SECURITY / A CONCEPT NOTE
Encryption Rest vs Transit
two places data leaks
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Encryption in Transit secures data as it travels across the network (TLS, HTTPS). Encryption at Rest secures data stored physically on disks (KMS keys, BitLocker).
02 / FOLLOW THE MECHANISM
How data is protected
Transit route
client sends credit card info. HTTPS encrypts traffic over internet cables.
Decrypt server
web server decrypts payload, sending it internally.
Rest write
database server encrypts record using KMS key before saving to block storage.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
manually encrypt data before writing to storage
openssl enc -aes-256-cbc -salt -in data.txt -out data.enc05 / CHECK YOURSELF
Could you explain Encryption Rest vs Transit to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityCVEs & Patchinghow vulnerabilities get names