{"id":4428,"date":"2026-09-24T17:10:25","date_gmt":"2026-09-24T11:40:25","guid":{"rendered":"https:\/\/cybx.in\/blog\/?p=4428"},"modified":"2026-09-24T17:10:27","modified_gmt":"2026-09-24T11:40:27","slug":"tls-vs-ssl-handshakes","status":"publish","type":"post","link":"https:\/\/cybx.in\/blog\/tls-vs-ssl-handshakes\/","title":{"rendered":"TLS vs. SSL Handshakes"},"content":{"rendered":"\n<meta name=\"description\" content=\"Open a secure website and a small conversation happens before the page loads. Your browser and the server need to agree on how they\u2019ll protect the connection\">\n<meta property=\"og:title\" content=\"TLS vs. SSL Handshakes: What\u2019s Actually Different?\">\n<meta property=\"og:description\" content=\"Open a secure website and a small conversation happens before the page loads. Your browser and the server need to agree on how they\u2019ll protect the connection\">\n<meta name=\"twitter:card\" content=\"summary_large_image\">\n<meta name=\"twitter:title\" content=\"TLS vs. SSL Handshakes: What\u2019s Actually Different?\">\n<meta name=\"twitter:description\" content=\"Open a secure website and a small conversation happens before the page loads. Your browser and the server need to agree on how they\u2019ll protect the connection\">\n\n\n<p>You open a secure site and there&#8217;s this tiny back and forth happening before the page even loads, your browser and the server basically negotiating how they&#8217;re going to protect the connection. That&#8217;s the handshake, and it happens in a fraction of a second without you noticing a thing.<\/p>\n<h2>What Was Actually Happening In An SSL Handshake<\/h2>\n<p>Back when SSL was the standard, the handshake worked roughly like this, the client would tell the server which SSL version and security options it could support, and the server would respond with its pick plus a digital certificate to prove who it was.<\/p>\n<p>Once that certificate got checked, both sides worked out shared session keys between them, and those keys ended up encrypting whatever data actually moved across the connection afterward.<\/p>\n<h2>Why SSL Eventually Got Dropped<\/h2>\n<p>Turns out SSL 2.0 and 3.0 both had some genuinely serious security holes. Attackers found ways to exploit parts of the protocol, which meant something better had to come along. SSL 3.0 eventually got officially deprecated, so at this point there&#8217;s really no scenario where you&#8217;d want modern web traffic relying on it.<\/p>\n<p>Here&#8217;s the confusing bit though, seeing &#8220;SSL certificate&#8221; written somewhere today doesn&#8217;t mean that site&#8217;s actually running SSL underneath. The certificate still gets called that out of habit even when TLS is doing all the actual work. Yeah, a little annoying honestly.<\/p>\n<h2>So How&#8217;s A TLS Handshake Different<\/h2>\n<p>Same basic concept really, just a newer protocol with a handshake that&#8217;s evolved over time. Still establishing security settings and shared keys before the real encrypted traffic starts flowing, just done better.<\/p>\n<h2>TLS 1.2 vs TLS 1.3<\/h2>\n<p>TLS 1.2&#8217;s still around and widely used, still an important version honestly. TLS 1.3 came along and stripped out a bunch of older cryptographic choices, simplified the whole handshake process in the process.<\/p>\n<p>Practical difference isn&#8217;t complicated. TLS 1.2 needs a bit more back and forth before secure data can actually start flowing. TLS 1.3 cuts that setup time down noticeably, and fewer steps in a handshake is genuinely just a smarter design choice. Older SSL versions at this point are just dead weight, there&#8217;s no good reason any modern site should be falling back to them.<\/p>\n<h2>The Actual Key Difference Here<\/h2>\n<p>Think of SSL as the earlier generation and TLS as what came after it, kept the core idea but fixed the serious problems. Both were built around the same goal really, establishing trust and encryption before anything sensitive travels across.<\/p>\n<p>But TLS is genuinely what you want running today. The handshake&#8217;s more secure, the newer versions are more efficient, and 1.3 in particular cuts a lot of legacy baggage that just wasn&#8217;t needed anymore.<\/p>\n<p>One thing that trips a lot of people up, that little padlock icon doesn&#8217;t literally mean &#8220;SSL is active.&#8221; It just means the connection&#8217;s secured using modern web security, which in practice almost always means TLS doing the actual work underneath.<\/p>\n<h2>Why Any Of This Actually Matters<\/h2>\n<p>If you&#8217;re running a website, server, or app, this isn&#8217;t just some vocabulary distinction to gloss over. Your server genuinely needs to support the right TLS versions and steer clear of outdated protocols. A certificate on its own doesn&#8217;t automatically make every connection safe, that&#8217;s a common misconception.<\/p>","protected":false},"excerpt":{"rendered":"<p>You open a secure site and there&#8217;s this tiny back and forth happening before the page even loads, your browser&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4428","post","type-post","status-publish","format-standard","hentry","category-learn"],"_links":{"self":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/comments?post=4428"}],"version-history":[{"count":1,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4428\/revisions"}],"predecessor-version":[{"id":4492,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4428\/revisions\/4492"}],"wp:attachment":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/media?parent=4428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/categories?post=4428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/tags?post=4428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}