Capstone: a secure channel from parts

P53.https-in-practice.02 · Audience: guest, it-ml, language-pro · Prerequisites: The TLS 1.3 handshake, Certificates & chains of trust, HMAC, integrity & timing

Real LLM grading for this pageLLM grading (this page):

HTTPS looks like one padlock, but the guarantee behind it is four promises kept at once: nobody read the message, nobody altered it, nobody replayed an old one, and it really came from the peer you meant to talk to. This capstone has you keep all four yourself, assembling parts you built across P52 and P53 into a tiny working secure channel: Diffie–Hellman key agreement for the shared secret, an HMAC tag for integrity and authenticity, a monotonic counter — one that only ever increases — to defeat replays, and a chain-validated certificate to pin down the sender's identity. The hidden suite then attacks your channel with a tampered message, a replayed counter, and an untrusted sender, and the receiver you build must reject every one. When it does, "how HTTPS actually works" stops being a diagram — it ran in your hands.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Capstone — seal and open messages on a secure channel

Loading exercise…

My notes on this module

Loading your notes...

Where next?

Capstone: a secure channel from parts — TransformerLab