Case 5AA3EE · Cryptography · L1 Foundations
Hashing vs Encryption vs Encoding
Practise as: Explain it · Interview
Interview questionWhat is the difference between hashing, encryption and encoding, and when would you use each?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Encoding (Base64, URL, hex) is a reversible format change with no key; it provides zero confidentiality.
- Encryption is reversible only with a key: AES-GCM for data, RSA/ECIES for key transport; goal is confidentiality.
- Hashing (SHA-256, SHA-3) is one-way and fixed-length; used for integrity, fingerprints and commitments.
- Hashes need preimage, second-preimage and collision resistance; MD5 and SHA-1 have practical collisions.
- Passwords need slow, salted KDFs (Argon2id, bcrypt), not fast hashes; integrity with a secret needs HMAC.
If the interviewer pushes back
- Why is SHA-256(key || message) unsafe as a MAC, and how does HMAC avoid length-extension?
- When is Base64 in a JWT a security problem, and what actually protects the token?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.