1

After handshake one could be assure that data are encrypted and secure.

But before that, handshake parameters are transferred via not secured channel. One could be MitM during the handshake procedure.

Why it's not a problem? What actions minimize the threat?

  • How TLS and its protection work is explained in depth already in [How does SSL/TLS work](https://security.stackexchange.com/questions/20803/how-does-ssl-tls-work). Therefore marked as duplicate. – Steffen Ullrich Dec 08 '17 at 09:54

0 Answers0