What you’ll be able to do
- Name what cafe Wi-Fi may observe during a modern TLS handshake (ephemeral public values) versus where the shared session secret appears (derived locally at both ends).
- Explain that the session secret is not sent as a shared password on the wire.
- Separate certificate name-bind for a typed name from human authentication and authorization to open a shipment.
Public values travel. The session secret does not.
After TCP reaches ESTABLISHED, TrackPort and the customer’s phone still need a protected application conversation. In a modern TLS 1.3 handshake they exchange ephemeral public values. Cafe Wi-Fi on the path may observe those public stubs. Both ends then derive a shared session secret locally. That secret is used to protect the HTTP bytes. It is not sent as a password on the wire.
A certificate binds a public key to a name such as track.riverstone.example. A matching name-bind is a check on the owner of that name for this connection. It is not proof of which human sits at the phone, and it is not authorization to open shipment 8821. A padlock and a valid certificate for a typed name still leave authentication and authorization to the application. More on that edge: the TLS glossary and the encryption-not-the-right-owner misconception.
You do not need the full TLS 1.3 transcript. Watch which values travel on the cafe-visible rail, where the session-secret wells fill, and what fails when the certificate name does not match the name the customer typed. Reachability stays with the TCP lesson. Name, DNS, and cookie faults stay with the Networks relay-race figure.
SESSION SECRET
The secret stays at the ends
Watch public values travel and session secrets form locally.
Client phone and TrackPort Server prepare a protected conversation.
Which path explains this picture?
Password on wire exposes a secret to the cafe. Shared secret derives locally at both ends.
Which path explains this picture?
Wrong-name cert refuses the typed TrackPort name. A matching name still does not authorize a human.
Chapter 1 of 5
Read all chapters
Plays once when the picture comes into view, then stops. Play resumes; Replay starts over. Scrub or choose a chapter to pause and inspect. Leaving the picture or hiding the tab pauses playback. Reduced motion shows still chapters with no travel.
Shared secret
- Client phone and TrackPort Server prepare a protected conversation.Riverstone uses TrackPort. Cafe Wi-Fi can observe the rail. Both session-secret wells are empty. No identity or permission is granted.
- An ephemeral public value travels from Client to Server. Cafe Wi-Fi may see it.The public stub crosses the rail. Private material stays inside each house. The session-secret wells remain empty.
- Server sends its public value back. The certificate matches the typed TrackPort name.Name bind holds for track.riverstone.example. Private material stays inside Server. No session secret travels.
- Both ends derive the same session secret locally. Nothing secret crosses the rail.The twin wells fill inside their houses. The public stubs park. The session secret protects HTTP bytes.
- Public values travel. The session secret does not.A certificate binds a public key to a name. It does not prove human identity, a trustworthy business, or permission to open shipment 8821.
Password on wire
- Client phone and TrackPort Server prepare a protected conversation.Riverstone uses TrackPort. Cafe Wi-Fi can observe the rail. Both session-secret wells are empty. No identity or permission is granted.
- This anti-path sends a password on the cafe rail. It is not how the shared TLS secret is derived.A warm, notched password stub travels Client to Server. Cafe Wi-Fi sees the secret. Both local wells stay empty.
- This anti-path sends a password on the cafe rail. It is not how the shared TLS secret is derived.A warm, notched password stub travels Client to Server. Cafe Wi-Fi sees the secret. Both local wells stay empty.
Wrong-name cert
- Client phone and TrackPort Server prepare a protected conversation.Riverstone uses TrackPort. Cafe Wi-Fi can observe the rail. Both session-secret wells are empty. No identity or permission is granted.
- An ephemeral public value travels from Client to Server. Cafe Wi-Fi may see it.The public stub crosses the rail. Private material stays inside each house. The session-secret wells remain empty.
- Wrong name. Client refuses this connection as TrackPort.Typed track.riverstone.example differs from certificate track.riverst0ne.example. The Server name-bind seal cracks. Trust does not settle.
- Wrong name. Client refuses this connection as TrackPort.Typed track.riverstone.example differs from certificate track.riverst0ne.example. The Server name-bind seal cracks. Trust does not settle.
Read this as a table
Ephemeral public values may cross cafe Wi-Fi. Both ends derive a shared session secret locally. Password on wire exposes a secret. Wrong-name cert refuses TrackPort trust. A name bind is not human authorization.
| Path / chapter | What changes |
|---|---|
| Place | Client phone and TrackPort Server prepare a protected conversation. |
| Public out | An ephemeral public value travels from Client to Server. Cafe Wi-Fi may see it. |
| Public back | Server sends its public value back. The certificate matches the typed TrackPort name. |
| Derive | Both ends derive the same session secret locally. Nothing secret crosses the rail. |
| Settle | Public values travel. The session secret does not. |
| Password on wire | A warm, notched password stub travels Client to Server. Cafe Wi-Fi sees the secret. Both local wells stay empty. |
| Wrong-name cert | Typed track.riverstone.example differs from certificate track.riverst0ne.example. The Server name-bind seal cracks. Trust does not settle. |
Scene checked 2026-09-28.
CHECK THE PICTURE
Cafe Wi-Fi watched a customer phone complete a TLS session to TrackPort for track.riverstone.example. What rode the cafe path, and where did the shared session secret appear?
Name-bind is not human permission
Certificate name-bind answers whether this connection’s certificate matches the name the customer typed. On the figure, wrong-name refuses TrackPort trust when the cert names a lookalike. That is the check working.
Name-bind does not authenticate which human holds the phone. It does not authorize shipment 8821. Those checks stay with the application after the TLS session exists.
Reachability and what comes next
On the Riverstone cast, the customer’s phone still needs TCP ESTABLISHED before any of this matters. That road lives on the TCP elective: Three packets. Then ESTABLISHED. Name, DNS, cookie, and wrong-host faults live on the Networks lesson’s relay-race figure.
Come back here when someone treats a padlock as proof that cafe Wi-Fi already shared a password, or that encryption proved the right human and the right shipment. Public values may travel. The session secret does not. Permission stays with the application.
CHECK YOUR JUDGMENT