Open cardosec

Case 5AA3EE · Cryptography · L1 Foundations

Hashing vs Encryption vs Encoding

Practise as: Explain it · Interview

Interview questionWhat is the difference between hashing, encryption and encoding, and when would you use each?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Encoding (Base64, URL, hex) is a reversible format change with no key; it provides zero confidentiality.
  2. Encryption is reversible only with a key: AES-GCM for data, RSA/ECIES for key transport; goal is confidentiality.
  3. Hashing (SHA-256, SHA-3) is one-way and fixed-length; used for integrity, fingerprints and commitments.
  4. Hashes need preimage, second-preimage and collision resistance; MD5 and SHA-1 have practical collisions.
  5. Passwords need slow, salted KDFs (Argon2id, bcrypt), not fast hashes; integrity with a secret needs HMAC.

If the interviewer pushes back

  • Why is SHA-256(key || message) unsafe as a MAC, and how does HMAC avoid length-extension?
  • When is Base64 in a JWT a security problem, and what actually protects the token?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.