Capstone: a secure channel from parts
P53.https-in-practice.02 · Audience: guest, it-ml, language-pro · Prerequisites: The TLS 1.3 handshake, Certificates & chains of trust, HMAC, integrity & timing
HTTPS looks like one padlock, but the guarantee behind it is four promises kept at once: nobody read the message, nobody altered it, nobody replayed an old one, and it really came from the peer you meant to talk to. This capstone has you keep all four yourself, assembling parts you built across P52 and P53 into a tiny working secure channel: Diffie–Hellman key agreement for the shared secret, an HMAC tag for integrity and authenticity, a monotonic counter — one that only ever increases — to defeat replays, and a chain-validated certificate to pin down the sender's identity. The hidden suite then attacks your channel with a tampered message, a replayed counter, and an untrusted sender, and the receiver you build must reject every one. When it does, "how HTTPS actually works" stops being a diagram — it ran in your hands.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Capstone — seal and open messages on a secure channel
Loading exercise…
My notes on this module
Loading your notes...