# Encryption in Transit and at Rest — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/c-transit

> TLS everywhere, sensible storage encryption.

## Classify data, then protect it

Start by classifying data (passwords, payment data, health records, personal data) and avoid storing what you do not need. Serve everything over **TLS** (1.2 or later, preferably 1.3) with **HSTS** so browsers never fall back to HTTP, and encrypt internal service traffic where possible. Encrypt sensitive data at rest using platform features (disk, database or field-level encryption) with keys in a key management service. Use well-reviewed libraries and modern algorithms (AES-GCM, ChaCha20-Poly1305); never invent your own cryptography or use broken algorithms such as MD5, SHA-1 for signatures, DES or ECB mode.

## Protect data in transit and at rest

Most cryptographic failures come from not encrypting, using weak algorithms or mishandling keys and passwords.

![Three ideas: transport and storage encryption, password hashing, secrets management.](assets/figures/owasp-top-10/section-4-map.svg) — Figure 4.1 — TLS, password hashing and secrets.

## Transport security headers

Example HTTP response headers.

```text
Strict-Transport-Security: max-age=31536000; includeSubDomains
    -> browsers use HTTPS only for this site for one year

Set-Cookie: session=...; Secure; HttpOnly; SameSite=Lax; Path=/
    -> cookie sent only over HTTPS, hidden from scripts, limited cross-site sending
```

## Do not log sensitive data

Tokens, card numbers and passwords in logs undo encryption elsewhere.

**Quiz:** What does HSTS do?

- [x] Tells browsers to use HTTPS only for the site
- [ ] Encrypts the database
- [ ] Hashes passwords
- [ ] Blocks all cookies

*Answer:* Tells browsers to use HTTPS only for the site. Prevents downgrade to HTTP.
