Hashing vs encryption vs encoding
Three ideas that beginners often mix up, and why the difference matters for security.
These three words describe different things. Confusing them causes real security mistakes, such as "protecting" passwords with Base64.
| Reversible? | Needs a key? | Purpose | |
|---|---|---|---|
| Encoding (Base64, URL encoding) | Yes | No | Represent data in a format that fits a channel. Not security. |
| Encryption (AES, RSA) | Yes, with the key | Yes | Keep data confidential. |
| Hashing (SHA-256, Argon2) | No | No (sometimes a salt) | Fingerprint data, verify integrity, store passwords. |
Encoding example
Base64 turns bytes into text made of 64 safe characters. Anyone can decode it:
hello -> aGVsbG8= (Base64)
aGVsbG8= -> hello (decoded by anyone, no key)CarefulA JWT payload and HTTP Basic credentials are only Base64-encoded. That hides nothing.
Encryption example
Encryption scrambles data with a key. Only someone with the right key can read it. Symmetric encryption (AES) uses one shared key. Asymmetric encryption (RSA, elliptic curves) uses a public/private key pair, the idea behind SSH keys and TLS.
Which one do I need?
- Need to read the data again later? Use encryption.
- Only need to check that two things match, such as a password or a file? Use a hash.
- Need the data to travel through a text-only channel? Use encoding, plus encryption if it is secret.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.