4 ms·
I don't really understand the confusion around these terms in terms of day-to-day actual work. Is this really a problem? This seems like a trivial question to m
by bgro 5y ago
I don't really understand the confusion around these terms in terms of day-to-day actual work. Is this really a problem? This seems like a trivial question to me so much so that I would (and have) screwed up this question in an interview which I'll discuss here.
In my pedantic technical opinion (technical as in literal, not technical-interview), these are all subsets of encryption. Encryption to me is anything that scrambles the data to non-literal-plain-text in a way where you need a key to read it. These are just encryption, but the password is always just the word "password", or for a specific example, the source text.
In my continued opinion, can't hashes be "found out" in theory if you had unlimited computing time + unlimited attempts at brute force hashing every string?
Encoding is just encrypting the text into a non-literal-plain-text format by using (an extremely weak, known password) to translate into another (computer-readable) language. I don't really have anything to add from the source to this one.
Why is my distinction about the definition of encryption important to me?
In my opinion, we shouldn't limit our mind to ONLY knowing encryption as a method containing some math formula someone came up with to scramble you data based on an input password. There are a magnitude of ways to encrypt your actions in a more broad sense.
For example, what if you identify yourself by handing in a series of paintings to somebody (an authenticator) who physically determines your entry? He can determine if you pass by having knowledge that the order of the paintings and the artist's initials correspond to their position in the alphabet to decrypt your ID number. (Some other tricks could be used to prevent random turn in or duplicates, such as only using a specific style of art, but I'm skipping that for this example.) Is that not an encryption method that accepts a user input and encrypts it with a black box formula to output some code?
- ignoramous 5y ago> Encryption to me is anything that scrambles the data to non-literal-plain-text in a way where you need a key to read it. You can't re-read what's hashed, though.
- 3np 5y agoIn the context of cryptography, encryption has a specific meaning. Your intuitive non-standard definition may be interesting and useful, but its aking to bringing up perceptive hashing like what Apple's been introducing for CPAM on iCloud. At this point it becomes an overloaded term and the meaning depends on context. Words are more useful and efficient if we have a common understanding to stand on. > I don't really understand the confusion around these terms in terms of day-to-day actual work. Is this really a problem? It absolutely is. I've seen software that, instead of salt-hashing passwords in the DB, will encrypt them with an global RSA public key (not only less secure and way less efficient, you now also have an effective undocumented max-length of passwords). Or, way more common, utilizing base64-encoding as "encryption". If understanding of the differences was more widespread, at least these systems may have been less terrible.
- bgro 5y agoI agree with everything you said. My point boils down to it seems like there is ambiguity between the technical definition vs the actual practice and security requirements we've currently decided on as acceptable. Somebody who uses base64 to "encrypt" into a database clearly did their job wrong. A test question that says something like "True/False, encryption can be used to alter the original string into a different string" is true because it doesn't go into the details about the security that we all (should) know needs to be there. When we ask the question kind of backwards from the ambiguous meaning like this, I think we can get a different definition and end up with silly things that technically meet the definition requirement such as base64. Anyway, my take doesn't really matter. It's more of venting how I always get stuck on easy questions in software dev interviews and end up losing out to somebody who uses base64 in prod to attempt implementing "encryption" to the database.