A handshake negotiates cryptographic parameters and verifies certificates before application data is exchanged. Session keys then protect traffic from passive reading and undetected modification in transit. SSL refers to obsolete predecessor protocols but remains common shorthand.