Watch
TLS Handshake Explained - Computerphile
Walks through how client and server agree keys and how the certificate proves the server's identity, which shows what you give up by disabling certificate verification.
Engineering Fundamentals for the Agent Era
TLS certificate verification disabled in a client to get past an error.
Home-made encryption, a hardcoded key or a reused initialization vector.
An encryption key stored next to the data it protects.
Database exports and backups left unencrypted in a publicly readable storage bucket.
How data moves securely between systems, and how it stays protected where it is stored.
An agent wrote a client for a partner API with certificate verification turned off 'for local testing', and encrypts stored API keys with a key defined as a constant in the same file. Find what an attacker on the network and an attacker who reads the repository can each do.
Watch
Walks through how client and server agree keys and how the certificate proves the server's identity, which shows what you give up by disabling certificate verification.
Shows how to use Google's misuse-resistant Tink library, which chooses algorithms and nonces for you and manages keys as rotatable keysets, instead of assembling primitives by hand.
PyCon 2013 introduction that builds from block and stream ciphers to hashes, MACs and key exchange, showing how naive constructions break and why hashing, MACs and encryption each have a separate job.
A practitioner's map of which primitive to use for which job (authenticated encryption, MACs, signatures, key exchange, TLS), written for engineers rather than mathematicians.
Explains authenticated encryption, hash functions, randomness and TLS's strengths and limits in enough depth that you can spot a reused IV or a home-made scheme.
The deployment reference for TLS 1.3, certificates, validation and PKI failures, from the author of SSL Labs.
RFC
The TLS 1.3 specification, whose security-properties section states exactly what TLS protects (confidentiality, integrity, server authentication) and what it does not.
Reference
Covers algorithm and mode choice, keeping keys separate from data, and envelope encryption with data-encryption and key-encryption keys, the rotation mechanism this subsection asks you to explain.