3 ms·
I agree with everything you said. My point boils down to it seems like there is ambiguity between the technical definition vs the actual practice and security
by bgro 5y ago
I agree with everything you said.
My point boils down to it seems like there is ambiguity between the technical definition vs the actual practice and security requirements we've currently decided on as acceptable.
Somebody who uses base64 to "encrypt" into a database clearly did their job wrong.
A test question that says something like "True/False, encryption can be used to alter the original string into a different string" is true because it doesn't go into the details about the security that we all (should) know needs to be there. When we ask the question kind of backwards from the ambiguous meaning like this, I think we can get a different definition and end up with silly things that technically meet the definition requirement such as base64.
Anyway, my take doesn't really matter. It's more of venting how I always get stuck on easy questions in software dev interviews and end up losing out to somebody who uses base64 in prod to attempt implementing "encryption" to the database.