पाठ 10 / 25

Encryption in Transit and at Rest

TLS everywhere, sensible storage encryption.

Classify data, then protect it

Start by classifying data (passwords, payment data, health records, personal data) and avoid storing what you do not need. Serve everything over TLS (1.2 or later, preferably 1.3) with HSTS so browsers never fall back to HTTP, and encrypt internal service traffic where possible. Encrypt sensitive data at rest using platform features (disk, database or field-level encryption) with keys in a key management service. Use well-reviewed libraries and modern algorithms (AES-GCM, ChaCha20-Poly1305); never invent your own cryptography or use broken algorithms such as MD5, SHA-1 for signatures, DES or ECB mode.

Protect data in transit and at rest

Most cryptographic failures come from not encrypting, using weak algorithms or mishandling keys and passwords.

Three ideas: transport and storage encryption, password hashing, secrets management.
Figure 4.1 — TLS, password hashing and secrets.

Transport security headers

Example HTTP response headers.

Strict-Transport-Security: max-age=31536000; includeSubDomains
    -> browsers use HTTPS only for this site for one year

Set-Cookie: session=...; Secure; HttpOnly; SameSite=Lax; Path=/
    -> cookie sent only over HTTPS, hidden from scripts, limited cross-site sending

Do not log sensitive data

Tokens, card numbers and passwords in logs undo encryption elsewhere.

त्वरित जाँच: What does HSTS do?

  • Tells browsers to use HTTPS only for the site
  • Encrypts the database
  • Hashes passwords
  • Blocks all cookies
Answer

Tells browsers to use HTTPS only for the site — Prevents downgrade to HTTP.