What actually happens during a TLS handshake?
The client and server agree on how to encrypt, prove who the server is, and establish a shared key — all before any application data is sent. It happens in milliseconds and is the reason a padlock means anything.
The modern version (TLS 1.3), simplified:
Client hello. The client sends the TLS versions it supports, the cipher suites it will accept, a random value, and — crucially — its key share for a key exchange it is guessing the server will accept. Guessing up front is what makes TLS 1.3 fast.
Server hello. The server picks a version and cipher suite, sends its own random value and key share, and from this point everything else is encrypted.
Certificate. The server presents its certificate chain, proving it holds the private key for that domain. Encrypting this step is a genuine privacy improvement over earlier versions, where certificates were visible.
Verification. The client checks the chain to a trusted root, checks the domain matches, checks expiry, and checks revocation status.
Finished. Both sides confirm the handshake was not tampered with.
What is actually happening cryptographically. The key exchange uses asymmetric cryptography, which is slow, to establish a shared secret. Everything afterwards uses symmetric encryption, which is fast. The handshake exists to bootstrap the fast thing using the slow thing.
Forward secrecy, which is the important property: ephemeral keys are generated per session and discarded. Recording encrypted traffic today and stealing the server's private key later does not decrypt it, which was possible before.
Why it improved:
TLS 1.3 removed a full round trip, halving handshake latency, and removed obsolete algorithms that had caused vulnerabilities.
Session resumption allows returning clients to skip most of it.
What can go wrong: an expired or misconfigured certificate; a missing intermediate, which is the most common real-world error and works in some clients and not others; a wrong clock; and a name mismatch.
What TLS does not hide: the domain you are connecting to remains visible unless encrypted client hello is in use, along with timing and volume.