logoalt Hacker News

lvlabguytoday at 12:23 AM0 repliesview on HN

Basically, the client signs the shared key obtained through Diffie-Hellman key exchange, which then gets verified by the server. This ensures that the client and the server have the same shared key, hence no man-in-the-middle.