Home / Software y Cloud / The journey of a data packet over HTTP/3 and QUIC: goodbye to the double handshake

The journey of a data packet over HTTP/3 and QUIC: goodbye to the double handshake

Ilustración de un paquete de red viajando por HTTP/3 QUIC

For decades, every new page you loaded started with the same three words in the world of bits: hello, hello, I am here. That two-round handshake was inherited from a protocol designed in 1981, when nobody imagined smartphones or video streaming. Today most of your connections have replaced that ritual with a far more direct one, and the culprit is a duo called HTTP/3 and QUIC.

The problem: the transport could not do much more

HTTP/2 (the previous protocol, from 2015) was already fast, but it still rode on top of the classic TCP. TCP has one good property and one bad one: it acknowledges every packet in order. If a single packet is lost on the way, the ones behind it wait even if they carry data for a different resource of your page. That clogging is called head-of-line blocking, and it is why a single lost packet could stall the download of an image, a video and a stylesheet all at once.

TCP also negotiates the connection in two passes (the famous handshake), and then, if you want encryption, TLS 1.2 added yet another round. In the worst case, three round trips between your phone and the server before sending a single useful byte. On a network with 100 milliseconds of latency, that is 300 ms of greeting alone.

QUIC: a new transport on a lane that already existed

Google started designing QUIC in 2012 precisely for that. The key decision was architectural: instead of waiting for the internet infrastructure to learn a new protocol, QUIC runs over UDP (the lightweight protocol with no delivery guarantees), and all of TCP’s intelligence — flow control, congestion control, reordering — moves up to user space, inside the browser’s own process. No router along the path needs to be touched.

That enables a masterstroke: losing one packet no longer blocks the independent streams. QUIC multiplexes several data flows inside a single connection, and each one is retransmitted and acknowledged separately. If the image is lost, the text and video keep coming down without waiting.

Encryption, built in from the first byte

Unlike TLS 1.2 (where encryption and transport were separate layers negotiated in different rounds), QUIC integrates TLS 1.3 into its own initial handshake. The result is that the handshake shrinks to a single round trip: on the first visit, one round-trip time (RTT) and you can already send data; on subsequent connections to the same server, QUIC remembers the session and sends 0-RTT packets, encrypted in the first burst reusing the negotiated TLS state.

Encryption also goes deeper: while TCP only exposed the port, QUIC encrypts most of the packet header, leaving visible only what routers need for forwarding. That makes life much harder for intermediaries trying to inspect or tamper with traffic.

A connection that survives a network change

You have a live QUIC connection and you move from Wi-Fi to mobile data; the server sees your phone’s IP change, but the connection does not blink. TCP would have torn down and rebuilt the handshake. QUIC instead identifies the connection by a Connection ID chosen by the client and carried inside the packet, not by the source IP. Packets get rerouted, the session stays alive, and you keep playing your video without losing a single frame. This is called connection migration, and it is pure gold for mobile traffic.

Network control, in the hands of the receiver

Congestion control (how to decide how many packets to send without drowning the network) was redesigned too. Classic algorithms like TCP’s slow start or hybla assumed a world of fiber. With QUIC, every browser or server can choose its own logic, and many have adopted BBR, Google’s algorithm that no longer uses packet loss as the congestion signal, but measures the actual bandwidth and the minimum delay along the path to saturate the pipe aggressively yet precisely. The gain is especially visible on lossy links, like congested mobile networks or VPN tunnels.

So what changes for me?

Every day, almost without noticing. HTTP/3 is now the reference standard and is on by default in Chrome, Firefox, Edge and Safari; in 2026 it is the majority connection to most major platforms. It speeds up the initial load, cheapens streaming, makes videos more tolerant to network drops, and protects privacy better because fewer metadata are exposed.

It is a good example of how a forty-year-old protocol, TCP, gave way to a new architecture without changing a single cable on the planet. Sometimes the biggest technological leap does not come from new hardware, but from deciding which layer should make the decisions.