SECURITY / A CONCEPT NOTE

Encryption Rest vs Transit

two places data leaks

~65 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Encryption in Transit secures data as it travels across the network (TLS, HTTPS). Encryption at Rest secures data stored physically on disks (KMS keys, BitLocker).

02 / FOLLOW THE MECHANISM

How data is protected

  1. Transit route

    client sends credit card info. HTTPS encrypts traffic over internet cables.

  2. Decrypt server

    web server decrypts payload, sending it internally.

  3. Rest write

    database server encrypts record using KMS key before saving to block storage.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

manually encrypt data before writing to storage

openssl enc -aes-256-cbc -salt -in data.txt -out data.enc

Explore command anatomy in the CLI lab