TLS 1.3 (Transport Layer Security version 1.3, standardised in RFC 8446, August 2018) is the current major version of the TLS protocol, redesigned to eliminate legacy cryptographic weaknesses, reduce handshake round-trips from two to one (zero for session resumption), mandate forward secrecy on every connection, and restrict the cipher suite to a small set of authenticated encryption algorithms. It replaces TLS 1.2 as the baseline secure transport for HTTPS, QUIC, and virtually all authenticated internet communications.
Content
- TLS 1.3 development began in 2014 as IETF Working Group TLS started addressing the structural weaknesses exposed by attacks on TLS 1.2 and earlier: BEAST, POODLE, DROWN, FREAK, Logjam, and others all exploited legacy RSA key exchange, RC4, CBC padding, or export-grade cryptography. After 28 drafts spanning four years—the longest IETF standardisation process for a security protocol—RFC 8446 was published in August 2018. Adoption was rapid: major browsers enabled TLS 1.3 by default within months.
- The TLS 1.3 handshake requires only one round-trip (1-RTT) for a new connection and zero round-trips (0-RTT) for resumed sessions using pre-shared keys, halving or eliminating handshake latency relative to TLS 1.2. The handshake exclusively uses Diffie-Hellman key exchange (ECDHE with X25519, P-256, or FFDHE groups), eliminating static RSA key exchange and guaranteeing perfect forward secrecy. Supported cipher suites are restricted to three AEAD algorithms: AES-128-GCM, AES-256-GCM, and ChaCha20-Poly1305. Session tickets replace session IDs for resumption, and downgrade protection is built into the ServerHello random field.
- TLS 1.3 is the security foundation for essentially all authenticated internet traffic: HTTPS, email (STARTTLS/SMTPS), LDAPS, database connections, and API calls. Its 0-RTT mode directly inspired QUIC’s design, making TLS 1.3 integral to HTTP/3. The protocol’s removal of obsolete cryptography has substantially reduced the attack surface for passive decryption and active downgrade attacks, and its mandatory forward secrecy means recorded traffic cannot be decrypted even if long-term keys are later compromised.
- As of 2024–2025, TLS 1.3 accounts for over 90% of HTTPS connections observed by Cloudflare and Google, with TLS 1.2 persisting mainly for legacy enterprise systems. Post-quantum cryptography integration is the active frontier: IETF and NIST are standardising hybrid key exchange (X25519Kyber768, ML-KEM) for TLS 1.3 to maintain forward secrecy against future quantum adversaries. Several browsers and CDNs already ship experimental post-quantum TLS 1.3 support. RFC 8446bis (TLS 1.3 errata consolidation) is in progress, and TLS 1.3 is also the handshake layer for QUIC/HTTP3 deployments now covering over 30% of web traffic.