Encryption, HTTPS and TLS

4.Locked Boxes and Open Padlocks

A

In this chapter

We'll learn what encryption really does — locking data so only the right key opens it — the two kinds of keys, how HTTPS and TLS use both, and the difference between protecting data while it travels and while it's stored, explained with locked boxes and open padlocks.

12–14 min

The Problem in Real Life

Samantha forwards a question from a large venue's IT department: "Is our customers' data encrypted in transit and at rest?" She adds one line: "Please answer this in words I can also understand."

Anna knows the padlock in the browser from Act 12, and that the database is "encrypted" from Act 20. But to answer properly, she needs to understand what encryption actually is — and why it's different from the hashing she just learned.

A

Hashing is a smoothie. So what's encryption?

Anna

Data Anyone Can Read vs. Data Only the Right Key Can Open

Data travels through strangers

Between a fan's phone and BlueTicket, data passes through Wi-Fi, ISPs and routers (Act 11).

Data sits on disks

Databases, backups and laptops can be stolen or copied.

Sharing a key safely

To lock and unlock messages, both sides need keys — without anyone else getting them.

Encryption, HTTPS and TLS

The locked box analogy: encryption is putting a message in a box and locking it. Anyone can carry the box, but only someone with the right key can open it and read the message. Unlike hashing (the smoothie), encryption is designed to be reversed — by the right key.

  • Encryption vs. hashing: hashing is one-way: good for checking (passwords). Encryption is two-way: good for hiding and later reading (messages, stored data). Use the wrong one and you get either readable passwords or unreadable data.
  • Symmetric encryption — one key for locking and unlocking: the same key locks and unlocks, like a normal house key. Very fast, so it's used for large amounts of data (the standard algorithm is AES). The problem: how do two sides who've never met agree on the same secret key, over a network full of strangers?
  • Asymmetric encryption — the open padlock: imagine handing out open padlocks to anyone who asks, while you keep the only key. Anyone can snap a padlock shut on a box and send it to you; only you can open it. That's asymmetric encryption: a public key (the padlock — share it freely) and a private key (keep it secret). It also works backwards for signatures: something "locked" with your private key can be checked by anyone with your public key — that's how certificates and JWT-style signatures prove who made them.
  • TLS — using both, cleverly: TLS (Transport Layer Security) is the protocol that secures connections. During the handshake (Act 12), the server shows its certificate (Act 19) — its public key, signed by a trusted authority, proving it's really blueticket.example. Then, using asymmetric tricks, browser and server agree on a fresh symmetric key that nobody watching can work out. The rest of the conversation is encrypted with that fast symmetric key.
  • HTTPS — HTTP inside TLS: HTTPS is ordinary HTTP (Act 12) sent through a TLS connection. It gives three things: privacy (nobody in between can read it), integrity (nobody can change it unnoticed) and authenticity (you're really talking to the site whose name you typed).
  • Encryption in transit — while it travels: data moving over a network is encrypted with TLS: browser to load balancer (HTTPS), and ideally also inside the system — app to database, app to Redis — so someone who gets into the network still sees only locked boxes.
  • Encryption at rest — while it's stored: data on disks — databases, backups, object storage, laptops — is encrypted, so a stolen disk or copied backup is unreadable without the keys. Cloud providers make this a setting (Act 20's storage_encrypted = true); the keys are kept in a key management service, separate from the data.
Table — Hashing vs. encryption
FeatureHashingEncryption
AnalogyA smoothieA locked box
Reversible?NoYes, with the key
Use forPasswords, checking files haven't changedMessages, stored data you need to read later
Examplesbcrypt, Argon2, SHA-256AES, TLS
Table — Symmetric vs. asymmetric
FeatureSymmetricAsymmetric
AnalogyOne house keyOpen padlocks + your private key
KeysOne shared secret keyPublic key + private key
SpeedVery fastSlower
Used forEncrypting the actual dataAgreeing on keys, certificates, signatures

Where BlueTicket's data is encrypted

Fan's browser or app

HTTPS

in transit: TLS

Load balancer

certificate for blueticket.example

in transit: TLS

App containers

inside the private network

in transit: TLS

Database + backups

at rest: encrypted disks

Object storage

at rest: encrypted

Anna's answer to the venue: "Yes. In transit: every connection from fans' browsers and apps uses HTTPS with TLS 1.2 or newer, and connections between our services and our database and Redis are also encrypted with TLS. At rest: our database, its backups and our file storage are encrypted on disk, with keys held in our cloud provider's key management service. Passwords are not encrypted at all — they're stored only as salted bcrypt hashes, so even we can't read them. Card numbers are never stored by us; our payment provider handles them." Samantha reads it twice. "I understood every sentence. Send it."

Key Takeaway

Encryption locks data in a box that only the right key can open — unlike hashing, it's meant to be reversed. Symmetric encryption uses one fast shared key (AES); asymmetric uses a public padlock and a private key, and also enables signatures. TLS combines them: certificates prove identity, then a fresh symmetric key encrypts the conversation. HTTPS is HTTP over TLS. Protect data in transit (TLS everywhere) and at rest (encrypted disks and backups, keys kept separately).

Why This Matters

Customers, venues, auditors and laws all ask the same question: is the data encrypted in transit and at rest? Knowing the difference between hashing and encryption, what TLS actually does and where keys live lets you answer clearly — and avoid classic mistakes like encrypting passwords or forgetting the connection to the database.

Encryption is only as safe as its keys. And on Thursday morning, one of BlueTicket's most powerful keys was sitting on a public website for anyone to copy.

Next