7. Encryption, Privacy, and Trust

A guided introduction to how encryption, authentication, hashing, secure protocols, and key management establish confidentiality, integrity, privacy, and trust while creating practical and legal trade-offs.

The Four Questions of Digital Trust

Digital security begins with four questions: who is communicating or requesting access, whether others can read the information, whether the information has changed, and whether the answer can be trusted. These questions correspond broadly to identity, confidentiality, integrity, and trust.

addresses confidentiality by transforming plaintext into ciphertext. It can protect files on a device, messages moving across a network, and, with greater difficulty, information being actively processed. does not necessarily conceal the fact that communication occurred, and it does not automatically establish the sender's identity or prove that a message was not altered.

A useful first distinction is between protection goals:

  • Confidentiality limits who can read information.

  • Integrity helps detect unauthorized changes.

  • establishes the identity of a person, device, or service.

  • Authorization determines what an authenticated entity may do.

Takeaway: is an important security tool, but confidentiality, integrity, identity, and permission are related goals that require complementary mechanisms.

Two Complementary Models

uses one shared secret key to encrypt and decrypt information. It is efficient for large files and ongoing communication, but the participants must establish the shared secret safely. If an attacker obtains that key, the protection may fail even when the algorithm itself is strong.

uses a public key that can be shared and a private key that must remain secret. A sender can use a recipient's public key for , while the matching private key is used for decryption. The same key-pair idea also supports digital signatures: a sender signs with a private key, and others verify with the corresponding public key. A signature supports authenticity and integrity, but it does not by itself provide confidentiality.

Secure systems commonly combine both approaches. Public-key operations help authenticate participants and establish a temporary session key; then protects the larger amount of data efficiently.

Takeaway: is fast but depends on secure secret sharing, while helps with public-key distribution and signatures but is usually used for limited setup operations.

Keys and Their Life Cycle

A cryptographic key controls an operation such as , decryption, signing, or verification. therefore covers more than keeping a password secret. A complete life cycle includes:

  1. Generating keys with a secure source of randomness.

  2. Distributing or establishing keys securely.

  3. Storing and protecting keys.

  4. Using keys only for their intended purposes.

  5. Rotating or replacing keys when appropriate.

  6. Revoking compromised keys.

  7. Backing up keys when recovery is necessary.

  8. Destroying keys so that protected data cannot be decrypted later.

A strong algorithm cannot compensate for a stolen private key, a weak secret, or careless storage. This is similar to a safe: the safe's construction matters, but possession of its combination can still defeat its protection.

Takeaway: Cryptographic strength depends on both the algorithm and the protection of the keys throughout their entire life cycle.

Identity, Permission, and Certificates

Trust requires more than encrypting data. asks whether a person, device, or service is really the entity it claims to be. Authorization follows and determines which actions or records that entity may access.

factors are commonly grouped as follows:

  • Something you know, such as a password or PIN.

  • Something you have, such as a security key, phone, or hardware token.

  • Something you are, such as a fingerprint or facial characteristic.

combines at least two different categories. It reduces the damage caused by a stolen password, although some methods resist phishing better than others. A physical security key is generally stronger against phishing than a text-message code.

Digital certificates add another layer of trust. A certificate binds an identity, such as a website name, to a public key. A certificate authority signs the certificate so that a browser can check the claimed association. This system is useful but not perfect because compromised authorities, deceptive websites, stolen private keys, and user mistakes can still create risks.

Takeaway: establishes who is present, authorization limits what that entity may do, and certificates help systems connect identities with public keys.

Hashing and Integrity Checks

A produces a fixed-length value from input of arbitrary length. The result is commonly called a hash, digest, or fingerprint. Secure hash functions are designed to be difficult to reverse and difficult to use to produce the same result from two different inputs.

Hashing differs from :

  • is intended to provide confidentiality and can be reversed with the correct key.

  • Hashing is intended mainly for integrity checks and verification and is designed to be impractical to reverse.

For example, a software publisher may publish a file's hash. After downloading the file, a user computes the hash again and compares the results. A mismatch indicates that the file may have been corrupted or replaced.

Password storage requires additional care. A secure service should not store ordinary passwords in readable form. It should use a password-hashing scheme with a unique salt and an appropriate cost factor. A salt prevents identical passwords from producing identical stored results, while the cost factor makes large-scale guessing more expensive. A plain, fast, unsalted hash is not an adequate password solution.

Takeaway: Hashes help verify information and protect password verifiers, but hashing does not make information confidential.

Secure Communication in Practice

Secure communication protocols combine several protections. , which is used by HTTPS, negotiates cryptographic algorithms, authenticates the server through a certificate, establishes session keys, and protects application data against eavesdropping and unauthorized modification.

An online purchase illustrates the sequence:

  1. The browser connects to the retailer's website.

  2. The website presents a certificate containing its public key.

  3. The browser checks the certificate and the certificate authority's signature.

  4. The browser and server establish temporary session keys.

  5. The purchase information is encrypted and integrity-protected during transmission.

sets a stronger communication boundary. The sender's device encrypts the message, and only the intended recipient's device decrypts it. A service provider may deliver the ciphertext without possessing the key needed to read the content. This can protect people from criminals, data breaches, and unauthorized surveillance, but it can also make content inaccessible to providers or governments even under a warrant.

Neither TLS nor end-to-end guarantees that an organization is honest, a device is free of malware, or an account password has not been stolen.

Takeaway: Secure protocols layer , key establishment, , and integrity protection, while end-to-end limits who can decrypt the content itself.

Trade-offs and Practical Protection

Cryptographic design involves trade-offs among privacy, security, convenience, and . Strong can reduce identity theft, industrial espionage, stalking, censorship, and cybercrime. It can also make it harder to investigate harmful activity when evidence is encrypted.

Security controls can create inconvenience. Long passphrases, hardware security keys, updates, recovery procedures, and extra verification take time. If controls are too difficult, people may reuse passwords, share accounts, disable protections, or adopt unsafe workarounds. Good security therefore aims for usable protections that match the risks people face.

refers to authorized government access to digital evidence under legal procedures such as a warrant or court order. A universal secret entry point, often called a backdoor, creates a security concern because the mechanism may become a target for criminals, hostile governments, insiders, or future attackers. Other investigative approaches may include unencrypted backups, endpoint evidence, metadata, or provider-held keys where they exist; each approach has its own privacy, legal, and security consequences.

Responsible policy should ask:

  • Is the access authorized by clear law and independent oversight?

  • Is the request specific and proportionate?

  • Could the method expose other users or systems?

  • Can access be audited and limited?

  • Does the design preserve strong security for everyone else?

Practical protections include using HTTPS, enabling phishing-resistant MFA when possible, using unique passphrases with a password manager, updating software, encrypting devices and backups, protecting private keys, checking trusted downloads and published hashes or signatures, recognizing phishing attempts, and planning account recovery.

Takeaway: No single security goal is absolute. Responsible design preserves strong protection while addressing usability, accountability, privacy, and legitimate investigative needs.