Encryption
- In Turkish
- Şifreleme
In short
Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
What is encryption?
Encryption transforms readable data, called plaintext, into unreadable ciphertext using an algorithm and a key. Anyone who intercepts the ciphertext sees only random-looking bytes, while someone with the right key can decrypt it back into the original. The security depends on keeping the key secret, not on keeping the algorithm secret.
There are two main kinds. Symmetric encryption, such as AES, uses the same secret key to encrypt and decrypt and is very fast, which makes it the choice for bulk data. Asymmetric, or public-key, encryption, such as RSA or elliptic-curve cryptography, uses a key pair: anyone can encrypt with the public key, but only the holder of the private key can decrypt. Protocols like TLS combine both, using public-key cryptography to agree on a shared key and symmetric encryption for the actual traffic.
Developers usually protect data in transit, such as HTTPS traffic, and data at rest, such as databases, backups, and disks. A locked box is a good analogy: anyone can see or carry the box, but only someone with the key can open it. End-to-end encryption, used in many messaging apps, means only the sender and the recipient hold the keys, so even the service provider cannot read the messages.
Encryption is often confused with hashing and encoding. Hashing is one-way and is used for passwords and integrity checks, while encoding such as Base64 only changes the format and provides no secrecy at all. To use encryption safely, rely on well-tested libraries and modern authenticated modes such as AES-GCM or ChaCha20-Poly1305, never invent your own algorithm, and keep keys in a key management service or secrets manager rather than in source code.
At a glance
Key takeaways
- Encryption turns plaintext into ciphertext that only key holders can read.
- Symmetric encryption uses one shared key; asymmetric uses a public and private key pair.
- Protect data both in transit (TLS) and at rest (disks, databases, backups).
- Encryption is reversible, unlike hashing, and Base64 encoding is not encryption.
- Use vetted libraries and authenticated modes, and keep keys out of code.
Example
import { randomBytes, createCipheriv, createDecipheriv } from "node:crypto";
// A 256-bit key, loaded from a secrets manager in real apps
const key = Buffer.from(process.env.DATA_KEY, "base64");
const iv = randomBytes(12); // a new random IV for every message
// Encrypt with AES-256-GCM, an authenticated mode that detects tampering
const cipher = createCipheriv("aes-256-gcm", key, iv);
const ciphertext = Buffer.concat([cipher.update("my secret note", "utf8"), cipher.final()]);
const tag = cipher.getAuthTag();
// Decrypt: throws an error if the ciphertext or tag was modified
const decipher = createDecipheriv("aes-256-gcm", key, iv);
decipher.setAuthTag(tag);
const plaintext = Buffer.concat([decipher.update(ciphertext), decipher.final()]).toString("utf8");Readers ask
What is the difference between encryption and hashing?
Encryption is two-way: data encrypted with a key can be decrypted with the right key. Hashing is one-way, producing a fixed fingerprint that cannot be turned back into the input, which is why passwords should be hashed rather than encrypted.
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses a single shared key for both encrypting and decrypting and is fast. Asymmetric encryption uses a public key to encrypt and a private key to decrypt, which solves the problem of sharing keys but is slower, so real systems usually combine the two.
Is Base64 encryption?
No. Base64 is an encoding that turns binary data into text characters, and anyone can decode it without a key. It offers no protection for secrets.
Often compared
See also
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- DatabaseDatabases, p. 6A database is an organized collection of data stored on a computer, managed by software that lets applications save, search, and update it efficiently.
- Environment VariableDevOps & Cloud, p. 20An environment variable is a named value set outside a program, by the operating system or runtime, that the program reads to configure its behavior.
- Symmetric EncryptionSecurity, p. 44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- End-to-End EncryptionSecurity, p. 13End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- Base64Programming Fundamentals, p. 5Base64 is a way to write any binary data, such as an image or a key, using only 64 safe text characters, so it can pass through systems built for text.
Sources
Spotted a mistake or something missing on this page?Suggest an edit