A protocol doesn&#8217;t become better just because it has a giant menu of options. TLS 1.3 cuts away a lot of legacy baggage.<\/p>\n<p>\u2022 No static RSA key exchange. That&#8217;s a major break from older TLS designs.<\/p>\n<p>\u2022 Forward secrecy is built into the normal handshake, rather than being something administrators need to think about separately.<\/p>\n<p>\u2022 The handshake messages after the initial exchange are encrypted, which hides more of the negotiation from someone watching the connection.<\/p>\n<h2>Encryption Starts Earlier<\/h2>\n<p>Another important difference is when encryption kicks in. In TLS 1.3, once the necessary key material has been exchanged, much of the remaining handshake is protected.<\/p>\n<p>That includes information that was more exposed during older handshakes. The server certificate is still sent as part of authentication, but it travels inside encrypted handshake traffic.<\/p>\n<h3>What About Resuming a Connection?<\/h3>\n<p>TLS 1.3 also improves connection resumption. After a successful connection, the server can provide a ticket that the client uses later. On the next connection, both sides already have some shared context, so the handshake can become even shorter.<\/p>\n<h2>Why TLS 1.3 Feels Different<\/h2>\n<p>The handshake isn&#8217;t merely shorter for the sake of being shorter. It was redesigned around modern cryptography and lower connection latency. The client sends useful key information early. The server responds with what it needs. Then protected communication gets moving.<\/p>\n<p>There&#8217;s also a useful side effect. Removing old cryptographic options makes the protocol easier to reason about. Fewer dusty corners means fewer places for outdated security choices to hang around.<\/p>\n<p>And once a TLS 1.3 connection becomes routine, you stop noticing the handshake at all. That&#8217;s probably the best outcome. Security should be doing its job quietly while you get on with whatever you opened that browser tab for.<\/p>","protected":false},"excerpt":{"rendered":"<p>A TLS handshake used to feel like a long introduction before the actual conversation could begin. TLS 1.3 trims that&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4425","post","type-post","status-publish","format-standard","hentry","category-learn"],"_links":{"self":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/comments?post=4425"}],"version-history":[{"count":1,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4425\/revisions"}],"predecessor-version":[{"id":4495,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4425\/revisions\/4495"}],"wp:attachment":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/media?parent=4425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/categories?post=4425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/tags?post=4425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}