ByteDance · CS Fundamentals
Explain TLS Handshakes and HTTPS Traffic Inspection
TrueInterview
October 7, 2026 · 2 min read
Describe how HTTPS secures a connection, covering the TLS handshake and certificate validation. Then explain how development tools can inspect HTTPS traffic.
Part 1 — Set up an authenticated connection
Walk through a modern TLS handshake that authenticates the server with a certificate. Specify the TLS version and key-agreement mode you are describing, and explain which properties of the server certificate the client checks.
This part should cover
- Negotiation, key agreement, proof of the server's identity, and integrity of the handshake.
- Validation of the certificate chain and matching the intended service identity.
Part 2 — Protect application data
Does application-data transfer use symmetric or asymmetric cryptography? Explain how the traffic keys are derived from or related to the handshake, and why it is inaccurate to say that all handshake traffic uses asymmetric encryption.
This part should cover
- The distinct roles of key agreement, digital signatures, and authenticated encryption of data.
- Protection against both modification and observation of application records.
Part 3 — Inspect traffic during development
Compare a trusted intercepting proxy such as Charles with passive capture and decryption in Wireshark. Assume the application and test traffic are your own and available for debugging.
This part should cover
- The trust and routing conditions needed for a proxy to terminate TLS.
- The secrets required to decrypt a passive capture.
- Why trusting a root certificate by itself does not decrypt an arbitrary captured session.
What a strong answer covers
- An explanation tied to a specific version instead of mixing legacy RSA key transport with modern ephemeral key agreement.
- Clear distinctions among capture, interception, certificate trust, and possession of traffic secrets.
- Awareness that application trust policies can prevent a development proxy from being accepted.
Follow-up questions
- Why is having a server's long-term private key generally insufficient to decrypt a captured TLS 1.3 session that uses ephemeral key agreement?
- Why might a browser accept a development proxy while an application on the same device refuses it?
Overview: Explain TLS handshakes, certificate validation, and symmetric protection of traffic, then distinguish HTTPS proxy interception from passive decryption.
See the full interview experience this question came from.